How to manage users with SCIM
System for Cross-domain Identity Management (SCIM) is a standard protocol for exchanging user identity and authorization data between an Identity Provider (IdP) and a Service Provider.
Combined with SAML, it allows IAM managers to fully manage user authentication, lifecycle, and personal data through their Identity Provider:
- SAML is used for members to log in by authenticating on their Identity Provider with the IdP-defined authentication policies
- SCIM is used to automatically create, update, lock, unlock, and delete Scaleway users based on actions performed on the user directory of the Identity Provider
Before you start
To complete the actions presented below, you must have:
- A Scaleway account logged into the console
- Owner status or IAM permissions allowing you to perform actions in the intended Organization
How to enable SCIM
- Click the Settings button in the upper-right corner of the Organization Dashboard. The Organization Settings page displays. Alternatively, click the avatar icon in the upper-right corner of the header navigation, then select Settings on the drop-down menu.
- Click Automatic user provisioning (SCIM), under Organization security, on the left navigation menu. The SCIM section displays.
- Click the Enable button. A pop-up displays, informing you that a token creation is required to enable SCIM.
- Click the Enable SCIM and create token button. SCIM is now enabled for the Organization, and two fields are displayed and must be copied:
- A SCIM token, which is used by the Identity Provider to authenticate to Scaleway and perform the necessary actions. This token is sensitive and should not be shared with anyone.
- A base URL, which is used by the Identity Provider to locate the Scaleway account to which connect.
- Click Close. The configuration is complete on the Scaleway side, but you now need to carry out the SCIM setup on your Identity provider.
Depending on the provider, changes might take from a few seconds to up to 30 minutes to be synchronized. This delay cannot be modified by Scaleway.
How to rotate a SCIM token
You can have up to two active SCIM tokens at a time. To create a second token:
- Click the Settings button in the upper-right corner of the Organization Dashboard. The Organization Settings page displays.
- Click Automatic user provisioning (SCIM), under Organization security, on the left navigation menu. The SCIM section displays.
- Click Generate token. A pop-up displays.
- Follow the same steps for first enabling SCIM.
-
Check if the SCIM configuration is still working.
Optionally, you can delete the previous token if no longer necessary.
How to disable SCIM
- Click the Settings button in the upper-right corner of the Organization Dashboard. The Organization Settings page displays.
- Click Automatic user provisioning (SCIM), under Organization security, on the left navigation menu. The SCIM section displays.
- Click the Disable button.
- Type Disable to confirm.
See Also
Still need help?Create a support ticket