Skip to main content
theauth-go serves a SCIM 2.0 API so an identity provider such as Okta or Entra ID can manage users and groups inside one organization. Each organization gets its own bearer tokens, and every SCIM request is scoped to the organization that owns the token.

Requirements

SCIM needs Config.Organizations, and theauth.New returns ErrSCIMRequiresOrganizations without it. Storage must support organizations: memory, Postgres or MySQL. SQLite does not.

Configure

Set RequireHTTPS explicitly: it is a plain bool, so leaving it out means false. When true, requests with no TLS and no X-Forwarded-Proto: https get a 403. MaxPageSize caps the count parameter on list calls and defaults to 200.

Issue a token

Create a token for an organization from Go:
The plaintext is returned once and cannot be read back. Also available: ListSCIMTokens(ctx, orgID) and RevokeSCIMToken(ctx, tokenID). The IdP sends the token as Authorization: Bearer <token>.

Routes

SCIM resources mount at /scim/v2, outside the /auth prefix, and use the bearer token for auth. Token management is also available over HTTP for signed-in users:

Security notes

  • Tokens are 256-bit random values stored as a SHA-256 hash. Treat the plaintext like a password and hand it straight to the IdP.
  • A revoked token is refused on its next request. Revoke and reissue when an IdP admin leaves.
  • Run SCIM behind HTTPS with RequireHTTPS: true. Only turn it off when a TLS-terminating proxy in front of you enforces HTTPS.
  • A token can only touch resources in its own organization. SCIM actions are written to the audit log with the token ID as the actor.
  • Combine SCIM with SAML SSO so deprovisioned users also lose the ability to sign in.
Last modified on October 8, 2026