> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SCIM Provisioning

> Connect Okta to StackOne with SCIM, assign users, and push Okta groups.

export const idp_0 = "Okta"

Sync users from Okta, your identity provider (IdP), into StackOne with SCIM. Once linked, assigning a person to the StackOne app in Okta adds them to the organization, and unassigning or deactivating them removes their access.

For what happens to users once SCIM Provisioning is running, see the [SCIM Provisioning overview](/secure/identity-and-access/manage-team/scim/overview).

Before setting up SCIM Provisioning, you need:

* A verified SSO connection between the organization and {idp_0}. See [Single Sign-On](/secure/identity-and-access/authentication/sso/overview).
* The **Organization Admin** role in StackOne.
* Admin access to the StackOne application in {idp_0}.
* (Optional) {idp_0} set up to send `admin` in the SCIM `roles` field for anyone who should join as an **Organization Admin**. Everyone else joins as an **Organization Member**. See [Organization Roles](/secure/identity-and-access/roles-and-groups/organization-roles).

<Note>
  The `roles` value only counts when a user first joins. After that, their role can only be changed in StackOne.
</Note>

<Warning>
  SCIM Provisioning only adds users whose email is on the organization's verified domain. Anyone else, including everyone assigned before the domain is verified, shows as an error in {idp_0}'s provisioning log.
</Warning>

## Link SCIM in StackOne

<Steps>
  <Step title="Open the SSO connection">
    1. In the StackOne dashboard, go to [**Organization > Security > SSO**](https://app.stackone.com/organization/security/sso).
    2. Open the verified SSO connection.
    3. Select the **Provisioning** tab.
  </Step>

  <Step title="Choose projects and roles">
    1. On the **Provisioned access** card, select **Manage access**.
    2. Pick the projects new users should join.
    3. Choose a role for each one. See [Project Roles](/secure/identity-and-access/roles-and-groups/project-roles).
    4. Select **Save changes**.

    Provisioned access applies to users added by both Just-in-Time Provisioning and SCIM Provisioning.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/provisioned-access.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=bff3ca2a885673e15f0e02197d3c9b40" alt="The Provisioned access panel with a project checked and its own role dropdown set to Viewer, and a note that the organization role is set separately." style={{ maxWidth: "440px" }} width="1010" height="758" data-path="images/secure/identity-and-access/manage-team/provisioned-access.png" />
    </Frame>
  </Step>

  <Step title="Link SCIM and copy the credentials">
    1. On the **Directory Sync** card, select **Link SCIM**.
    2. In the **SCIM Details** section, copy the **SCIM base URL** and the **Provisioning token**. You paste both into the IdP.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/directory-sync-card.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=b70bdadae2fa7b4c72427f4125499345" alt="The Provisioning tab on an SSO connection, showing the Provisioned access, Just-in-time provisioning, and Directory Sync cards with their Manage access, Enable JIT, and Link SCIM actions." width="1064" height="1135" data-path="images/secure/identity-and-access/manage-team/scim/directory-sync-card.png" />
    </Frame>

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/link-scim.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=f8c07363f93fe8ea7aaca98261a7c710" alt="The Directory Sync panel showing the SCIM base URL and the masked provisioning token with a Regenerate action." style={{ maxWidth: "360px" }} width="1010" height="678" data-path="images/secure/identity-and-access/manage-team/scim/link-scim.png" />
    </Frame>

    <Warning>
      The token is only shown once. Store it somewhere safe before you close the panel. To replace a lost or leaked token, see [Rotate the token](/secure/identity-and-access/manage-team/scim/overview#rotate-the-token).
    </Warning>
  </Step>
</Steps>

## Configure provisioning in Okta

<Steps>
  <Step title="Enable the API integration">
    1. In the Okta admin console, go to **Applications > Applications** and open the app you created for StackOne SSO.
    2. Go to the **Provisioning** tab.
    3. Click **Configure API Integration**.
    4. Select **Enable API integration**.
  </Step>

  <Step title="Add the SCIM endpoint and token">
    1. Set the following:
       * **SCIM connector base URL**: the **SCIM base URL** from StackOne.
       * **Unique identifier field for users**: `userName`.
       * **Supported provisioning actions**: `Push New Users` and `Push Profile Updates`.
       * **Authentication Mode**: `HTTP Header`.
       * **Authorization**: the **Provisioning token** from StackOne.
    2. Click **Test Connector Configuration** to confirm Okta can reach StackOne.
    3. Click **Save**.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-provisioning.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=6f42d283edb9f84a10e616dfa9550bb4" alt="Okta, Provisioning > Integration, showing the SCIM Connection with the connector base URL, userName as the unique identifier, Push New Users and Push Profile Updates enabled, and HTTP Header bearer-token authentication." data-og-width="1176" width="1176" data-og-height="1008" height="1008" data-path="images/secure/identity-and-access/manage-team/scim/okta-provisioning.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-provisioning.png?w=280&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=ba80e0595ee1c6f419f4b654dbc3d023 280w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-provisioning.png?w=560&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=fb7a32c74e3d3b1b31965e458311264e 560w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-provisioning.png?w=840&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=f10221cf50668d3f01b76d768f978c56 840w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-provisioning.png?w=1100&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=02bd5d0523b380d8d9f26e976dfcce18 1100w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-provisioning.png?w=1650&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=1f68849c8fc3a55d8eb3240ef75d05f8 1650w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-provisioning.png?w=2500&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=96edb4d31eb99961b7fbef434a4b303c 2500w" />
    </Frame>
  </Step>

  <Step title="Turn on the provisioning actions">
    1. Under **Provisioning > To App**, click **Edit**.
    2. Enable **Create Users**, **Update User Attributes**, and **Deactivate Users**.
    3. Click **Save**.

    These let Okta create members in StackOne, keep their profiles in sync, and remove access when you unassign or deactivate them.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-to-app.png?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=7778bf735679a6a95486ded228d2e6e1" alt="Okta, Provisioning > To App, with Create Users, Update User Attributes, and Deactivate Users all enabled." data-og-width="1316" width="1316" data-og-height="908" height="908" data-path="images/secure/identity-and-access/manage-team/scim/okta-to-app.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-to-app.png?w=280&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=9f7971fef4e991141682679dbefebad0 280w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-to-app.png?w=560&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=614d49c924e4553c047c8476cc59fa91 560w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-to-app.png?w=840&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=fd10430801439fe2979e6f2666e667be 840w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-to-app.png?w=1100&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=4b85fd85b793eb88f2da41be619eabb4 1100w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-to-app.png?w=1650&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=7c89f9d9ea52fd2ff3d9792b5e787740 1650w, https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/manage-team/scim/okta-to-app.png?w=2500&fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=510866744ec6b7f0b59c72bf9aa144a5 2500w" />
    </Frame>
  </Step>
</Steps>

## Assign members in Okta

<Steps>
  <Step title="Assign people to the app">
    1. Open the **Assignments** tab of the StackOne app.
    2. Assign the people you want in StackOne.

    You can assign individuals or Okta groups. Either way, Okta adds each assigned person to the organization, with their organization role and provisioned access.

    <Info>
      Assigning an Okta group provisions its members as individual users. To bring the group itself into StackOne, with its membership kept in step, push it as well. See [Push groups](#push-groups).
    </Info>
  </Step>

  <Step title="Confirm the sync">
    Return to the **Directory Sync** card in StackOne. The **Synced members** and **Last synced** values update as Okta pushes users, and new members appear in the projects you selected.
  </Step>
</Steps>

## Push groups

Okta's **Group Push** creates the group in StackOne as a synced group and keeps its members in step. Only members who are assigned to the StackOne app, and so already provisioned, are pushed.

<Note>
  If StackOne already has a group with the same name, an empty one becomes the synced group and keeps its access.

  If the group has members, it's left untouched, and StackOne creates a second, synced group with the same name instead. To set up a group's access before anyone is pushed into it, see [Prepare the access before you push](/secure/identity-and-access/manage-team/scim/groups#prepare-the-access-before-you-push).
</Note>

<Steps>
  <Step title="Enable Push Groups on the app">
    1. On the app's **Provisioning** tab, under **Integration**, click **Edit**.
    2. Make sure **Push Groups** is enabled alongside **Push New Users** and **Push Profile Updates**.
    3. Click **Save**.
  </Step>

  <Step title="Push the group">
    1. Open the app's **Push Groups** tab.
    2. Click **Push Groups**, and choose **Find groups by name**. To push several groups that share a naming pattern, choose **Find groups by rule** instead.
    3. Select the Okta group, and leave **Push group memberships immediately** on.
    4. Click **Save**.

    Okta creates the group in StackOne.
  </Step>

  <Step title="Confirm in StackOne">
    1. Go to [**Organization > Manage Team**](https://app.stackone.com/organization/manage_team) and open the **Groups** tab. The group is listed with a **Synced** tag and its pushed members.
    2. Assign it to projects from its **Projects** tab.
  </Step>
</Steps>

<Note>
  Use different Okta groups for assigning the app and for Group Push. For example, assign the app to ***StackOne Users*** and push ***Finance***. Okta doesn't support using one group for both, and the group's members in StackOne can end up different from Okta's. See Okta's [App assignments and Group Push](https://help.okta.com/en-us/content/topics/users-groups-profiles/app-assignments-group-push.htm).
</Note>

After a group is pushed:

* **To rename it**, rename it in Okta.
* **To stop pushing it**:

  1. On the **Push Groups** tab, choose **Unlink pushed group** on the group's row.
  2. Choose whether to also delete the group in StackOne.

  A group you keep stays a synced group in StackOne until you unlink SCIM Provisioning.

## Next steps

<CardGroup cols={2}>
  <Card title="SCIM Provisioning" icon="book-open" href="/secure/identity-and-access/manage-team/scim/overview">
    How SCIM provisioning works across identity providers.
  </Card>

  <Card title="Microsoft Entra SCIM Provisioning" icon="https://stackone-logos.com/api/microsoft-entra/filled/svg" href="/secure/identity-and-access/manage-team/scim/microsoft-entra">
    Provision members from Microsoft Entra ID instead.
  </Card>

  <Card title="SCIM Groups" icon="users" href="/secure/identity-and-access/manage-team/scim/groups">
    Push the identity provider's groups into StackOne and grant access through them.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.