How to Configure SCIM Provisioning
Automate user provisioning and deprovisioning from your identity provider using SCIM 2.0.
Overview
SCIM (System for Cross-domain Identity Management) 2.0 lets your identity provider automatically create, update, and deactivate user accounts in Chainsaw. Instead of manually inviting users or relying solely on JIT provisioning, SCIM keeps Chainsaw in sync with your IdP’s user directory.
With SCIM:
- New users are automatically provisioned when added to the Chainsaw app in your IdP
- Deactivated users are automatically disabled and removed from the organization
- Group changes in your IdP update Chainsaw role assignments
- Attribute updates (name, email) are synced automatically
Prerequisites
- Owner or Admin role in Chainsaw
- An IdP that supports SCIM 2.0 outbound provisioning (Okta, Azure AD, OneLogin, CyberArk Identity, etc.)
- SSO is recommended but not required
Step 1: Generate a SCIM Bearer Token
Navigate to Settings > SCIM.
- Enter a descriptive token name (e.g. “Okta SCIM” or “Azure AD Provisioning”)
- Click Generate Token
- Copy the token immediately – it is shown only once
Step 2: Copy the SCIM Base URL
On the same page, copy the SCIM Endpoint URL displayed at the top:
https://chain305.com/chainproxy/scim/v2
You will enter both the token and URL into your IdP in the next step.
Step 3: Configure Your IdP for SCIM Provisioning
Okta
- Navigate to your Chainsaw application in Okta
- Go to the Provisioning tab > Configure API Integration
- Check Enable API integration
- Enter the SCIM Base URL and Bearer Token
- Click Test API Credentials to verify connectivity
- Under Provisioning > To App, enable:
- Create Users
- Update User Attributes
- Deactivate Users
- Go to Assignments and assign users/groups to the application
Azure AD (Entra ID)
- Navigate to Enterprise Applications > your Chainsaw app
- Go to Provisioning > Get started
- Set Provisioning Mode to Automatic
- Under Admin Credentials:
- Tenant URL: your SCIM Base URL
- Secret Token: your SCIM bearer token
- Click Test Connection
- Configure Attribute Mappings (map
userPrincipalNametouserName,mailtoemails[type eq "work"].value) - Set Provisioning Status to On
CyberArk Identity
- Navigate to Apps > Web Apps > your Chainsaw app
- Enable Provisioning in the app settings
- Enter the SCIM Base URL and Bearer Token
- Configure user/group sync settings
- Map CyberArk roles to Chainsaw groups
/chainproxy prefix and ends with /scim/v2 and the bearer token is correct.Step 4: Map SCIM Groups to Chainsaw Roles
SCIM groups in Chainsaw map directly to roles. When your IdP assigns a user to a SCIM group, Chainsaw updates their membership role.
The available groups correspond to Chainsaw’s built-in roles:
| SCIM Group ID | Chainsaw Role |
|---|---|
org-admin | Organization Admin |
org-owner | Organization Owner |
org-manager | Manager |
org-member | Member |
Custom roles are also available as SCIM groups (using their slug as the group ID).
To assign roles via SCIM:
- In your IdP, create groups matching the Chainsaw role names
- Assign users to the appropriate groups
- Push the group assignments via SCIM
Step 5: Verify Provisioning
After configuring your IdP:
- Assign a test user to the Chainsaw application in your IdP
- Wait for the provisioning cycle (Okta: near-instant, Azure AD: up to 40 minutes for first sync)
- Navigate to Settings > Users in Chainsaw and verify the user appears
- Check Settings > SCIM for the Last Used timestamp on your token to confirm API calls are happening
Testing User Lifecycle
| Action in IdP | Expected in Chainsaw |
|---|---|
| Assign user to app | User created with Member role (or group-assigned role) |
| Update user name | User name updated |
| Change group assignment | User role updated |
| Unassign user from app | User deactivated and removed from org |
Supported SCIM Operations
Chainsaw’s SCIM server supports:
| Resource | Operations |
|---|---|
| Users | List (GET with filters), Create (POST), Get (GET), Replace (PUT), Patch (PATCH), Delete (DELETE) |
| Groups | List (GET), Get (GET), Replace (PUT), Patch (PATCH) |
| Filters | userName eq "value", emails.value eq "value", externalId eq "value" |
Troubleshooting
| Issue | Cause | Fix |
|---|---|---|
| Test connection fails | Wrong URL or token | Verify the URL is https://chain305.com/chainproxy/scim/v2 – the /chainproxy prefix is required and /chainsaw/scim/v2 returns a 404 from the static site, not from the API; regenerate token if needed |
| Users not provisioned | IdP provisioning not enabled | Check IdP provisioning settings are “On” with create/update enabled |
| Duplicate user error | User already exists with that email | Existing users are linked automatically on email match |
| Role not updated | Group push not configured | Enable group push in your IdP’s SCIM settings |
| Azure AD slow to sync | Normal first-sync behavior | Initial sync can take 20-40 minutes; subsequent syncs are faster |
Checking SCIM Activity
Monitor the Last Used column on the SCIM tokens page to verify your IdP is making API calls. For detailed troubleshooting, check server logs:
docker logs chainsaw | grep -i "scim"
Best Practices
- Use one SCIM token per IdP – if you have multiple IdPs, create separate tokens
- Name tokens descriptively – e.g. “Okta Production” or “Azure AD Staging”
- Rotate tokens periodically – delete old tokens and generate new ones
- Combine with SSO – SCIM handles provisioning, SSO handles authentication
- Test in staging first – verify user create/update/deactivate cycles before production
- Monitor the token activity – a token that stops being used may indicate a broken integration
Next Steps
- How to Configure SSO/OIDC – Set up SSO alongside SCIM
- How to Configure SAML 2.0 SSO – Use SAML for authentication
- How to Set Up SSO Group-to-Role Mappings – Layer role mappings on top of SCIM
- How to Invite Team Members and Assign Roles – Manual alternative to SCIM