SCIM provisioning
With SCIM, your identity provider tells Updawg who should be a member. Adding somebody to the Updawg application in Okta or Entra ID makes them a member; removing them, or deactivating their account, removes their membership and ends every session they have immediately — nobody has to remember to do it.
SCIM builds on single sign-on: roles come from the same group mappings, and only addresses at your verified domains can be provisioned. Set single sign-on up first.
Connect your provider
Section titled “Connect your provider”Under Settings → Single sign-on → SCIM, an owner issues a token. It is shown once; issuing another replaces it and revoking it stops provisioning. Give your provider:
| SCIM base URL | https://api.updawg.net/scim/v2 |
| Authentication | HTTP header, Bearer token: the scim_… token |
| Unique identifier | userName (the person’s email address) |
In Okta, add SCIM provisioning to the Updawg app and enable Create users, Update user attributes and Deactivate users; push the groups your role mappings name. In Entra ID, set provisioning to Automatic on the enterprise application with the URL and token above, and assign the users and groups.
What it does
Section titled “What it does”- Users: created (or, if the address is already a member, linked) with the role their groups map to, or the default role.
- Groups: pushed groups decide roles through your mappings. Moving somebody between groups changes their role.
- Deactivated or deleted: membership removed and every session ended.
- Owners are never removed or demoted by the provider: that is done by a person in Updawg.
Supported: Users and Groups with create, read, replace, patch and delete;
filtering by userName eq and displayName eq; ServiceProviderConfig,
ResourceTypes and Schemas. Bulk operations, sorting and ETags are not.