Provision accounts with SCIM
Let your identity provider (such as Okta or Microsoft Entra ID) create Flowstate accounts and set roles, based on which groups people are in. Adding someone to a group gives them access. Removing them from the group suspends them.
You need to be a Flowstate admin.
Before you start
- Single sign-on: set up and switched on. See Set up OAuth single sign-on. If you sign in with SAML, talk to your Flowstate contact before you set up SCIM.
- One provider, one organisation: if you have more than one single sign-on provider or more than one Flowstate organisation, talk to your Flowstate contact first.
- In your identity provider: someone who can change its provisioning settings.
1. Create a SCIM token
- Go to Settings → Users & Access → SCIM Provisioning and select Create Token.
- Enter a Name, such as “Okta SCIM”.
- Choose an Expiration.
- Create the token and copy it. It’s only shown once.
2. Give each group a role
Do this before your identity provider sends the group, so the group arrives with the role you chose.
- Go to Settings → Organisation → Single Sign On and edit your provider.
- Under Group Mappings, enter the Group Name exactly as your identity provider names it.
- Choose the Organization and the Role.
- Add the mapping. Repeat for every group you’ll send.
Not sure which role to choose? See Roles and permissions.
3. Connect your identity provider
Enter these in your identity provider’s provisioning settings:
| Setting | Value |
|---|---|
| Base URL (Okta) or Tenant URL (Entra ID) | https://<your Flowstate address>/api/scim/v2 |
| Authentication | Bearer token: the token from step 1 |
Then:
- Send the person’s sign-in email as
userName. Flowstate uses it as their email address. - Push groups, not just users. Accounts are only created when people are added to a group.
Okta: on the app’s Provisioning tab, enable API integration, enter the base URL and token, and test the credentials. Under To App, enable creating users and updating user attributes. Push your groups from the Push Groups tab.
Microsoft Entra ID: in your enterprise application, set Provisioning to Automatic, enter the tenant URL and secret token, and test the connection. In the attribute mappings, map userName to the attribute that holds the address people sign in with. Assign your groups to the application, then start provisioning.
4. Check it works
- In your identity provider, add a test person to a mapped group.
- In Flowstate, go to Settings → Users & Access → Users and check they’re listed under Active with the role you mapped.
- Remove them from the group in your identity provider.
- Check they move to Suspended.
Remove someone’s access
Remove the person from their Flowstate groups in your identity provider. Flowstate suspends them. You can also select Suspend User on their row under Settings → Users & Access → Users.
Replace a token
Create a new token, update your identity provider with it, then revoke the old one from its row. Provisioning stops if your identity provider is left with a revoked or expired token.
If something’s not right
People appear in your identity provider’s logs but have no Flowstate account. They aren’t in a pushed group yet. Push the group or add them to it.
Pushing a group fails with “No auth provider configured for this tenant”. No single sign-on provider is switched on. Set one up first.
Someone has the wrong role. Their group’s mapping has a different role. Delete the mapping, add the right one, and push the group again.
Provisioning suddenly stops. The token has expired or been revoked. Create a new one.
For your technical team
- Base URL:
https://<your Flowstate address>/api/scim/v2 - Authentication:
Authorization: Bearer fs_scim_… - Resources:
/Usersand/Groups(GET,POST,PUT,PATCH,DELETE), plus/ServiceProviderConfig,/Schemasand/ResourceTypes. - User attributes read:
userName,externalId,name.givenName,name.familyNameandactive. - Filtering:
eqonly:userNameandexternalIdon/Users,displayNameon/Groups. - Group members: each member’s
valueis the SCIM useridFlowstate returned. - Not supported: bulk operations, sorting, ETags and password changes.