---
title: Setting up the X.509 Certificate Integration Kit
description: The Jamf Integration Kit requires the X.509 Certificate IdP Adapter to get device information from the device's client certificate.
component: jamf
page_id: jamf:setup:pf_jamf_ik_setting_up_the_x509_certificate_i
canonical_url: https://docs.pingidentity.com/integrations/jamf/setup/pf_jamf_ik_setting_up_the_x509_certificate_i.html
revdate: November 4, 2025
section_ids:
  steps: Steps
---

# Setting up the X.509 Certificate Integration Kit

The Jamf Integration Kit requires the X.509 Certificate IdP Adapter to get device information from the device's client certificate.

## Steps

1. Follow the steps in [Deploying the integration files](../../x509/x509_certificate_integration_kit/pf_x509_certificate_ik_deploying_the_integration_files.html) in the X.509 Certificate Integration Kit documentation.

2. Configure an adapter instance as shown in [Configuring an adapter instance](../../x509/x509_certificate_integration_kit/pf_x509_certificate_ik_configuring_an_adapter_instance.html) in the X.509 Certificate Integration Kit. Use the following details:

   1. On the **IdP Adapter** tab, in the **Advanced Fields** section, select the **Include Subject Alternative Name (SAN)** checkbox.

   2. On the **Extended Contract** tab, check that the device identifier and device type are available in either the core or extended contract.

      In the Jamf IdP Adapter configuration, you can specify that the device identifier is contained in one of the following attributes:

      * `deviceId`

      * `macAddress`

      * `serialNumber`

      * `udid`

      Depending on your certificate configuration, you might need to add one of these attributes to the extended contract.

      Optionally, you can also include an attribute that contains the device type. The value must be `computers` or `mobiledevices`.
