# SCIM 2.0

> Automatically create, update, and deactivate users from Okta, Microsoft Entra ID, OneLogin, or JumpCloud.

SCIM (System for Cross-domain Identity Management) automatically carries user changes from your identity provider into the CRM: new hires become CRM users, and people who leave lose access.

| | |
|---|---|
| Base URL | `https://<company>.solk.app/api/scim/v2` |
| Authentication | `Authorization: Bearer <SCIM key>` |
| Resources | `Users` (groups are not synced) |
| Filter | `userName eq "…"`, `id eq "…"` |
| Content type | `application/scim+json` |

## Setup

:::steps
### Get a SCIM key

In the CRM, connect the **Settings → Apps → Okta / Entra ID (SCIM)** (*Ayarlar → Uygulamalar → Okta / Entra ID (SCIM)*) card. The card shows the base URL and the SCIM key. The key is valid only on SCIM endpoints; you can't use it with the REST API.

### Configure your identity provider

**Okta:** Applications → your app → Provisioning → Integration → *SCIM connector base URL* = the base URL, *Unique identifier field* = `userName`, *Authentication Mode* = HTTP Header, *Authorization* = the key. In the **To App** section, enable *Create Users*, *Update User Attributes*, and *Deactivate Users*.

**Microsoft Entra ID:** Enterprise applications → your app → Provisioning → Automatic → *Tenant URL* = the base URL, *Secret Token* = the key → **Test Connection**.

### Assign users

Users you assign to the app in your identity provider are created in the CRM.
:::

## Behavior

| In the identity provider | In the CRM |
|---|---|
| User assigned | The user is created with the **sales** role, and a password setup invitation is sent to their email. |
| Name, email, department, or phone changed | The user is updated. |
| User suspended / unassigned (`active: false`) | The user is deactivated: they can't sign in, and their mobile sessions and API keys are revoked. Their records remain. |
| User deleted (`DELETE`) | The user is deactivated (not deleted). |
| User reactivated | The user is reactivated (requires a free seat on the license). |

- `userName` is used as the email address in the CRM; a second user with the same email can't be created (`409 uniqueness`).
- Roles (admin / sales) and module permissions are assigned in the CRM; SCIM doesn't change them.
- The last active admin can't be deactivated through SCIM.
- The department comes from the `department` field in the SCIM enterprise extension and is used for [team visibility](/users-and-roles#visibility).

## Example: create a user

```bash
curl https://ornek.solk.app/api/scim/v2/Users \
  -H "Authorization: Bearer $SCIM_TOKEN" \
  -H "Content-Type: application/scim+json" \
  -d '{
    "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
    "userName": "ayse.demir@ornekkimya.com.tr",
    "name": { "givenName": "Ayşe", "familyName": "Demir" },
    "emails": [{ "value": "ayse.demir@ornekkimya.com.tr", "primary": true }],
    "active": true,
    "urn:ietf:params:scim:schemas:extension:enterprise:2.0:User": { "department": "Satış" }
  }'
```

All SCIM endpoints and their real responses are in the reference section: [List users](/rest-api/scim/users-list), [Create a user](/rest-api/scim/users-create), [Update a user](/rest-api/scim/users-update), [Deactivate a user](/rest-api/scim/users-delete).

## Errors

SCIM errors use the SCIM format:

```json
{ "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"], "status": "401", "detail": "Geçersiz ya da eksik SCIM anahtarı." }
```