Requirements
SCIM needsConfig.Organizations, and theauth.New returns ErrSCIMRequiresOrganizations without it. Storage must support organizations: memory, Postgres or MySQL. SQLite does not.
Configure
RequireHTTPS explicitly: it is a plain bool, so leaving it out means false. When true, requests with no TLS and no X-Forwarded-Proto: https get a 403. MaxPageSize caps the count parameter on list calls and defaults to 200.
Issue a token
Create a token for an organization from Go:ListSCIMTokens(ctx, orgID) and RevokeSCIMToken(ctx, tokenID). The IdP sends the token as Authorization: Bearer <token>.
Routes
SCIM resources mount at/scim/v2, outside the /auth prefix, and use the bearer token for auth.
Token management is also available over HTTP for signed-in users:
Security notes
- Tokens are 256-bit random values stored as a SHA-256 hash. Treat the plaintext like a password and hand it straight to the IdP.
- A revoked token is refused on its next request. Revoke and reissue when an IdP admin leaves.
- Run SCIM behind HTTPS with
RequireHTTPS: true. Only turn it off when a TLS-terminating proxy in front of you enforces HTTPS. - A token can only touch resources in its own organization. SCIM actions are written to the audit log with the token ID as the actor.
- Combine SCIM with SAML SSO so deprovisioned users also lose the ability to sign in.