SCIM provisioning
Automatically add and remove organization access from your directory.
Requires working SAML SSO, contract billing with available seats, and administrator access in both systems.
Add the SAML identity claim
Same SSO application → Sign On → Attribute statements → Add expression
- Claim name
- directoryId
- Expression
- user.id
Keep existing NameID, email/name claims, callback, and audience unchanged.
Create the Shortcut connection
Organization settings → Security → Directory provisioning (SCIM)
Select your SSO provider and Okta → Enable provisioning and create token. Copy the base URL and token.
The token appears once. Save it in your secret manager, not email or screenshots.
Already have Shortcut users?
Existing SSO accounts enroll automatically when SCIM userName matches their existing SAML NameID for this provider. No preparatory sign-in is needed. Push provisioning for existing assignments too. Contact Shortcut for users with only password or social login; email alone does not link accounts. Provision new users before their first sign-in.
Configure Okta provisioning
General → Enable SCIM; then Provisioning → Integration → Edit SCIM Connection
- SCIM version
- 2.0
- Base URL
- Base URL copied from Shortcut
- Unique identifier
- userName
- Authentication
- HTTP Header
- Token
- Token copied from Shortcut
Enable Push New Users and Push Profile Updates. Under To App, enable Create Users, Update User Attributes, and Deactivate Users. Leave groups, imports, and password sync off. Okta adds the Bearer prefix.
Confirm SCIM userName uses the same value as your existing SAML NameID. Keep externalId equal to the immutable ID sent in directoryId.
Run Test Connector Configuration and save.
Test one user before rollout
Assignments → Assign; push provisioning for already-assigned users
| Do this | Check in Shortcut |
|---|---|
| Provision an existing SSO user without asking them to sign in first. | Same account; counted as managed by SCIM in Security settings. |
| Assign a new user; sign in from Shortcut and the provider dashboard. | Correct organization membership. |
| Change their display name; push the update. | Updated profile. |
| Unassign the app; refresh Shortcut. | Organization access removed. |
| Reassign; sign in again. | Same account, access restored. |
Wait for successful provisioning between steps. Then expand assignments and review “Not managed by SCIM” in Security settings. Enabling provisioning alone does not enroll every existing member.
Supported behavior
SCIM provisions members, not teams, admin roles, or passwords. Stripe subscription organizations are unsupported. Removing access preserves the global account and other organizations. Profile updates affect directory-created users; linking an existing account preserves its name and email. If setup is unavailable or seats are exhausted, contact your administrator or Shortcut.
Replace or revoke a token
Tokens expire after one year. Create replacement token → update directory → test connection → revoke old token. Both work during replacement. A revoked token cannot provision, but memberships remain. If you lose a token, replace and revoke it.
Disconnect or reconnect
Pause directory provisioning, then disconnect in Shortcut. All tokens stop working. Current members keep access; removed users stay removed. Manual membership management resumes.
Keep the directoryId claim: removing it blocks SSO, including administrators. Known directory users still need membership. Users never managed by SCIM can join through normal SSO.
Reconnect with the same provider and directory, replace the token, and reprovision. Existing verified identities reuse their accounts. Old tokens stay invalid. Contact Shortcut before changing identity mappings or providers; routine certificate/metadata updates remain supported.
Troubleshooting
- Unauthorized: check token expiry, revocation, and connection status.
- Identity or email conflict: check that SCIM userName matches the existing SAML NameID for this provider. If it does not resolve, contact Shortcut. Do not delete or rename the existing account to bypass the conflict.
- Seat limit: free a seat or adjust the contract, then retry. Failed provisioning leaves no partial membership.
- SSO denied: check assignment and that signed
directoryIdequals SCIMexternalId, not email or display name.