Configure Certificate Credentials
Use a Certificate Credential when the external API requires a client certificate for the outbound request.
The certificate itself is managed in Salesforce Setup. The Credential stores the certificate name Payloads should use when it sends the callout.
Before you start
Create or upload the certificate in Salesforce Setup under Certificate and Key Management.
Copy the certificate's Unique Name from Salesforce. Use the Unique Name, not the label, when configuring the Credential.
Confirm with the external system that the matching public certificate has been registered on their side.
Configure the Credential
Create a Credential from the relevant Integration.
Set Type to Certificate.
Enter the Certificate Name from Salesforce Certificate and Key Management.
Save the Credential.
A Certificate Credential references the Salesforce certificate by unique name so Payloads can apply it to outbound callouts.
Attach it to a Payload
Open the Outbound Payload and select HTTP Request in Actions.
Edit Request Settings.
Choose the Credential and save the settings section.
Use the HTTP Request Body, Headers and Parameters sections for request-specific values. Avoid adding a second authentication header or parameter that duplicates the Credential.
Run a controlled request and open the Job’s HTTP Request and HTTP Response Actions to inspect the outcome.
What to check
Before testing, check that:
the Certificate Name exactly matches the Salesforce certificate Unique Name
the certificate has not expired
the external system trusts the matching public certificate
the Payload has this Credential selected
the endpoint is the environment that expects this certificate
After a test run, open the Job record and check the response status. Certificate trust problems are usually returned by the external system or connection layer before the API processes the request body.

