API: SCIM
SCIM 2.0 provisioning of members and groups by an identity provider, and the SCIM tokens a company admin creates for it. All endpoints require authentication unless noted. 18 endpoints.
GET /api/scim/tokens
Section titled “GET /api/scim/tokens”This company’s SCIM tokens and base URL
Responses: 200 · 400 · 401 · 404
POST /api/scim/tokens
Section titled “POST /api/scim/tokens”Create a SCIM token (shown once)
Request body (JSON)
| Field | Type | Required | Description |
|---|---|---|---|
name |
string | yes | |
workspaceId |
string | yes | Where provisioned members get their viewer seat |
Responses: 201 · 400 · 401 · 409
DELETE /api/scim/tokens/{id}
Section titled “DELETE /api/scim/tokens/{id}”Revoke a SCIM token
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Responses: 200 · 400 · 401 · 404
GET /api/scim/v2/Groups
Section titled “GET /api/scim/v2/Groups”List or find groups (filter: displayName, externalId, id, members.value eq …)
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
filter |
string | no | |
startIndex |
integer | no | |
count |
integer | no | |
excludedAttributes |
string | no |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
POST /api/scim/v2/Groups
Section titled “POST /api/scim/v2/Groups”Push a group into the token’s workspace
Responses: 201 · 400 · 401 · 403 · 404 · 409 · 500
GET /api/scim/v2/Groups/{id}
Section titled “GET /api/scim/v2/Groups/{id}”Get a group
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
excludedAttributes |
string | no |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
PUT /api/scim/v2/Groups/{id}
Section titled “PUT /api/scim/v2/Groups/{id}”Replace a group
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
PATCH /api/scim/v2/Groups/{id}
Section titled “PATCH /api/scim/v2/Groups/{id}”Update a group (rename, add / remove / replace members)
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Request body (JSON)
| Field | Type | Required | Description |
|---|---|---|---|
Operations |
array of object | yes |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
DELETE /api/scim/v2/Groups/{id}
Section titled “DELETE /api/scim/v2/Groups/{id}”Delete a group
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Responses: 204 — No content · 400 · 401 · 403 · 404 · 409 · 500
GET /api/scim/v2/ResourceTypes
Section titled “GET /api/scim/v2/ResourceTypes”SCIM resource types
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
GET /api/scim/v2/Schemas
Section titled “GET /api/scim/v2/Schemas”SCIM schemas
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
GET /api/scim/v2/ServiceProviderConfig
Section titled “GET /api/scim/v2/ServiceProviderConfig”SCIM service provider configuration
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
GET /api/scim/v2/Users
Section titled “GET /api/scim/v2/Users”List or find users (filter: userName, externalId, emails.value, id eq …)
Query parameters
| Name | Type | Required | Description |
|---|---|---|---|
filter |
string | no | |
startIndex |
integer | no | |
count |
integer | no |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
POST /api/scim/v2/Users
Section titled “POST /api/scim/v2/Users”Provision a user
Responses: 201 · 400 · 401 · 403 · 404 · 409 · 500
GET /api/scim/v2/Users/{id}
Section titled “GET /api/scim/v2/Users/{id}”Get a user
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
PUT /api/scim/v2/Users/{id}
Section titled “PUT /api/scim/v2/Users/{id}”Replace a user
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
PATCH /api/scim/v2/Users/{id}
Section titled “PATCH /api/scim/v2/Users/{id}”Update a user (active, name, email, externalId)
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Request body (JSON)
| Field | Type | Required | Description |
|---|---|---|---|
Operations |
array of object | yes |
Responses: 200 · 400 · 401 · 403 · 404 · 409 · 500
DELETE /api/scim/v2/Users/{id}
Section titled “DELETE /api/scim/v2/Users/{id}”Remove a user from this organization
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id |
string | yes |
Responses: 204 — No content · 400 · 401 · 403 · 404 · 409 · 500