Skip to main content
Okta SCIM provisioning is a paid feature.If you’re using Infisical Cloud, then it’s available under the Enterprise Tier. If you’re self-hosting Infisical, then you should contact sales@infisical.com to purchase an enterprise license to use it.
Prerequisites:
1

Create a SCIM token in Infisical

In Infisical, head to SSO & Provisioning and select the Provisioning tab. Under SCIM Provisioning, turn on the Enable SCIM toggle to allow Okta to provision and deprovision users and user groups for your organization.SCIM enable provisioningNext, select Configure on the SCIM Provisioning card, then select Create Token in the Manage SCIM Credentials modal to generate a SCIM token for Okta.SCIM create tokenNext, copy the SCIM URL and New SCIM Token to use when configuring SCIM in Okta.SCIM copy token
2

Configure SCIM in Okta

In Okta, head to your Application > General > App Settings. Next, select Edit and check the box labeled Enable SCIM provisioning.SCIM OktaNext, head to Provisioning > Integration and set the following SCIM connection fields:
  • SCIM connector base URL: Input the SCIM URL from Step 1.
  • Unique identifier field for users: Input email.
  • Supported provisioning actions: Select Push New Users, Push Profile Updates, and Push Groups.
  • Authentication Mode: HTTP Header. SCIM Okta
Under HTTP Header > Authorization: Bearer, input the New SCIM Token from Step 1.SCIM OktaNext, press Test Connector Configuration to check that SCIM is configured properly.SCIM OktaNext, head to Provisioning > To App and check the boxes labeled Enable for Create Users, Update User Attributes, and Deactivate Users.SCIM OktaNow Okta can provision/deprovision users and user groups to/from your organization in Infisical.