SCIM provisioning

Automatically add and remove organization access from your directory.

Requires working SAML SSO, contract billing with available seats, and administrator access in both systems.

01

Add the SAML identity claim

Same SSO application → Sign On → Attribute statements → Add expression

Claim name
directoryId
Expression
user.id

Keep existing NameID, email/name claims, callback, and audience unchanged.

02

Create the Shortcut connection

Organization settings → Security → Directory provisioning (SCIM)

Select your SSO provider and Okta → Enable provisioning and create token. Copy the base URL and token.

The token appears once. Save it in your secret manager, not email or screenshots.

Already have Shortcut users?

Existing SSO accounts enroll automatically when SCIM userName matches their existing SAML NameID for this provider. No preparatory sign-in is needed. Push provisioning for existing assignments too. Contact Shortcut for users with only password or social login; email alone does not link accounts. Provision new users before their first sign-in.

03

Configure Okta provisioning

General → Enable SCIM; then Provisioning → Integration → Edit SCIM Connection

SCIM version
2.0
Base URL
Base URL copied from Shortcut
Unique identifier
userName
Authentication
HTTP Header
Token
Token copied from Shortcut

Enable Push New Users and Push Profile Updates. Under To App, enable Create Users, Update User Attributes, and Deactivate Users. Leave groups, imports, and password sync off. Okta adds the Bearer prefix.

Confirm SCIM userName uses the same value as your existing SAML NameID. Keep externalId equal to the immutable ID sent in directoryId.

Run Test Connector Configuration and save.

04

Test one user before rollout

Assignments → Assign; push provisioning for already-assigned users

Do thisCheck in Shortcut
Provision an existing SSO user without asking them to sign in first.Same account; counted as managed by SCIM in Security settings.
Assign a new user; sign in from Shortcut and the provider dashboard.Correct organization membership.
Change their display name; push the update.Updated profile.
Unassign the app; refresh Shortcut.Organization access removed.
Reassign; sign in again.Same account, access restored.

Wait for successful provisioning between steps. Then expand assignments and review “Not managed by SCIM” in Security settings. Enabling provisioning alone does not enroll every existing member.

Supported behavior

SCIM provisions members, not teams, admin roles, or passwords. Stripe subscription organizations are unsupported. Removing access preserves the global account and other organizations. Profile updates affect directory-created users; linking an existing account preserves its name and email. If setup is unavailable or seats are exhausted, contact your administrator or Shortcut.

Replace or revoke a token

Tokens expire after one year. Create replacement token → update directory → test connection → revoke old token. Both work during replacement. A revoked token cannot provision, but memberships remain. If you lose a token, replace and revoke it.

Disconnect or reconnect

Pause directory provisioning, then disconnect in Shortcut. All tokens stop working. Current members keep access; removed users stay removed. Manual membership management resumes.

Keep the directoryId claim: removing it blocks SSO, including administrators. Known directory users still need membership. Users never managed by SCIM can join through normal SSO.

Reconnect with the same provider and directory, replace the token, and reprovision. Existing verified identities reuse their accounts. Old tokens stay invalid. Contact Shortcut before changing identity mappings or providers; routine certificate/metadata updates remain supported.

Troubleshooting
  • Unauthorized: check token expiry, revocation, and connection status.
  • Identity or email conflict: check that SCIM userName matches the existing SAML NameID for this provider. If it does not resolve, contact Shortcut. Do not delete or rename the existing account to bypass the conflict.
  • Seat limit: free a seat or adjust the contract, then retry. Failed provisioning leaves no partial membership.
  • SSO denied: check assignment and that signed directoryId equals SCIM externalId, not email or display name.