Skip to main content
SCIM lets your identity provider (IdP) be the source of truth for who is in your Vibely workspace. When you assign someone to the Vibely app in your IdP, they get a membership. When you unassign or deactivate them, the membership goes away.
Set up SCIM user provisioning
Vibely implements SCIM 2.0.

Prerequisites

  • A Business workspace. SCIM requests to a workspace on another plan are refused with SCIM provisioning requires the Business plan.
  • The owner or admin role, to issue the token.
  • Admin access to your IdP.
  • SSO is recommended but not required. See SSO.

How SCIM works in Vibely

User provisioning

When your IdP pushes a user: Pending invitations are reported back to your IdP as active users, so it doesn’t try to create them again.

User deprovisioning

When your IdP deactivates or deletes a user, Vibely removes their membership. If they only had a pending invitation, the invitation is deleted instead. Reactivating them adds them back at the current default role.
The workspace owner is never removed by SCIM. Transfer ownership first if you need to remove them.
Names and emails come from the person’s Vibely account and aren’t overwritten from SCIM.

Groups

This is where Vibely differs most from other SCIM apps. Vibely always exposes exactly three groups, one per workspace role: Membership in a group is the role. Adding someone to Admins makes them an admin; removing them drops them back to the default role.
Your own IdP groups don’t create groups in Vibely. Pushing a group called Engineering does nothing. Map your IdP groups onto these three instead, or your first sync will look like it silently did nothing.
These role groups are separate from Vibely’s member groups, which SCIM can’t create or change.

Supported SCIM operations

Only userName eq filters are supported; other filters return the full list.

Set up SCIM provisioning

Step 1: Configure SCIM in Vibely

1

Open User provisioning

Go to Settings → Identity → User provisioning. The same controls are on Settings → Security center.
2

Copy the SCIM base URL

Copy it from the page rather than typing it. It ends in /scim/v2.
3

Issue a token

Click Issue token and copy the SCIM bearer token straight away. It’s shown once and never again.
4

Set the default role

Role for SCIM users decides what a pushed user becomes: Viewer, Editor (the default), or Admin.

Step 2: Configure SCIM in your IdP

  1. Open your Vibely app → Provisioning → Configure API Integration → Enable API integration.
  2. Base URL: the SCIM base URL. API Token: the bearer token. Click Test API Credentials.
  3. Turn on Create Users, Update User Attributes, and Deactivate Users.
  4. For roles, use Push Groups to push each Okta group to the existing Vibely group with the matching name (Admins, Editors, or Viewers). Don’t create new groups.

Manage SCIM provisioning

Rotate the token

A workspace has one active token. Rotate issues a new one and revokes the old one in the same step, so update your IdP right away. The page identifies the active token by its first 12 characters and shows when it was created and last used. Last used is the quickest way to check your IdP is actually reaching Vibely.

Change the default role

Change Role for SCIM users at any time. It applies to people provisioned from then on, and to anyone dropped out of a role group.

Turn off SCIM

Click Revoke. Your IdP stops provisioning until you issue a new token. Existing members stay.

Troubleshooting

FAQ

The Business plan.
No. SCIM only sets workspace roles through the three role groups. Create member groups yourself in Settings → Groups.
Their membership is removed and they lose access. Projects they created stay in the workspace.
No, but they work best together: SCIM decides who’s a member, SSO decides how they sign in.

Identity

Verify your domain and choose how people join.

SSO

Connect your identity provider for sign-in.