Skip to main content
Requires a Keeper Enterprise plan with the email domain reserved, since Keeper only accepts SCIM provisioning for reserved domains. Keeper shows a SCIM token once, when it is generated; if your identity provider already uses the node’s SCIM token, generating a new one replaces it, so update your identity provider with the new token too.

Get the SCIM token and node ID

A Keeper Administrator sets up SCIM provisioning on the node that holds the users you want to review. A node’s SCIM method does not control its sub-nodes, so users in sub-nodes may not be included. A sub-node can have its own SCIM method.

1

Open the node

In the Keeper Admin Console, go to Admin and select the node to review.

2

Add or open the SCIM method

Open the node’s Provisioning tab. Select Add Method > SCIM (System for Cross-Domain Identity Management) and click Next, or edit the existing SCIM method.

3

Copy the node ID

The SCIM URL on that page ends with the node ID, for example https://keepersecurity.com/api/rest/scim/v2/1234567890. Copy the number after /v2/.

4

Generate and save the token

Click Generate, copy the token, then click Save right away.

  • The token can create and lock users in Keeper, though this connector only reads with it.
5

Pick the data center

Select the data center that matches the domain in your SCIM URL.

Linking the Account from the Hub

1

Navigate to the Hub

Use one of the three Linking Account Methods to access the Hub.
2

Fill out the fields

Fill out the following fields using details from your provider:
  • SCIM Token
  • Node ID
  • Data Center
3

Connect

  • Click Connect
  • If applicable, the provider will redirect you to a sign-in or authorization page. Complete the provider’s authorization flow.
  • Once authorization is successful, you will see a confirmation popup

If the account linking is successful, you will see the newly linked account in your Accounts page.