SCIM user provisioning
Set up SCIM 2.0 to create, update and remove workspace members automatically from your identity provider, with the base URL, token and supported endpoints.
SCIM 2.0 keeps workspace members in sync with your directory (Business plan, with SSO set up).
Connect#
- Workspace settings → SSO → SCIM token → Generate. The
token (
scim_…) is shown once. Generating a new one replaces the old. - In your IdP's provisioning settings:
| Setting | Value |
|---|---|
| SCIM base URL | https://privatusanalytics.com/scim/v2 |
| Authentication | HTTP header, Bearer token: the scim_… token |
| Unique identifier | userName = email address |
- Enable create, update and deactivate users, and assign the people or groups to provision.
What's supported#
| Operation | Endpoint | Effect |
|---|---|---|
| List / filter users | GET /scim/v2/Users |
Users provisioned into this workspace (filter=userName eq "…" supported) |
| Get a user | GET /scim/v2/Users/{id} |
|
| Create | POST /scim/v2/Users |
Creates the user if needed and adds them as a member with the SSO default role |
| Update | PUT or PATCH /scim/v2/Users/{id} |
Display name and active. active: false removes the membership |
| Delete | DELETE /scim/v2/Users/{id} |
Removes the member from the workspace |
Groups aren't provisioned: set roles and site access in Privatus. Removing a member revokes their API tokens for this workspace. The person's account itself is kept (they may belong to other workspaces).
Every SCIM change is recorded in the audit log.