SCIM Configuration with Okta
This article will explain how to setup SCIM with your IdP. Before enabling SCIM, you must first enable SSO. For information on how to enable Single Sign On, read more here.
Spoke API token
To turn on SCIM, log into Spoke. You will need to be a Spoke admin to make these changes.
- Navigate to Settings
- Click the "SSO" tab
- Turn the "Provision Users with SCIM" toggle to on
- Select "Generate a token" to generate an API token. Copy this API Token.
Log into Okta, and navigate to "Applications" to search your active applications for "Spoke"
- Click the "Provisioning" tab
- select "API Integration" from the left menu.
- Click "Configure API integration"
- Click the "Enable API Integration" checkbox
- Paste the API Token copied in Section 1 into this field
- Click Save
Click the "To App" tab on the left menu. Select the provisioning features you wish to enable, and select Save.
- Create Users: Enable this if you would like to create or link a user when assigning the app to a user in Okta
- Update User Attributes: Enable this if you would like Okta to update user profiles in Spoke. If this is enabled, Okta will overwrite user details in Spoke.
- Deactivate Users: Enable this if you would like a user's Spoke account to be deactivated when it is unassigned in Okta, or when their Okta account is deactivated.
SCIM can be used to update the following attributes
- Display name
- Job title
- Joined teams
- Manager name
- Manager email
- Employee Type
- Start Date
Assigning the app
Select the "Assignments" menu on the right side.
From the Assignments menu, select "Assign" then choose "Assign to People" or "Assign to Group"
Choose the people or groups you'd like to assign by selecting the "Assign" button on the right side.
Select "Save and Go Back"
Navigate back to Spoke and check the user's profile to make sure that the user you assigned was updated. You will see the user you just added to Okta created as a user in Spoke.
You can also navigate to the SSO tab and check the bottom of the page. If SCIM is connected you will see the last time Okta sent an update to Spoke.