What Is SCIM?
SCIM (System for Cross-domain Identity Management) is an open standard (RFC 7642 – 7643 – 7644) that defines a REST API schema for automating the exchange of identity data between domains. Think of it as a universal adapter for user provisioning.
Before SCIM, every SaaS app had its own proprietary API for creating, updating, and deleting users. Identity providers (Azure AD / Okta) had to write custom connectors for each one — a maintenance nightmare. SCIM standardises this: one API contract that any SCIM-compliant app can speak. Credenti sits alongside other services as a SCIM receiver, ingesting identity data pushed by the IdP.
graph TD
IdP["<b>Identity Provider</b><br/>Azure AD / Okta"] -->|SCIM| Slack["<b>Slack</b><br/>messaging"]
IdP -->|SCIM| Credenti["<b>Credenti</b><br/>SCIM receiver"]
IdP -->|SCIM| GitHub["<b>GitHub</b><br/>dev tools"]
style IdP fill:#e8f0fe,stroke:#0071e3,color:#1d1d1f
style Slack fill:#f5f5f7,stroke:#d2d2d7,color:#1d1d1f
style Credenti fill:#e8f0fe,stroke:#0071e3,color:#1d1d1f
style GitHub fill:#f5f5f7,stroke:#d2d2d7,color:#1d1d1f
The Provisioning Problem
When a new hire joins, they need accounts in: HRIS, email, Slack, GitHub, Jira, VPN, and dozens of other tools. When they leave, every account must be deactivated — ideally within minutes.
Doing this manually is slow, error-prone, and a security risk. Orphan accounts (active accounts for former employees) are one of the most common attack vectors in enterprise breaches. SCIM automates the entire lifecycle.
SCIM in the Identity Stack
SCIM fills a specific gap. Understanding where it fits helps clarify why it exists:
| Layer | Protocol | What It Does |
|---|---|---|
| Authentication | OIDC / SAML | ”Who is this user?” — verifies identity at login |
| Authorisation | OAuth 2.0 | ”What can this app do?” — grants API permissions |
| Provisioning | SCIM | ”Does this user have an account?” — creates/deactivates accounts |
| Directory | LDAP | ”Where is this user in the org chart?” — looks up attributes |
OIDC lets Alice log into Slack. SCIM ensures Alice has a Slack account to log into — and deactivates it when she leaves.
The JML Lifecycle
SCIM maps directly to the three phases of identity management:
graph LR
J["<b>JOINER</b><br/>POST /Users {active:true}"] -->|account created| M["<b>MOVER</b><br/>PATCH /Users {dept: "Eng"}"]
M -->|roles updated| L["<b>LEAVER</b><br/>PATCH /Users {active:false}"]
style J fill:#e8f0fe,stroke:#0071e3,color:#1d1d1f
style M fill:#f5f5f7,stroke:#86868b,color:#1d1d1f
style L fill:#f5f5f7,stroke:#d2d2d7,color:#1d1d1f
How It Works: A Complete Flow
Here’s what happens when a new engineer joins Credenti:
Step 1: HR system creates user
The HRIS (Workday, BambooHR) adds Alice with department=Engineering. This triggers a webhook to the IdP.
Step 2: IdP pushes to SCIM endpoints
The IdP makes a POST /Users request to every SCIM-connected app:
{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
"userName": "alice@credenti.com",
"name": { "givenName": "Alice", "familyName": "Jones" },
"emails": [{ "value": "alice@credenti.com", "type": "work", "primary": true }],
"active": true,
"urn:ietf:params:scim:schemas:extension:enterprise:2.0:User": {
"department": "Engineering",
"employeeNumber": "12345"
}
}
Step 3: Each app provisions
Slack creates an account, adds Alice to #engineering and #general. GitHub adds her to the engineering team with read access. Zoom creates a licensed account.
Step 4: Lifecycle event
When Alice moves to Product, the IdP sends PATCH /Users/{id} with { "department": "Product" }. Group memberships update automatically. When Alice leaves, PATCH /Users/{id} { "active": false } deactivates every account.
SCIM API Sequence
The SCIM API calls over the wire:
sequenceDiagram
participant IdP as Identity Provider
participant App as SCIM Service<br/>(Credenti)
Note over IdP,App: JOINER
IdP->>App: POST /Users
Note right of App: active: true<br/>department: "Eng"
App-->>IdP: 201 Created
Note over IdP,App: MOVER
IdP->>App: PATCH /Users/{id}
Note right of App: department: "Product"
App-->>IdP: 200 OK
Note over IdP,App: LEAVER
IdP->>App: PATCH /Users/{id}
Note right of App: active: false
App-->>IdP: 200 OK
Core Operations
| Operation | HTTP Method | Endpoint | Lifecycle Event |
|---|---|---|---|
| List users | GET | /Users | IdP sync (discovery) |
| Create user | POST | /Users | Joiner |
| Get user | GET | /Users/{id} | Lookup |
| Update user | PUT | /Users/{id} | Mover (full replace) |
| Patch user | PATCH | /Users/{id} | Mover (partial update) |
| Delete user | DELETE | /Users/{id} | Leaver (hard delete) |
| Deactivate | PATCH | /Users/{id} | Leaver (soft delete via active:false) |
SCIM also supports groups via /Groups and bulk operations via /Bulk for large-scale syncs.
Why SCIM Matters for Security
- Instant deprovisioning — When a user is deactivated in the IdP, SCIM propagates deactivation to every connected app within seconds to minutes. No orphan accounts.
- Least privilege at scale — Entitlements (group memberships, roles) are managed centrally. A role change in the IdP automatically updates access across all apps.
- Audit trail — Every create, update, and delete is logged on both sides.
- JML automation — Joiners, movers, and leavers are handled without IT tickets.
Real-World Adoption
Major identity providers support SCIM out of the box:
- Azure AD / Entra ID — SCIM provisioning for 1000s of gallery apps and custom apps
- Okta — Universal Directory sync with SCIM
- OneLogin — SCIM connector framework
- Google Cloud Identity — SCIM for Google Workspace
- PingIdentity — SCIM-based provisioning
Thousands of SaaS apps expose SCIM endpoints — from Salesforce and ServiceNow to Zoom and Slack. Most enterprise apps in the major cloud marketplaces now require SCIM support.
SCIM 2.0 vs. Custom Integrations
| Aspect | SCIM 2.0 | Custom API Integration |
|---|---|---|
| Standardisation | RFC 7642 – 7643 – 7644 | Proprietary per vendor |
| Time to integrate | Days (known contract) | Weeks to months |
| Maintenance | Minimal (stable spec) | Ongoing (API changes) |
| Tooling | Built into every major IdP | Custom code required |
| Attribute mapping | Standard schema | Ad-hoc per integration |
SCIM is the plumbing that keeps identity consistent across hundreds of SaaS apps. Without it, deprovisioning is manual, slow, and leaky. With it, identity lifecycle management becomes automated, auditable, and secure. In a zero-trust world, knowing exactly who has access to what — and revoking it instantly — is non-negotiable. SCIM makes that possible.