> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vikat.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Setup SCIM

> Enable real-time user and group provisioning from Okta to Vikat Enterprise using SCIM 2.0.

SCIM (System for Cross-domain Identity Management) keeps Vikat in sync with Okta in real time — new users are provisioned, deactivated users are suspended, and group memberships are updated without waiting for the next login or background sync.

<Note>
  Complete [SSO using OIDC](./oidc) before setting up SCIM. Okta does not support SCIM on a custom OIDC app, so SCIM runs as a **separate** app alongside your existing OIDC integration.
</Note>

***

## Step 1: Enable SCIM in Vikat

<Steps>
  <Step title="Open your Okta provider">
    In your Vikat dashboard, go to **Governance** → **User Provisioning** and open your configured Okta provider.

    <Frame caption="The Okta provider dashboard showing your connection details and attribute mappings.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/vikat-provider-setting.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=69f2b0646ec487dd0b3e7fca64022202" alt="Vikat Okta provider dashboard showing connection details and attribute mappings" width="2916" height="1672" data-path="media/user-provisioning/okta/vikat-provider-setting.png" />
    </Frame>
  </Step>

  <Step title="Enable SCIM provisioning">
    Click the settings icon to open **Provider Configuration**.

    Toggle on **Enable SCIM Provisioning** and click **Save & Enable**.

    <Frame caption="Enable SCIM Provisioning in Provider Configuration — the SCIM endpoint URL and token are generated after saving.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/vikat-enable-scim.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=1d64fb8d75c96667dbeb7f6b614be691" alt="Vikat Provider Configuration with Enable SCIM Provisioning toggle turned on" width="2916" height="1674" data-path="media/user-provisioning/okta/vikat-enable-scim.png" />
    </Frame>
  </Step>

  <Step title="Copy the SCIM credentials">
    After saving, Vikat shows a **Setup Complete** dialog with:

    * **SCIM Endpoint URL** — the base URL Okta will send provisioning requests to
    * **Provisioning Token** — the bearer token Okta uses to authenticate

    Copy both values now — you will need them in [Step 3](#step-3-configure-the-scim-app).

    <Frame caption="Setup Complete dialog showing the SCIM Endpoint URL and Provisioning Token.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/vikat-scim-provisioning-token-dialog.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=c38fe79bc2844f2b957f67fdc8ccef0b" alt="Vikat Setup Complete dialog displaying the SCIM Endpoint URL and one-time Provisioning Token" width="2916" height="1674" data-path="media/user-provisioning/okta/vikat-scim-provisioning-token-dialog.png" />
    </Frame>

    <Warning>
      The provisioning token is only shown once. Store it somewhere safe before closing this dialog. You can always rotate it later, but the previous token will immediately become invalid.
    </Warning>
  </Step>
</Steps>

***

## Step 2: Create a SCIM App in Okta

<Steps>
  <Step title="Browse the App Catalog">
    In the Okta Admin Console, go to **Applications** → **Applications** and click **Browse App Catalog**.

    <Frame caption="Click Browse App Catalog from the Applications page.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-browse-app-catalog.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=4a8c30c83900d9e20145f5c936b71147" alt="Okta Applications page with Browse App Catalog button highlighted" width="3024" height="1588" data-path="media/user-provisioning/okta/okta-browse-app-catalog.png" />
    </Frame>
  </Step>

  <Step title="Add the SCIM 2.0 Test App">
    Search for **SCIM 2.0 Test App (Header Auth)** and add it.

    <Frame caption="Select SCIM 2.0 Test App (Header Auth) from the catalog.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-choose-scim-header-auth.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=a109976c101abb37fe658734d8954666" alt="Okta App Catalog search results with SCIM 2.0 Test App (Header Auth) highlighted" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-choose-scim-header-auth.png" />
    </Frame>

    Name the app `Vikat SCIM` (or any label you prefer). On the sign-on options screen, skip everything and click **Done** — this app is used for SCIM provisioning only, not authentication.
  </Step>
</Steps>

***

## Step 3: Configure the SCIM App

<Steps>
  <Step title="Connect the app to Vikat">
    Open the **Vikat SCIM** app and go to the **Provisioning** tab.

    Click **Configure API Integration**, check **Enable API Integration**, and enter:

    * **SCIM 2.0 Base URL**: the SCIM Endpoint URL from [Step 1](#step-1-enable-scim-in-vikat)
    * **API Token**: the Provisioning Token from [Step 1](#step-1-enable-scim-in-vikat)

    Click **Test API Credentials** to verify the connection, then **Save**.

    <Frame caption="Enter the SCIM Endpoint URL and Provisioning Token from Vikat to connect the app.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-scim-provisioning-setup.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=edca411e1da91c2642f0524c7247238b" alt="Okta SCIM app Configure API Integration dialog with Base URL and API Token fields filled in" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-scim-provisioning-setup.png" />
    </Frame>
  </Step>

  <Step title="Enable provisioning actions">
    Still under the **Provisioning** tab, go to **To App** and enable:

    * **Create Users**
    * **Update User Attributes**
    * **Deactivate Users**

    Click **Save**.

    <Frame caption="Provisioning → To App — enable Create Users, Update User Attributes, and Deactivate Users.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-scim-provisioning-to-app.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=ac7b2fa102b33f7f3e4cf03e4ba7e510" alt="Okta Provisioning To App section with Create Users, Update User Attributes, and Deactivate Users enabled" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-scim-provisioning-to-app.png" />
    </Frame>
  </Step>

  <Step title="Add custom attributes (optional)">
    Skip this step if you only need to sync standard user fields (name, email, groups).

    <Accordion title="Syncing custom profile attributes (e.g. employeeId, costCenter, division)">
      Custom attributes need to be declared in the SCIM app schema before Okta can include them in provisioning payloads.

      Go to **Directory** → **Profile Editor** and select the **Vikat SCIM** app profile. Click **Add Attribute**.

      <Frame caption="Profile Editor for the Vikat SCIM app — click Add Attribute to declare a new custom field.">
        <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-profile-editor-add-attribute.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=d8f329b651c7468ae2018c00c7818bd8" alt="Okta Profile Editor for the Vikat SCIM app showing the Add Attribute and Mappings buttons" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-profile-editor-add-attribute.png" />
      </Frame>

      Configure the attribute — for example, for `Employee ID`:

      | Field                  | Value                                                        |
      | ---------------------- | ------------------------------------------------------------ |
      | **Display name**       | `Employee ID`                                                |
      | **Variable name**      | `employeeID`                                                 |
      | **External name**      | `employeeID`                                                 |
      | **External namespace** | `urn:ietf:params:scim:schemas:extension:enterprise:2.0:User` |

      <Frame caption="Add Attribute dialog — the External name is what Vikat receives and must match exactly what you configure in Vikat's SCIM attribute settings.">
        <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-custom-attribute-employee-id.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=d065a63ab86f9eada82004d7fe949d8b" alt="Add Attribute dialog with Display name Employee ID, Variable name employeeID, and External name employeeID filled in" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-custom-attribute-employee-id.png" />
      </Frame>

      Click **Save**, then click **Mappings** on the Vikat SCIM profile.

      <Frame caption="Click Mappings on the Vikat SCIM profile to open the attribute mapping view.">
        <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-scim-custom-attribute-mapping-button.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=557aacac008311032b826c522e8f8591" alt="Vikat SCIM Attribute Mappings screen with Go to Profile Editor and Force Sync buttons" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-scim-custom-attribute-mapping-button.png" />
      </Frame>

      Select the **Okta User → Vikat SCIM** tab.

      <Frame caption="Okta User to Vikat SCIM mapping direction — map each Okta profile field to the corresponding SCIM attribute.">
        <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-custom-attribute-mapping.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=8df5caa5f637f09847fe696f6aa263b3" alt="Okta User to Vikat SCIM mapping direction tab showing attribute mapping fields" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-custom-attribute-mapping.png" />
      </Frame>

      Scroll to find your attribute and set its source from the Okta user profile — e.g. `user.employeeNumber` → `employeeID`. Click **Save Mappings**.

      <Frame caption="Mapping user.employeeID from the Okta user profile to the employeeID SCIM attribute.">
        <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-custom-attribute-mapping-employeeid.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=6e9a7fe24677f80bc9799317d2692eff" alt="Attribute mapping row showing user.employeeID mapped to the employeeID SCIM attribute" width="3024" height="1590" data-path="media/user-provisioning/okta/okta-custom-attribute-mapping-employeeid.png" />
      </Frame>

      Back in Vikat, go to **Attribute Mapping** in the provider setup and add a **SCIM Attribute** entry for `employeeID`. The External name you set in Okta must match this exactly.

      <Frame caption="In Vikat's Attribute Mapping step, add the custom SCIM attribute using the same External name configured in Okta.">
        <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/vikat-custom-user-attribute-scim.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=f29eca1a2c7ee00d5f847eb05eee6556" alt="Vikat Attribute Mapping step showing SCIM Attributes section with employeeID custom attribute entry" width="2914" height="1670" data-path="media/user-provisioning/okta/vikat-custom-user-attribute-scim.png" />
      </Frame>

      <Note>
        The **External name** in Okta's Profile Editor and the SCIM attribute name in Vikat must match exactly — including case.
      </Note>
    </Accordion>
  </Step>
</Steps>

***

## Step 4: Assign Users and Push Groups

<Steps>
  <Step title="Assign users">
    Go to the **Assignments** tab in the Vikat SCIM app.

    Click **Assign** → **Assign to People** or **Assign to Groups** and select the users or groups to sync with Vikat.

    <Frame caption="Assign users or groups from the Assignments tab — users are pushed to Vikat immediately on assignment.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-scim-assignments.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=5741859d620b9bc564432501c080c4d0" alt="Vikat SCIM app Assignments tab with Assign dropdown showing Assign to People and Assign to Groups options" width="2128" height="1480" data-path="media/user-provisioning/okta/okta-scim-assignments.png" />
    </Frame>

    Assigned users are pushed to Vikat immediately. When a user is unassigned or deactivated in Okta, Vikat deactivates them in real time.
  </Step>

  <Step title="Push groups (for team and BU mapping)">
    If you use group membership to drive Vikat team or business unit assignments, you need to push the groups themselves — not just the users in them.

    Go to the **Push Groups** tab in the Vikat SCIM app and click **Push Groups**.

    You can push groups **by name** (search for specific groups) or **by rule** (create a filter that automatically pushes any matching groups — useful if your groups follow a naming convention like `Vikat-*`).

    <Frame caption="Push Groups tab — choose to find groups by name or create a rule to push all matching groups automatically.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-scim-push-groups.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=dd2c7b159d7b98189ce927dc774cc88f" alt="Push Groups tab showing Find groups by name and Find groups by rule options" width="3024" height="1592" data-path="media/user-provisioning/okta/okta-scim-push-groups.png" />
    </Frame>

    <Frame caption="Push by rule — set a filter (e.g. Group name starts with 'Vikat') to automatically push all matching groups.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-scim-push-groups-by-rule.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=d532c8d712d8f797c7b872715172387b" alt="Push Groups by rule dialog with Rule name Vikat Groups and Group name filter starting with Vikat" width="2128" height="1480" data-path="media/user-provisioning/okta/okta-scim-push-groups-by-rule.png" />
    </Frame>

    Once groups are pushed and showing as **Active**, Vikat tracks their membership in real time.

    <Frame caption="Pushed groups showing as Active — Vikat now tracks membership changes for these groups in real time.">
      <img src="https://mintcdn.com/vikat-ai/Ui4AlBSF379KQPi5/media/user-provisioning/okta/okta-scim-push-groups-active.png?fit=max&auto=format&n=Ui4AlBSF379KQPi5&q=85&s=8fb40ae5a333698fae58ce319b451e5b" alt="Push Groups list showing Vikat-Admin and Vikat-Viewer groups with Active push status" width="2128" height="1480" data-path="media/user-provisioning/okta/okta-scim-push-groups-active.png" />
    </Frame>

    In Vikat, configure **Attribute-to-Team** or **Attribute-to-Business Unit** mappings using the group `displayName` as the match value to automatically assign users to teams or business units based on their group membership.
  </Step>
</Steps>

***

## Step 5: Verify in Vikat

Once assignments and group pushes are active, confirm everything is syncing correctly.

* Go to **Governance** → **Users** to see provisioned users and their assigned roles
* Go to **Governance** → **Teams** to see teams populated from pushed groups
* Go to **Governance** → **Business Units** to see business units resolved from group or attribute mappings

Changes in Okta — new assignments, group membership updates, deactivations — will reflect in Vikat in real time.

***

## How Sync Works

**Real-time push** — Okta pushes user and group changes to Vikat immediately when they occur.

**Background reconciliation** — if you configured an API token in [SSO using OIDC Step 4](./oidc#step-4-copy-your-credentials), Vikat also runs a full reconciliation every 24 hours to catch anything the SCIM push may have missed.

***

## Troubleshooting

**Test API Credentials fails** — verify the SCIM Base URL has no trailing slash and the API token matches exactly what Vikat generated. Rotate the token in Vikat and update Okta if needed.

**Users are pushed but have no role** — SCIM provisions the user record; role assignment comes from attribute mappings in the OIDC provider. Confirm your Attribute-to-Role mappings are set and the relevant claims are present in the JWT.

**Custom attribute is not arriving in Vikat** — confirm the External name in Okta's Profile Editor matches the SCIM attribute name in Vikat exactly (case-sensitive). Also verify the Okta User → Vikat SCIM mapping direction is saved.

**Group membership is not syncing** — ensure groups are added under **Push Groups**, not just **Assignments**. Assignments sync users; Push Groups syncs group membership.
