---
sourceDocument: Yokohama Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/platform-security

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Certificate-based authentication

# Certificate-based authentication {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Certificate-based authentication lets you mutually authenticate user logins or inbound API requests using certificates from a trusted Certificate Authority (CA).  
Note:  
* Certificate Based Authentication is not supported on the On-Prem and edge encryption enabled instance.
* To enable Certificate Based Authentication on self-hosted instance, review this [KB article](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1272738) and follow the instructions available in the Native Certificate-Based Authentication row within the table.
{#certificate-based-authentication__ul_iqy_hkr_rjc}.

Certificate-based authentication for user interface logins

:   Enable end users to use PIV (Personal Identity Verification) or CAC (Common Access Card)
    cards to log in to the ServiceNow AI Platform or Service Portal instead of
    using a user name and password. To set up mutual authentication for user interface logins,
    see [Set up Certificate-based authentication](https://www.servicenow.com/docs/HGcChE4NiNp~bq6JM~bklA#set-up-mutual-auth "Set up mutual authentication for either user interface-based logins or inbound web services.").

    After Certificate-based authentication is set up, end users can finalize their set up and
    log in. See [Log in using Certificate-based authentication](https://www.servicenow.com/docs/DHTQMLAFsX6sc3crY2Uj6Q#ui-login-mutual-auth "After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.").

Certificate-based authentication for Inbound web services

:   Authenticate inbound requests to ServiceNow SOAP and REST APIs. To
    set up mutual authentication for inbound web services, see [Set up Certificate-based authentication](https://www.servicenow.com/docs/HGcChE4NiNp~bq6JM~bklA#set-up-mutual-auth "Set up mutual authentication for either user interface-based logins or inbound web services.").


