Skip to main content
Account settings, security & privacy

Provision users with SCIM

Create, update and remove fynk users automatically from Microsoft Entra ID or Okta, with roles based on group names.

Written By Sebastian

Last updated About 12 hours ago

With SCIM, your identity provider manages fynk users for you. New colleagues get access automatically, role changes are synced, and leavers lose access.

Available on Pro · Owner and Admin

Before you start

  • SCIM is a standard. It works with any identity provider that supports SCIM 2.0, for example Google Workspace. fynk has tested Microsoft Entra ID and Okta. Entra ID requires a P1 or P2 licence.
  • Set up SSO first, so users can log in. See Set up SSO.

Set up SCIM

  1. In fynk, go to Account settings → Integrations → SCIM.
  2. Copy the base URL and create an API token.
  3. In your identity provider, set up provisioning for your fynk application and paste the base URL and token.
  4. Create groups for fynk roles and assign users to them (see below).
  5. Start provisioning.

Assign roles with groups

fynk reads the role from the group name. The group name must contain one of these terms:

Group name containsfynk role
account-ownerOwner
account-adminAdmin
account-editorEditor
account-managerManager
account-limited-managerLimited Manager

Setup in Microsoft Entra ID

  1. Create a separate enterprise application for SCIM. We recommend one app for SSO and one for SCIM.
  2. Open Provisioning and set Provisioning Mode to Automatic.
  3. Paste the fynk base URL into Tenant URL and the API token into Secret Token. Click Test Connection, then Save.
  4. Under Mappings, remove all user attributes except userName (mapped to mail), active, name.givenName, name.familyName and externalId.
  5. Assign the role groups to the app and click Start provisioning.

To sync right away instead of waiting for the next cycle, click Sync now. Entra ID doesn't follow the SCIM 2.0 standard in every detail. If something doesn't sync as expected, check Microsoft's known issues for SCIM provisioning.

Setup in Okta

In Okta, you can use the same app for SSO and SCIM. You need an Okta admin account with permissions for app integrations and provisioning.

  1. Create an app integration with SAML 2.0 and turn on SCIM provisioning, or use your existing fynk SSO app.
  2. Under Provisioning → Integration, paste the fynk base URL. Set the unique identifier field to userName or email, set Authentication Mode to HTTP Header and paste the API token. Click Test Connector Configuration and save.
  3. Under Provisioning → To App, turn on Create Users, Update User Attributes and Deactivate Users. Don't turn on Sync Password.
  4. In the attribute mappings, keep only userName (mapped to email), givenName, familyName and email.
  5. Push each role group under Push Groups and assign users under Assignments.
  6. Run Force Sync for the first sync.

Good to know

  • If a user's role in fynk doesn't match their group, the sync corrects it. Check your groups before you start provisioning, or users can lose access to fynk or to Account settings.
  • Your IT admin can do the setup alone if they temporarily get the Owner or Admin role in fynk.
  • If you turn off provisioning, existing users stay in fynk. Later changes in the identity provider are no longer synced.
  • Users who aren't in any of these groups are removed from fynk.
  • Changes made manually in fynk are overwritten by the next sync.
  • The sync runs every 20 to 40 minutes.
  • Teams aren't synced. Assign users to teams in fynk.
  • Nested groups aren't supported.