Skip to content

SCIM provisioning

With SCIM, your identity provider tells Updawg who should be a member. Adding somebody to the Updawg application in Okta or Entra ID makes them a member; removing them, or deactivating their account, removes their membership and ends every session they have immediately — nobody has to remember to do it.

SCIM builds on single sign-on: roles come from the same group mappings, and only addresses at your verified domains can be provisioned. Set single sign-on up first.

Under Settings → Single sign-on → SCIM, an owner issues a token. It is shown once; issuing another replaces it and revoking it stops provisioning. Give your provider:

SCIM base URL https://api.updawg.net/scim/v2
Authentication HTTP header, Bearer token: the scim_… token
Unique identifier userName (the person’s email address)

In Okta, add SCIM provisioning to the Updawg app and enable Create users, Update user attributes and Deactivate users; push the groups your role mappings name. In Entra ID, set provisioning to Automatic on the enterprise application with the URL and token above, and assign the users and groups.

  • Users: created (or, if the address is already a member, linked) with the role their groups map to, or the default role.
  • Groups: pushed groups decide roles through your mappings. Moving somebody between groups changes their role.
  • Deactivated or deleted: membership removed and every session ended.
  • Owners are never removed or demoted by the provider: that is done by a person in Updawg.

Supported: Users and Groups with create, read, replace, patch and delete; filtering by userName eq and displayName eq; ServiceProviderConfig, ResourceTypes and Schemas. Bulk operations, sorting and ETags are not.