# 7. Download Identity Provider files

{% hint style="info" %}
NOTE: If you use Okta to provide Single Sign-On access to Salesforce for your users, you will also need to complete the steps in [Delegate Authentication to Okta](https://docs.slapfive.com/integrations/salesforce/slapfive-app-spring-2024-4.0-and-earlier-versions/delegate-authentication-to-okta).
{% endhint %}

Go to **Setup** > **Identity** > **Identity Provider**.

Click on the **Enable Identity Provider** button if not already enabled.

Self-signed certificates expire after 12 months, so if your .crt file is about to expire or has already expired, generate a new certificate by going to **Setup** > **Security** > **Certificate and Key Management**. More information on this is contained in the **Generate new security certificate** section.

* [ ] Click on the **Download Certificate** button to download the .crt file.
* [ ] Click the **Download Metadata** button to download the .xml file.
* [ ] Provide these files to your SlapFive Coach.

{% hint style="info" %}
NOTE: Make sure that the Certificate shown in the Label field of the Identity Provider record is the same Certificate that you send to us at SlapFive, otherwise the authentication won't work.
{% endhint %}

<figure><img src="https://2901117923-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlkxMKaLwhXP9Cu98jtv6%2Fuploads%2F3XhJYQzyLQCLnlIVPvSo%2FScreenshot%202024-11-21%20161154.png?alt=media&#x26;token=cf274e57-59b4-430a-b19f-1e52e193393d" alt=""><figcaption><p>Download Certificate and Download Metadata file</p></figcaption></figure>
