Skip to content
Enterprise & agencies

SCIM user provisioning

SCIM keeps Climails in sync with your identity directory automatically. When someone joins, changes role or leaves, your IdP pushes the change and their Climails access follows — no manual invites or cleanup.

6 min read

What you'll need

  • An IdP that supports SCIM 2.0 (Okta, Azure AD, etc.)
  • Admin access to generate a SCIM token in Climails

What SCIM automates

  • Provisioning — new directory users get a Climails account automatically.
  • Updates — changes to a user (name, status) flow through.
  • Deprovisioning — deactivating someone in your directory removes their access, so offboarding is instant and complete.

Set it up

  1. 1

    Generate a SCIM token

    Create a SCIM bearer token in Climails for your IdP to authenticate with.

  2. 2

    Configure the SCIM app in your IdP

    Point your IdP's SCIM connector at Climails' SCIM base URL and paste the token.

  3. 3

    Assign users

    Assign people (or groups) to the app; the IdP provisions them into Climails over the standard SCIM Users endpoints.

Climails implements the SCIM 2.0 standard (Users with create/read/update/deactivate), so any compliant IdP connector works.

Frequently asked questions

What happens when I deactivate a user in Okta?

SCIM propagates the change and the user loses Climails access — no orphaned accounts left behind.

Do I still need SSO?

They're complementary: SCIM manages the accounts, SSO manages how those accounts log in. Most enterprises use both.

How does the IdP authenticate to SCIM?

With a bearer token you generate in Climails and paste into your IdP's SCIM connector.

Start sending in minutes

Create a free account, connect your domain and reach your audience across every channel — no credit card needed.

Free plan forever · No credit card required · Set up in minutes

SCIM 2.0 automated user provisioning — Climails