Connect directory sync (SCIM)
Mint a SCIM token in the Developer Console, point your identity provider at the Environment, map pushed groups to roles, and revoke the token.
Mint a token and connect your provider
In the Developer Console, Access Control → Integrations → Directory Sync is one page with three tabs: Connection, Groups, and Activity. It provisions and deprovisions identities in this Environment from Okta, Entra ID, or any SCIM 2.0 provisioner. Directory Sync is a Pro feature; on a Free account the page says so and offers no actions.
- Application
- Developer Console
- Path
- Access ControlIntegrationsDirectory Sync
- Opens with
sso.viewRead SSO connections, verified domains, the custom auth domain, and directory sync.
- Context
- Select an Application and an Environment in the switcher first; the page belongs to that Environment.
Mint a token and connect your provider
Map groups to roles
A pushed group starts Unmapped. Mapping it to a role at a node grants every current member that role there, and membership pushes keep the grants in sync afterwards.
Map groups to roles
Revoke a token
Revoking ends the connection at once.
Revoke a token
If you don't see this
Each control on this page exists only for someone who may use it. When something described above is missing, one of these is why:
Tell us how we can improve this guide.