> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta Directory Sync

> Provision and deprovision members from Okta to StackOne with SCIM.

Sync members from Okta into StackOne with SCIM. Once the two are linked, assigning a person to the StackOne app in Okta provisions them into your organization, and unassigning or deactivating them removes their access.

## Prerequisites

Directory Sync attaches to an existing SSO connection, so set up SSO first.

* An active SSO connection for your organization, with its domain verified. Directory Sync keys on this connection and can't be enabled without it. See [SSO setup](/identity/sso/overview).
* The **Org Admin** role in StackOne, which is required to manage provisioning.
* Admin access to your Okta org to configure the app.

<Info>
  Provisioned members and their Okta SSO logins converge on one StackOne account by email, which is why the SSO connection's domain must be verified. Keep provisioning and SSO on the same verified domain.
</Info>

<Note>
  The **Provisioning** tab is turned on per organization. If you don't see it on your SSO connection, even as an Org Admin, contact StackOne support to enable it.
</Note>

## Link SCIM in StackOne

<Steps>
  <Step title="Open Directory Sync">
    Go to **Organization > Security > SSO**, open your connection, and select the **Provisioning** tab. On the **Directory Sync** card, click **Link SCIM** to open the **Directory Sync** panel.
  </Step>

  <Step title="Copy the SCIM base URL and token">
    In the **SCIM Details** section, copy the **SCIM base URL** and the **Provisioning token**. The token is shown once. Copy it now, because StackOne stores only a hash of it and can't display it again.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/link-scim.png?fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=52f3c8cab90333356e1416bd2717dd77" alt="The Directory Sync panel showing the SCIM base URL and the masked provisioning token with a Regenerate action." style={{ maxWidth: "360px" }} width="1010" height="678" data-path="images/identity/scim/link-scim.png" />
    </Frame>

    <Note>
      The SCIM base URL ends in `/api/auth/scim/v2`. Copy it from the panel rather than typing it. If the token is ever lost or leaked, reopen the panel with **Edit SCIM** on the **Directory Sync** card, then click **Regenerate** next to the **Provisioning token** and confirm with **Confirm rotate**. Rotating the token swaps the secret only and leaves your provisioned access unchanged, so update Okta with the new token afterward.
    </Note>
  </Step>

  <Step title="Set the provisioned access">
    On the **Provisioned access** card, select **Manage access**. Choose the projects synced members join and a role for each one (**Viewer**, **Member**, or **Admin**), then click **Save changes**. This access is shared with [JIT provisioning](/identity/sso/jit-provisioning), and every provisioned user still joins your organization at the **Viewer** role.
  </Step>
</Steps>

## Configure provisioning in Okta

<Steps>
  <Step title="Enable the API integration">
    In your Okta admin console, open the StackOne app you use for SSO and go to the **Provisioning** tab. Click **Configure API Integration** and select **Enable API integration**.
  </Step>

  <Step title="Add the SCIM endpoint and token">
    Paste the **SCIM base URL** from StackOne into **SCIM connector base URL**. Set the authentication mode to **HTTP Header** and paste the **Provisioning token** as the bearer token. Click **Test Connector Configuration** to confirm Okta can reach StackOne, then click **Save**.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-provisioning.png?fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=2fd42ea38ff121cfd7f4268e2ca268ce" alt="Okta, Provisioning > Integration, showing the SCIM Connection with the connector base URL, userName as the unique identifier, Push New Users and Push Profile Updates enabled, and HTTP Header bearer-token authentication." data-og-width="1176" width="1176" data-og-height="1008" height="1008" data-path="images/identity/scim/okta-provisioning.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-provisioning.png?w=280&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=5e6ff2a375f063f35fcc99d50ea38e87 280w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-provisioning.png?w=560&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=4b0c2bcbb30a7ebec9aa9a76dcdcf911 560w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-provisioning.png?w=840&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=4fd08652b335fc844c8526b0fb246c43 840w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-provisioning.png?w=1100&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=edf80ae2f2387e0ad163d527ac1b4bf4 1100w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-provisioning.png?w=1650&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=639ed5f98e21b74d25dbef24cda76f7c 1650w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-provisioning.png?w=2500&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=adf2b25054d6d8fda24dfe5f6908df83 2500w" />
    </Frame>
  </Step>

  <Step title="Turn on the provisioning actions">
    Under **Provisioning > To App**, click **Edit** and enable **Create Users**, **Update User Attributes**, and **Deactivate Users**. These let Okta create members in StackOne, keep their profiles in sync, and remove access when you unassign or deactivate them.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-to-app.png?fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=8879853a58ff71f1b221e30518954937" alt="Okta, Provisioning > To App, with Create Users, Update User Attributes, and Deactivate Users all enabled." data-og-width="1316" width="1316" data-og-height="908" height="908" data-path="images/identity/scim/okta-to-app.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-to-app.png?w=280&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=ccc669cea3adffb27f03252f5e80041a 280w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-to-app.png?w=560&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=1df1902fa54426ec439fbb6b6a911112 560w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-to-app.png?w=840&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=e25f949f1b7e826f2378fff32743a54b 840w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-to-app.png?w=1100&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=2cb2d6e175c34829587b449f963c24d9 1100w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-to-app.png?w=1650&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=bdde7e7252c80ed95010553e14b5d1b7 1650w, https://mintcdn.com/stackone-60/UkwbfeWWnEleiUW3/images/identity/scim/okta-to-app.png?w=2500&fit=max&auto=format&n=UkwbfeWWnEleiUW3&q=85&s=49ca34a2ecd8ed16ef6f9ad585d9f6f0 2500w" />
    </Frame>
  </Step>
</Steps>

## Assign members in Okta

<Steps>
  <Step title="Assign people to the app">
    Open the **Assignments** tab of the StackOne app and assign the people you want in StackOne. You can assign individuals or Okta groups; in both cases Okta provisions each assigned person into your organization with the default role and projects you set.

    <Info>
      Directory Sync provisions users only. Assigning an Okta group provisions its members as individual users; the group itself and its membership don't sync into StackOne. Group sync isn't available yet.
    </Info>
  </Step>

  <Step title="Confirm the sync">
    Return to the **Directory Sync** card in StackOne. The **Synced members** and **Last synced** values update as Okta pushes users, and new members appear in the projects you selected.
  </Step>
</Steps>

## Next steps

<CardGroup cols={2}>
  <Card title="Directory Sync overview" icon="book-open" href="/identity/scim/overview">
    How SCIM provisioning works across identity providers.
  </Card>

  <Card title="Microsoft Entra Directory Sync" icon="microsoft" iconType="brands" href="/identity/scim/microsoft-entra">
    Provision members from Microsoft Entra ID instead.
  </Card>
</CardGroup>
