Documentation Get help

Provision accounts with SCIM

Let your identity provider (such as Okta or Microsoft Entra ID) create Flowstate accounts and set roles, based on which groups people are in. Adding someone to a group gives them access. Removing them from the group suspends them.

You need to be a Flowstate admin.

Before you start

  • Single sign-on: set up and switched on. See Set up OAuth single sign-on. If you sign in with SAML, talk to your Flowstate contact before you set up SCIM.
  • One provider, one organisation: if you have more than one single sign-on provider or more than one Flowstate organisation, talk to your Flowstate contact first.
  • In your identity provider: someone who can change its provisioning settings.

1. Create a SCIM token

  1. Go to Settings → Users & Access → SCIM Provisioning and select Create Token.
  2. Enter a Name, such as “Okta SCIM”.
  3. Choose an Expiration.
  4. Create the token and copy it. It’s only shown once.

2. Give each group a role

Do this before your identity provider sends the group, so the group arrives with the role you chose.

  1. Go to Settings → Organisation → Single Sign On and edit your provider.
  2. Under Group Mappings, enter the Group Name exactly as your identity provider names it.
  3. Choose the Organization and the Role.
  4. Add the mapping. Repeat for every group you’ll send.

Not sure which role to choose? See Roles and permissions.

3. Connect your identity provider

Enter these in your identity provider’s provisioning settings:

SettingValue
Base URL (Okta) or Tenant URL (Entra ID)https://<your Flowstate address>/api/scim/v2
AuthenticationBearer token: the token from step 1

Then:

  • Send the person’s sign-in email as userName. Flowstate uses it as their email address.
  • Push groups, not just users. Accounts are only created when people are added to a group.

Okta: on the app’s Provisioning tab, enable API integration, enter the base URL and token, and test the credentials. Under To App, enable creating users and updating user attributes. Push your groups from the Push Groups tab.

Microsoft Entra ID: in your enterprise application, set Provisioning to Automatic, enter the tenant URL and secret token, and test the connection. In the attribute mappings, map userName to the attribute that holds the address people sign in with. Assign your groups to the application, then start provisioning.

4. Check it works

  1. In your identity provider, add a test person to a mapped group.
  2. In Flowstate, go to Settings → Users & Access → Users and check they’re listed under Active with the role you mapped.
  3. Remove them from the group in your identity provider.
  4. Check they move to Suspended.

Remove someone’s access

Remove the person from their Flowstate groups in your identity provider. Flowstate suspends them. You can also select Suspend User on their row under Settings → Users & Access → Users.

Replace a token

Create a new token, update your identity provider with it, then revoke the old one from its row. Provisioning stops if your identity provider is left with a revoked or expired token.

If something’s not right

People appear in your identity provider’s logs but have no Flowstate account. They aren’t in a pushed group yet. Push the group or add them to it.

Pushing a group fails with “No auth provider configured for this tenant”. No single sign-on provider is switched on. Set one up first.

Someone has the wrong role. Their group’s mapping has a different role. Delete the mapping, add the right one, and push the group again.

Provisioning suddenly stops. The token has expired or been revoked. Create a new one.

For your technical team

  • Base URL: https://<your Flowstate address>/api/scim/v2
  • Authentication: Authorization: Bearer fs_scim_…
  • Resources: /Users and /Groups (GET, POST, PUT, PATCH, DELETE), plus /ServiceProviderConfig, /Schemas and /ResourceTypes.
  • User attributes read: userName, externalId, name.givenName, name.familyName and active.
  • Filtering: eq only: userName and externalId on /Users, displayName on /Groups.
  • Group members: each member’s value is the SCIM user id Flowstate returned.
  • Not supported: bulk operations, sorting, ETags and password changes.