SCIM endpoints enable automated user lifecycle management from your identity provider (Okta, Azure AD, OneLogin, and others). Connect your IdP once and user accounts are created, updated, and deactivated automatically.

Authentication

All SCIM requests require a Bearer token in the Authorization header. The token is org-scoped and managed by org admins:
  • GET /org/scim/token — retrieve the current token
  • POST /org/scim/token — rotate the token

Users

List users

curl https://your-gateway/scim/v2/Users \
  -H "Authorization: Bearer $SCIM_TOKEN"
Supports query parameters: filter, startIndex, count.

Create a user

curl -X POST https://your-gateway/scim/v2/Users \
  -H "Authorization: Bearer $SCIM_TOKEN" \
  -H "Content-Type: application/scim+json" \
  -d '{
    "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
    "userName": "alice@example.com",
    "active": true,
    "name": {
      "givenName": "Alice",
      "familyName": "Smith"
    }
  }'

Get a user

curl https://your-gateway/scim/v2/Users/$USER_ID \
  -H "Authorization: Bearer $SCIM_TOKEN"

Replace a user

curl -X PUT https://your-gateway/scim/v2/Users/$USER_ID \
  -H "Authorization: Bearer $SCIM_TOKEN" \
  -H "Content-Type: application/scim+json" \
  -d '{
    "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
    "userName": "alice@example.com",
    "active": true,
    "name": {"givenName": "Alice", "familyName": "Johnson"}
  }'

Deactivate a user

curl -X PATCH https://your-gateway/scim/v2/Users/$USER_ID \
  -H "Authorization: Bearer $SCIM_TOKEN" \
  -H "Content-Type: application/scim+json" \
  -d '{
    "schemas": ["urn:ietf:params:scim:api:messages:2.0:PatchOp"],
    "Operations": [
      {"op": "replace", "path": "active", "value": false}
    ]
  }'

Delete a user

curl -X DELETE https://your-gateway/scim/v2/Users/$USER_ID \
  -H "Authorization: Bearer $SCIM_TOKEN"

Groups

Groups currently return an empty list. Write operations return 501 Not Implemented. Group management is handled through ManyLayers’ own group and permission system.
curl https://your-gateway/scim/v2/Groups \
  -H "Authorization: Bearer $SCIM_TOKEN"
{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
  "totalResults": 0,
  "Resources": []
}

Error format

SCIM errors use the standard SCIM error schema:
{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"],
  "status": "401",
  "detail": "Bearer token required"
}
All responses use Content-Type: application/scim+json.