1. Docs
  2. Single Sign-On
  3. Connect directory sync

Connect directory sync (SCIM)

Mint a SCIM token in the Developer Console, point your identity provider at the Environment, map pushed groups to roles, and revoke the token.

Mint a token and connect your provider

In the Developer Console, Access Control → Integrations → Directory Sync is one page with three tabs: Connection, Groups, and Activity. It provisions and deprovisions identities in this Environment from Okta, Entra ID, or any SCIM 2.0 provisioner. Directory Sync is a Pro feature; on a Free account the page says so and offers no actions.

Application
Developer Console
Path
Access ControlIntegrationsDirectory Sync
Opens with
  • sso.view Read SSO connections, verified domains, the custom auth domain, and directory sync.
Context
Select an Application and an Environment in the switcher first; the page belongs to that Environment.
Mint a token and connect your provider
Open Directory Sync from the left nav under Access Control → Integrations. On Connection, with nothing minted yet, the page reads No SCIM tokens yet.Click Mint SCIM Token and name it. The token is revealed once; copy it now. The table then lists it by name and Token Prefix, with Last Used reading Never until your provider first calls.In your identity provider, point SCIM provisioning at this Environment's SCIM endpoint using the token. Pushed users appear in the Environment's identities; pushed groups appear on the Groups tab.

Map groups to roles

A pushed group starts Unmapped. Mapping it to a role at a node grants every current member that role there, and membership pushes keep the grants in sync afterwards.

Map groups to roles
On Groups, click Map role on a group. In Map SCIM group to a role, choose the role and the node, and save. The dialog warns that every current member is granted the role on save; a Group mapped. Members granted the role. toast appears and the row shows the role.Edit mapping changes the role or node for the whole group.Unmap removes the mapping. The confirmation states that every member granted the role through the group loses it immediately, that group membership itself is unchanged, and that this cannot be undone. A Mapping removed. toast appears.The Activity tab is the feed of what your provider has done: users provisioned, updated, deprovisioned, and reactivated; groups created, updated, deleted, mapped, and unmapped; and any sync that failed.

Revoke a token

Revoking ends the connection at once.

Revoke a token
On Connection, click Revoke on the token. The Revoke SCIM Token dialog warns that provisioning requests using it stop working immediately and that a new token must be minted to reconnect. Confirm; a SCIM token revoked. toast appears.
If you don't see this

Each control on this page exists only for someone who may use it. When something described above is missing, one of these is why:

Directory Sync is not under Integrations. Either no Application and Environment is selected yet, or your administrator role does not carry sso.view.There is no Mint SCIM Token, Map role, Unmap, or Revoke. You hold sso.view but not sso.manage.The page says Directory Sync is a Pro feature. The Account is on the Free plan; upgrade from the Admin Workspace's Billing page.Groups is empty. Nothing appears until your identity provider pushes a group over SCIM using the token.
Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.