SCIM Provisioning

Dernière mise à jour 28 septembre 2026

SCIM (System for Cross-domain Identity Management) lets your identity provider add and remove users from your Compound team. Instead of manually inviting and removing team members, your IdP pushes changes to Compound in real time. When you assign someone to the Compound app in your IdP, they are added to your team, and when you unassign them, they are removed.

Prerequisites

Before you can enable SCIM, your team must meet the following requirements:

  • Enterprise SSO configured. SCIM requires an active SAML or OIDC SSO configuration. See Set Up SSO for Compound to configure SSO first.
  • The Team Owner role. Only Team Owners can enable and manage SCIM provisioning.
Important

SCIM cannot be enabled until your team has a working SSO configuration (SAML or OIDC). The Enable SCIM button does not appear unless SSO is active.

Enable SCIM provisioning

Open SCIM settings

In Compound, navigate to Settings > Organization > Security. Scroll down to the SCIM Provisioning section below the SSO configuration.

Enable SCIM

Click Enable SCIM. Compound generates a SCIM endpoint URL and a bearer token for authenticating your identity provider.

Copy the endpoint URL and bearer token

After enabling, Compound displays:

  • The SCIM Endpoint URL: the base URL your IdP uses to communicate with Compound.
  • A bearer token, shown once under Copy this token now. It will not be shown again. Your IdP includes it in SCIM API requests.

Copy both values. You will need to enter them in your identity provider’s SCIM configuration.

Important

The bearer token is displayed only once. Copy it and store it securely. If you navigate away without copying the token, you will need to rotate it to generate a new one.

Configure your identity provider

After enabling SCIM in Compound, configure your IdP to use the endpoint URL and bearer token. See the provider-specific guide for your IdP:

For other identity providers, enter the SCIM endpoint URL as the SCIM connector base URL, and the bearer token as the OAuth bearer token or API token, depending on your IdP’s terminology.

Compound supports SCIM Users only (no Groups). Your IdP must send externalId when it creates a user, and deprovision by setting active to false (PATCH or PUT). DELETE requests are not supported.

Rotate the bearer token

If the bearer token is compromised or you need to issue a new one:

  1. Go to Settings > Organization > Security > SCIM Provisioning.
  2. Click Rotate Token, then confirm with Rotate Token in the dialog.
  3. Compound generates a new bearer token and invalidates the previous one immediately.
  4. Copy the new token and update it in your identity provider’s SCIM configuration.
Note

After rotating the token, your IdP cannot make SCIM requests until you update the token in your IdP’s settings. Update it promptly to avoid provisioning interruptions.

Disable SCIM provisioning

To stop your IdP from provisioning users:

  1. Go to Settings > Organization > Security > SCIM Provisioning.
  2. Click Disable SCIM.
  3. Confirm the action in the dialog.

Disabling SCIM revokes the bearer token and stops all SCIM API requests from your IdP. Existing team members are not affected and remain on the team. You can re-enable SCIM at any time. The endpoint URL stays the same and Compound issues a new bearer token, which you must enter in your IdP.

What happens during provisioning

While SCIM is on, your IdP owns the team roster: manual invitations are disabled, and members provisioned by SCIM can only be removed by unassigning them in your IdP. Roles are still changed in Compound.

When a user is provisioned

When your IdP sends a SCIM create request (e.g., when you assign a user to the Compound app in your IdP):

  1. If the user does not have a Compound account, one is created using their email address.
  2. The user is added to your team as a Member.
  3. The user can sign in via SSO right away.

When a user is deprovisioned

When your IdP sends a SCIM deactivate request (e.g., when you unassign a user from the Compound app or disable their account in your IdP):

  1. The user is removed from your team.
  2. Their Compound account is not deleted. Only the team membership is removed.
  3. The user loses access to team resources but keeps their personal account and data.
Note

Team Owners cannot be deprovisioned via SCIM. If your IdP attempts to deactivate the team owner, the request is rejected.

When a user is reactivated

If a previously deprovisioned user is reassigned to the Compound app in your IdP:

  1. The user is added back to your team as a Member.
  2. Their existing Compound account is reused, and no new account is created.