Skip to main content

SCIM Provisioning

SCIM lets your identity provider manage organization membership directly. When you add, remove, or change someone's role in your identity provider, it's reflected in Observatory automatically, with no manual invites.

SCIM is configured per SSO connection, so set up your connection first.

  1. 1
    Open the connection's Provisioning tab
    Organization settings → SSO → your connection → Provisioning.
  2. 2
    Turn on SCIM
    And set the user ID attribute your provider will send (usually email).
  3. 3
    Generate a bearer token
    Copy it now. It's shown once and is what your provider uses to authenticate.
  4. 4
    Finish setup in your identity provider
    Paste the SCIM endpoint URL and bearer token into your provider's SCIM app configuration.

From this point on, membership changes made in your identity provider take effect in Observatory within the usual sync interval your provider uses.