- Purpose: Manage cryptographic keys that sign tokens, assertions, or artifacts consumed by downstream parties to validate authenticity.
Rotate a Signing Key (recommended approach)
- Step 1: Create a new key and publish its public material (cert/JWK) to relying parties.
- Step 2: Configure systems to trust both old and new keys for a transition window.
- Step 3: After confirming adoption, revoke the old key.
- Step 4: Document change and store the rollout evidence.

Revoke a Key
- Immediate removal when compromise is suspected; coordinate with all consuming parties.

Best Practices
- Use distinct keys for distinct protocols (SAML signing vs token signing).
- Plan rotations and communicate dates to downstream teams.
- Keep rotation scripts and runbooks for incident response.

Troubleshooting
- Relying party signature validation fails:
- Ensure they fetched the updated public key and that clock skew/metadata endpoints are accessible.
Operational Checklist
- Publish a JWKS or metadata endpoint so RPs can rotate keys automatically.
- Keep a record of all key IDs and owners for audits.