Authentication
All SCIM requests require a Bearer token in theAuthorization header. The token is org-scoped and managed by org admins:
GET /org/scim/token— retrieve the current tokenPOST /org/scim/token— rotate the token
Users
List users
filter, startIndex, count.
Create a user
Get a user
Replace a user
Deactivate a user
Delete a user
Groups
Groups currently return an empty list. Write operations return 501 Not Implemented. Group management is handled through ManyLayers’ own group and permission system.Error format
SCIM errors use the standard SCIM error schema:Content-Type: application/scim+json.