Skip to main content
To test out SCIM, set up an Okta developer instance to use for this guide.

Configure a SCIM connection for a specific Organization

1

Enable SCIM provisioning for app

On the existing SSO SAML application in Okta, enable SCIM provisioning by navigating to the General tab of the application and checking “Enable SCIM Provisioning” under “App Settings”.Enable SCIM for an existing Okta SAML AppSave this change.
2

Create SCIM Connection in Stytch

Create a SCIM Connection on the Organization in the Stytch Dashboard or the Create SCIM Connection endpoint. Select Okta as the IdP.Create SCIM Connection in Stytch DashboardOnce you click save, you’ll be provided with the base url and bearer token you’ll need for the next step.Stytch Okta SCIM Connection CredentialsLeave this tab open and navigate back to Okta to input the returned credentials.
3

Configure Okta SCIM settings

In the application view in Okta, navigate to the new “Provisioning” tab and:
  1. Change the Authentication mode to HTTP Header
  2. Copy the “BaseURL” from Stytch into the “SCIM connector base URL” field
  3. Set the Unique identifier to userName
  4. Under “Supported provisioning actions”, select all the “Push..” options
  5. Copy the “HTTP Header Bearer Token” from Stytch into the “HTTP Header → Authorization” field
Your connection settings should look as follows:Expected SCIM Configuration for existing SAML AppSave.
4

Provision users

Once saved, you can test the SCIM integration by assigning people to and removing people from the application.You should see the status of the member changing from active to deactivated.
5

(Optional) Configure webhooks

To notify your own system of changes that occur via SCIM, configure webhooks. See the full list of relevant webhooks here.

Next Steps

If you only have a few customers who require SCIM connections, you can manage them by hand in the Stytch Dashboard. However, as your enterprise customer base grows, you may want to build a UI in your application to allow admins of Organizations to self-serve creating and updating their own SCIM connections. The simplest way to add SCIM connection management to your application is to use Stytch’s pre-built Admin Portal component. Admin Portal SCIM Management UI