UiPath does not send the SAML Certificate in the Assertion.
Expected behavior, the certificates are not sent in the SAML assertion, as UiPath acts only as the Service Provider in the SAML authentication context. The signing certificate is mainly used by the Identity Provider (corresponding SAML provider) to prove that they are the actual IDP that was set in the UiPath setup for us to trust them and further validate the authentication request.
The SAML Login in Orchestrator is usually initiated from the Orchestrator Login page (SP-initiated), meaning that the authentication request is sent only to the IDP and the confirmation is expected in the form of a signed assertion back.
As explained below, in step 5, the Identity Provider signs the assertion with the certificate:
More details available in the documentation of SP-Initiated SSO: Redirect/POST Bindings .