SCIM (System for Cross-domain Identity Management) lets your identity provider add and remove users from your Compound team. Instead of manually inviting and removing team members, your IdP pushes changes to Compound in real time. When you assign someone to the Compound app in your IdP, they are added to your team, and when you unassign them, they are removed.
Prerequisites
Before you can enable SCIM, your team must meet the following requirements:
- Enterprise SSO configured. SCIM requires an active SAML or OIDC SSO configuration. See Set Up SSO for Compound to configure SSO first.
- The Team Owner role. Only Team Owners can enable and manage SCIM provisioning.
SCIM cannot be enabled until your team has a working SSO configuration (SAML or OIDC). The Enable SCIM button does not appear unless SSO is active.
Enable SCIM provisioning
Open SCIM settings
In Compound, navigate to Settings > Organization > Security. Scroll down to the SCIM Provisioning section below the SSO configuration.
Enable SCIM
Click Enable SCIM. Compound generates a SCIM endpoint URL and a bearer token for authenticating your identity provider.
Copy the endpoint URL and bearer token
After enabling, Compound displays:
- The SCIM Endpoint URL: the base URL your IdP uses to communicate with Compound.
- A bearer token, shown once under Copy this token now. It will not be shown again. Your IdP includes it in SCIM API requests.
Copy both values. You will need to enter them in your identity provider’s SCIM configuration.
The bearer token is displayed only once. Copy it and store it securely. If you navigate away without copying the token, you will need to rotate it to generate a new one.
Configure your identity provider
After enabling SCIM in Compound, configure your IdP to use the endpoint URL and bearer token. See the provider-specific guide for your IdP:
- Set Up Okta SCIM Provisioning: step-by-step guide for configuring SCIM with Okta
For other identity providers, enter the SCIM endpoint URL as the SCIM connector base URL, and the bearer token as the OAuth bearer token or API token, depending on your IdP’s terminology.
Compound supports SCIM Users only (no Groups). Your IdP must send externalId when it creates a user, and deprovision by setting active to false (PATCH or PUT). DELETE requests are not supported.
Rotate the bearer token
If the bearer token is compromised or you need to issue a new one:
- Go to Settings > Organization > Security > SCIM Provisioning.
- Click Rotate Token, then confirm with Rotate Token in the dialog.
- Compound generates a new bearer token and invalidates the previous one immediately.
- Copy the new token and update it in your identity provider’s SCIM configuration.
After rotating the token, your IdP cannot make SCIM requests until you update the token in your IdP’s settings. Update it promptly to avoid provisioning interruptions.
Disable SCIM provisioning
To stop your IdP from provisioning users:
- Go to Settings > Organization > Security > SCIM Provisioning.
- Click Disable SCIM.
- Confirm the action in the dialog.
Disabling SCIM revokes the bearer token and stops all SCIM API requests from your IdP. Existing team members are not affected and remain on the team. You can re-enable SCIM at any time. The endpoint URL stays the same and Compound issues a new bearer token, which you must enter in your IdP.
What happens during provisioning
While SCIM is on, your IdP owns the team roster: manual invitations are disabled, and members provisioned by SCIM can only be removed by unassigning them in your IdP. Roles are still changed in Compound.
When a user is provisioned
When your IdP sends a SCIM create request (e.g., when you assign a user to the Compound app in your IdP):
- If the user does not have a Compound account, one is created using their email address.
- The user is added to your team as a Member.
- The user can sign in via SSO right away.
When a user is deprovisioned
When your IdP sends a SCIM deactivate request (e.g., when you unassign a user from the Compound app or disable their account in your IdP):
- The user is removed from your team.
- Their Compound account is not deleted. Only the team membership is removed.
- The user loses access to team resources but keeps their personal account and data.
Team Owners cannot be deprovisioned via SCIM. If your IdP attempts to deactivate the team owner, the request is rejected.
When a user is reactivated
If a previously deprovisioned user is reassigned to the Compound app in your IdP:
- The user is added back to your team as a Member.
- Their existing Compound account is reused, and no new account is created.