REST API

SCIM 2.0

Automatically create, update, and deactivate users from Okta, Microsoft Entra ID, OneLogin, or JumpCloud.

SCIM (System for Cross-domain Identity Management) automatically carries user changes from your identity provider into the CRM: new hires become CRM users, and people who leave lose access.

Base URL https://<company>.solk.app/api/scim/v2
Authentication Authorization: Bearer <SCIM key>
Resources Users (groups are not synced)
Filter userName eq "…", id eq "…"
Content type application/scim+json

Setup

  1. 1

    Get a SCIM key

    In the CRM, connect the Settings → Apps → Okta / Entra ID (SCIM) (Ayarlar → Uygulamalar → Okta / Entra ID (SCIM)) card. The card shows the base URL and the SCIM key. The key is valid only on SCIM endpoints; you can't use it with the REST API.

  2. 2

    Configure your identity provider

    Okta: Applications → your app → Provisioning → Integration → SCIM connector base URL = the base URL, Unique identifier field = userName, Authentication Mode = HTTP Header, Authorization = the key. In the To App section, enable Create Users, Update User Attributes, and Deactivate Users.

    Microsoft Entra ID: Enterprise applications → your app → Provisioning → Automatic → Tenant URL = the base URL, Secret Token = the key → Test Connection.

  3. 3

    Assign users

    Users you assign to the app in your identity provider are created in the CRM.

Behavior

In the identity provider In the CRM
User assigned The user is created with the sales role, and a password setup invitation is sent to their email.
Name, email, department, or phone changed The user is updated.
User suspended / unassigned (active: false) The user is deactivated: they can't sign in, and their mobile sessions and API keys are revoked. Their records remain.
User deleted (DELETE) The user is deactivated (not deleted).
User reactivated The user is reactivated (requires a free seat on the license).
  • userName is used as the email address in the CRM; a second user with the same email can't be created (409 uniqueness).
  • Roles (admin / sales) and module permissions are assigned in the CRM; SCIM doesn't change them.
  • The last active admin can't be deactivated through SCIM.
  • The department comes from the department field in the SCIM enterprise extension and is used for team visibility.

Example: create a user

curl https://ornek.solk.app/api/scim/v2/Users \
  -H "Authorization: Bearer $SCIM_TOKEN" \
  -H "Content-Type: application/scim+json" \
  -d '{
    "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
    "userName": "ayse.demir@ornekkimya.com.tr",
    "name": { "givenName": "Ayşe", "familyName": "Demir" },
    "emails": [{ "value": "ayse.demir@ornekkimya.com.tr", "primary": true }],
    "active": true,
    "urn:ietf:params:scim:schemas:extension:enterprise:2.0:User": { "department": "Satış" }
  }'

All SCIM endpoints and their real responses are in the reference section: List users, Create a user, Update a user, Deactivate a user.

Errors

SCIM errors use the SCIM format:

{ "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"], "status": "401", "detail": "Geçersiz ya da eksik SCIM anahtarı." }