Provisioning (SCIM)
Let an identity provider such as Okta or Microsoft Entra ID create, suspend and remove an organization's members with SCIM 2.0.
Self-hostedManaged cloud
With SCIM 2.0, an identity provider manages an organization's members. It complements single sign-on: SCIM decides who is a member, sign-in decides how they prove who they are.
Turn it on
An owner or administrator opens Settings → Members → Provisioning. It gives:
| Base URL | <PUBLIC_URL>/scim/v2 |
| Bearer token | Shown once, stored hashed. Creating a new one replaces it. |
Enter both in the identity provider's SCIM application. A token acts in its own organization only.
What the provider can do
| Action | Effect |
|---|---|
| Create a user | An existing account with that email joins the organization. Otherwise an account without a password is created, for single sign-on. |
Deactivate (active: false) | Suspends the membership at once — also for sessions and API tokens issued before. Nothing is deleted. |
| Reactivate | Lifts the suspension |
| Change role | roles[0].value: ADMIN, MANAGER, DEVELOPER or VIEWER — never OWNER |
| Delete | Removes the member from the organization |
The only owner cannot be suspended or removed through SCIM.
Supported
/Userswith the filtersuserName eqandexternalId eq, and paging.PUTandPATCH, in the forms Okta and Microsoft Entra ID send./ServiceProviderConfig,/ResourceTypesand/Schemas.
Groups are not provisioned: /Groups answers with an empty list.
A suspended member's API access ends at once. A dashboard that is open keeps its live connection until it next reconnects.
Verification status
Tested with requests in the forms Okta and Microsoft Entra ID document, not yet against either service.