Skip to content

Overview

SCIM provisioning

Use SCIM provisioning to let your identity provider create, update and deactivate the SurrealDB accounts of a single sign-on connection. SCIM (System for Cross-domain Identity Management) is a standard protocol that identity providers use to keep user accounts in other apps up to date.

Without SCIM, SurrealDB makes an account the first time a person signs in, and the account stays until you disable it. With SCIM, your identity provider tells SurrealDB when a person joins, changes or leaves, so an account that you disable in your identity provider stops working in SurrealDB too.

You need:

  • A single sign-on connection that works.

  • Permission to update identity providers in your enterprise.

  • An identity provider that supports SCIM 2.0, and access to its admin console.

SCIM is available for these connection types:

Connection typeSCIM
OktaAvailable
Microsoft Entra IDAvailable
SAMLAvailable
OpenID ConnectAvailable
Google Workspace, ADFS, PingFederate, KeycloakNot available
  1. Open Single sign-on in your enterprise.

  2. Open the connection.

  3. Open the Provisioning tab.

  4. Turn on SCIM provisioning.

Studio then shows the SCIM base URL for the connection. Each connection has its own URL.

Your identity provider uses a bearer token to prove that it may change accounts.

  1. On the Provisioning tab, select Create token.

  2. Copy the token.

  3. Select Done.

Warning

Studio shows the token one time only. Copy it before you select Done or leave the page. Anyone who has the token can create and deactivate accounts on this connection, so keep it in a secure place.

Each identity provider sets up SCIM in its own way, and each one must send the user ID that matches the identity people sign in with. Follow the instructions for your provider:

Identity providerInstructions
OktaProvision users from Okta
Microsoft Entra IDProvision users from Entra ID
Another SAML providerProvision users over a SAML connection
Another OpenID Connect providerProvision users over an OpenID Connect connection
Important

If the user ID that your identity provider sends over SCIM is different from the one it sends at sign-in, the person gets a second account the first time they sign in. Each provider's instructions say which attribute to send.

Change in your identity providerResult in SurrealDB
A person is assigned to the appSurrealDB makes their account. They join the enterprise the first time they sign in.
A person's name or email changesSurrealDB updates their account.
A person is deactivated or unassignedSurrealDB disables their login and ends their sessions. The Members page shows them as Disabled.
A person is activated againSurrealDB enables their login again.
A person is deletedSurrealDB deletes their account.

SCIM does not assign roles. A new member holds no roles until you grant them.

A connection holds up to two tokens at a time. To replace a token without a gap in provisioning:

  1. Create a new token.

  2. Give the new token to your identity provider.

  3. Beside the old token, select Revoke token.

The Provisioning tab shows when each token was last used, which helps you find a token that nothing uses any more.

Turn off SCIM provisioning on the Provisioning tab. SurrealDB revokes every token of the connection, and your identity provider can no longer change accounts. The accounts that SCIM made stay, and people can still sign in through the connection.

  • Single sign-on: Connect your identity provider and route people to it.

  • Members: Who belongs to the enterprise, and how to disable a login.

  • Roles: What a member may administer once they have signed in.

Was this page helpful?