> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SCIM Provisioning

> Provision and deprovision members from Okta to StackOne with SCIM.

Sync members from Okta into StackOne with SCIM. Once the two are linked, assigning a person to the StackOne app in Okta provisions them into your organization, and unassigning or deactivating them removes their access.

## Prerequisites

SCIM Provisioning attaches to an existing SSO connection, so set up SSO first.

* An active SSO connection for your organization, with its domain verified. SCIM Provisioning keys on this connection and can't be enabled without it. See [SSO setup](/secure/identity-and-access/authentication/sso/overview).
* The organization **Admin** role in StackOne, which is required to manage provisioning.
* Admin access to your Okta org to configure the app.

<Info>
  Provisioned members and their Okta SSO logins converge on one StackOne account by email, which is why the SSO connection's domain must be verified. Keep provisioning and SSO on the same verified domain.
</Info>

## Link SCIM in StackOne

<Steps>
  <Step title="Open the Directory Sync card">
    Go to **Organization > Security > SSO**, open your connection, and select the **Provisioning** tab. On the **Directory Sync** card, click **Link SCIM** to open the **Directory Sync** panel.
  </Step>

  <Step title="Copy the SCIM base URL and token">
    In the **SCIM Details** section, copy the **SCIM base URL** and the **Provisioning token**. The token is shown once. Copy it now, because StackOne stores only a hash of it and can't display it again.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/link-scim.png?fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=d5ced928911ec2f083e63cb5182a8e49" alt="The Directory Sync panel showing the SCIM base URL and the masked provisioning token with a Regenerate action." style={{ maxWidth: "360px" }} width="1010" height="678" data-path="images/secure/identity-and-access/provisioning/scim/link-scim.png" />
    </Frame>

    <Note>
      The SCIM base URL ends in `/api/auth/scim/v2`. Copy it from the panel rather than typing it. If the token is ever lost or leaked, reopen the panel with **Edit SCIM** on the **Directory Sync** card, then click **Regenerate** next to the **Provisioning token** and confirm with **Confirm rotate**. Rotating the token swaps the secret only and leaves your provisioned access unchanged, so update Okta with the new token afterward.
    </Note>
  </Step>

  <Step title="Set the provisioned access">
    On the **Provisioned access** card, select **Manage access**. Choose the projects synced members join and a role for each one (**Viewer**, **Member**, or **Admin**), then click **Save changes**. This access is shared with [JIT provisioning](/secure/identity-and-access/provisioning/jit), and every provisioned user still joins your organization at the **Member** role.
  </Step>
</Steps>

## Configure provisioning in Okta

<Steps>
  <Step title="Enable the API integration">
    In your Okta admin console, open the StackOne app you use for SSO and go to the **Provisioning** tab. Click **Configure API Integration** and select **Enable API integration**.
  </Step>

  <Step title="Add the SCIM endpoint and token">
    Paste the **SCIM base URL** from StackOne into **SCIM connector base URL**. Set the authentication mode to **HTTP Header** and paste the **Provisioning token** as the bearer token. Click **Test Connector Configuration** to confirm Okta can reach StackOne, then click **Save**.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-provisioning.png?fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=52dd1248d4a81031a1fdfe04afa06240" alt="Okta, Provisioning > Integration, showing the SCIM Connection with the connector base URL, userName as the unique identifier, Push New Users and Push Profile Updates enabled, and HTTP Header bearer-token authentication." data-og-width="1176" width="1176" data-og-height="1008" height="1008" data-path="images/secure/identity-and-access/provisioning/scim/okta-provisioning.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-provisioning.png?w=280&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=f239fd7c81dcee5a202e5be9cd720091 280w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-provisioning.png?w=560&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=25b61e95e189f5461ffa5ee6fab54404 560w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-provisioning.png?w=840&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=85092a9017408f18b70a9bab0ab48d07 840w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-provisioning.png?w=1100&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=3a0969d1d30d08794c0d4dd83ad80626 1100w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-provisioning.png?w=1650&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=25ec1ff6fc9a49a58f56ead2f5c9d72b 1650w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-provisioning.png?w=2500&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=622e1c4ccd30ab49f98dede0c080ddf6 2500w" />
    </Frame>
  </Step>

  <Step title="Turn on the provisioning actions">
    Under **Provisioning > To App**, click **Edit** and enable **Create Users**, **Update User Attributes**, and **Deactivate Users**. These let Okta create members in StackOne, keep their profiles in sync, and remove access when you unassign or deactivate them.

    <Frame>
      <img src="https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-to-app.png?fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=0fb829be1ce9e995b17b037f466af2d6" alt="Okta, Provisioning > To App, with Create Users, Update User Attributes, and Deactivate Users all enabled." data-og-width="1316" width="1316" data-og-height="908" height="908" data-path="images/secure/identity-and-access/provisioning/scim/okta-to-app.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-to-app.png?w=280&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=701ea6d3f6aef36fefe59dfad0072ab5 280w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-to-app.png?w=560&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=475278f61f9eadf946f185eaedfb5451 560w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-to-app.png?w=840&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=cba98632bb8b51fa55712efb6ad61c91 840w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-to-app.png?w=1100&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=2e38285e1ce602249769df9af54919e9 1100w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-to-app.png?w=1650&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=d6aeeee3746a2f91f17dc5e2db162f15 1650w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/provisioning/scim/okta-to-app.png?w=2500&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=2299fbf93afe7b511746df72d70b767b 2500w" />
    </Frame>
  </Step>
</Steps>

## Assign members in Okta

<Steps>
  <Step title="Assign people to the app">
    Open the **Assignments** tab of the StackOne app and assign the people you want in StackOne. You can assign individuals or Okta groups; in both cases Okta provisions each assigned person into your organization with the default role and projects you set.

    <Info>
      Assigning an Okta group provisions its members as individual users. To bring the group itself into StackOne, with its membership kept in step, push it as well. See [Push groups](#push-groups).
    </Info>
  </Step>

  <Step title="Confirm the sync">
    Return to the **Directory Sync** card in StackOne. The **Synced members** and **Last synced** values update as Okta pushes users, and new members appear in the projects you selected.
  </Step>
</Steps>

## Push groups

Okta's **Group Push** creates the group in StackOne as a synced group and keeps its members in step. Only members who are assigned to the StackOne app, and so already provisioned, are pushed.

<Steps>
  <Step title="Enable Push Groups on the app">
    On the app's **Provisioning** tab, under **Integration**, click **Edit** and make sure **Push Groups** is enabled alongside **Push New Users** and **Push Profile Updates**. Click **Save**.
  </Step>

  <Step title="Push the group">
    Open the app's **Push Groups** tab, click **Push Groups**, and choose **Find groups by name**. Select the Okta group, leave **Push group memberships immediately** on, and click **Save**. To push several groups that share a naming pattern, choose **Find groups by rule** instead.

    Okta creates the group in StackOne. If StackOne already has an empty group with the same name, that group becomes the synced group and keeps its access. See [Prepare the access before you push](/secure/identity-and-access/provisioning/scim/groups#prepare-the-access-before-you-push).
  </Step>

  <Step title="Confirm in StackOne">
    Go to **Organization > Manage Team** and open the **Groups** tab. The group is listed with a **Synced** tag and its pushed members. Assign it to projects from its **Projects** tab.
  </Step>
</Steps>

<Note>
  Okta doesn't support using one group both for app assignment and for Group Push. Assign the app with one group and push a separate group, or the two memberships can fall out of step. See Okta's [App assignments and Group Push](https://help.okta.com/en-us/content/topics/users-groups-profiles/app-assignments-group-push.htm).
</Note>

To rename the group, rename it in Okta. To stop pushing it, choose **Unlink pushed group** on its row in **Push Groups** and pick whether to delete the group in StackOne as well. If you keep it, it stays a synced group in StackOne until you unlink SCIM Provisioning.

## Next steps

<CardGroup cols={2}>
  <Card title="SCIM Provisioning overview" icon="book-open" href="/secure/identity-and-access/provisioning/scim/overview">
    How SCIM provisioning works across identity providers.
  </Card>

  <Card title="Microsoft Entra SCIM Provisioning" icon="https://stackone-logos.com/api/microsoft-entra/filled/svg" href="/secure/identity-and-access/provisioning/scim/microsoft-entra">
    Provision members from Microsoft Entra ID instead.
  </Card>

  <Card title="SCIM Groups" icon="users" href="/secure/identity-and-access/provisioning/scim/groups">
    Push your identity provider's groups into StackOne and grant access through them.
  </Card>
</CardGroup>
