Capabilities

Enterprise-Grade SCIM

A complete, production-grade SCIM 2.0 connector with deep operator tooling, customer self-service, and airtight security.

SCIM Protocol

👤 User Provisioning

Full user lifecycle: create, read, update, deactivate. Attribute mapping, external ID tracking, and idempotent operations.

👥 Group Sync

Group create, update, membership add/remove, and delete. Handles large membership sets with robust filtering.

🔍 Filtering & Pagination

SCIM filter support (userName eq, externalId eq, displayName eq), sorted paginated responses.

🔄 Reconciliation

Background consistency checks detect drift between IdP state and connector state. Dry-run preview before applying fixes.

📊 Audit Events

Every SCIM operation emits a structured audit event with actor, tenant, resource, outcome, and timestamp.

⚙ ServiceProviderConfig

Standards-compliant capability discovery endpoint for automated IdP configuration.

Operator Tooling

🏢 Multi-Tenant

Full tenant isolation per customer. Separate credentials, data scoping, and audit streams per tenant.

🔐 Token Management

Generate, rotate, and revoke SCIM bearer tokens per tenant from the operator dashboard.

📅 Job Scheduling

Schedule background sync jobs, reconciliation runs, and health checks on configurable intervals.

Compatibility

FeatureStatusNotes
SCIM 2.0 (RFC 7643/7644)✓ Complete
Filter (eq operator)userName, externalId, displayName, id
PaginationstartIndex/count consistent
Multi-tenancyFull isolation per tenant
Okta SCIM integrationTested and compatible
Azure AD / Entra IDCompatible via SCIM 2.0

Ready to see it in action?

Talk to us about your identity stack and provisioning requirements.

Request a Demo