implementing-scim-provisioning-with-okta skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- Overview
- When to Use
- Prerequisites
- Core Concepts
- SCIM 2.0 Protocol
- Okta SCIM Integration Architecture
- Required SCIM Endpoints
- Workflow
- Step 1: Build SCIM 2.0 API Server
- Step 2: Configure Okta Application
- Step 3: Map Attributes
- Step 4: Implement Error Handling
- Step 5: Test with Runscope/Okta SCIM Validator
- Validation Checklist
- References
- Other files in this skill
- assets/template.md (verbatim)
- Project:
- Date:
- Engineer:
- Pre-Implementation
- SCIM Server Configuration
- Attribute Mapping
- Endpoint Testing Results
- Okta Configuration
- Validation
- Production Readiness
- references/api-reference.md (verbatim)
- Libraries Used
- Installation
- Authentication
- Okta Management API
- SCIM 2.0 Endpoint (Bearer Token)
- SCIM 2.0 Endpoints
- Core Operations
- List SCIM Users with Filtering
- Create a User
- Deactivate a User (PATCH)
- Manage Group Membership
- Okta Management API Endpoints
- List Okta Applications with SCIM Provisioning
- Output Format
- references/standards.md (verbatim)
- Protocol Standards
- RFC 7644 - SCIM Protocol
- RFC 7643 - SCIM Core Schema
- RFC 7642 - SCIM Definitions, Overview, Concepts, and Requirements
- Okta SCIM Requirements
- Mandatory Endpoints
- Required Filter Support
- Pagination Requirements
- Compliance Standards
- SOC 2 Type II
- ISO 27001 - A.9.2 User Access Management
- NIST SP 800-53 - AC (Access Control)
- references/workflows.md (verbatim)
- User Provisioning Workflow
- User Deprovisioning Workflow
- Group Push Workflow
- Profile Sync Workflow
- Error Recovery Workflow
- Implementation Testing Workflow
What it does. Implement automated user lifecycle provisioning and deprovisioning using Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/implementing-scim-provisioning-with-okta/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-scim-provisioning-with-okta, or copy the skill folder into~/.claude/skills/implementing-scim-provisioning-with-okta/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-scim-provisioning-with-okta/SKILL.md
SKILL.md (verbatim)
name: implementing-scim-provisioning-with-okta
description: Implement automated user lifecycle provisioning and deprovisioning using
the SCIM 2.0 protocol with Okta as the identity provider. Use when automating account
creation, attribute sync, or deactivation across downstream applications through
Okta SCIM integration, or when troubleshooting SCIM provisioning failures.
domain: cybersecurity
subdomain: identity-access-management
tags:
- scim
- okta
- provisioning
- identity-management
- automation
- sso
- lifecycle-management
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.AA-01
- PR.AA-02
- PR.AA-05
- PR.AA-06
mitre_attack:
- T1078
- T1110
- T1556
- T1098
mitre_f3:
version: '1.1'
tactics:
- initial-access
- positioning
- resource-development
techniques:
- id: T1586
name: Compromise Accounts
tactic: resource-development
source: attack
- id: F1005.002
name: 'Account Manipulation: Add Authorized User'
tactic: positioning
source: f3
- id: F1005.004
name: 'Account Manipulation: Change Account Details'
tactic: positioning
source: f3
- id: F1042
name: Reactivate Account
tactic: positioning
source: f3
- id: F1006.002
name: 'Account Takeover: Exposed Login Credential'
tactic: initial-access
source: f3
Implementing SCIM Provisioning with Okta
Overview
SCIM (System for Cross-domain Identity Management) is an open standard protocol (RFC 7644) that automates the exchange of user identity information between identity providers like Okta and service providers. This skill covers building a SCIM 2.0-compliant API endpoint and integrating it with Okta for automated user lifecycle management including provisioning, deprovisioning, profile updates, and group management.
When to Use
- When deploying or configuring implementing scim provisioning with okta capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Okta tenant with admin access (Developer or Production)
- Application with REST API capable of user management
- TLS-secured endpoint (HTTPS required)
- Okta API token or OAuth 2.0 client credentials
- Python 3.9+ with Flask or FastAPI
Core Concepts
SCIM 2.0 Protocol
SCIM defines a standard schema for representing users and groups via JSON, with a RESTful API for CRUD operations:
| Operation | HTTP Method | Endpoint | Description |
|---|---|---|---|
| Create User | POST | /scim/v2/Users | Provisions a new user account |
| Read User | GET | /scim/v2/Users/{id} | Retrieves user details |
| Update User | PUT/PATCH | /scim/v2/Users/{id} | Modifies user attributes |
| Delete User | DELETE | /scim/v2/Users/{id} | Removes user account |
| List Users | GET | /scim/v2/Users | Lists users with filtering |
| Create Group | POST | /scim/v2/Groups | Creates a group |
| Manage Group | PATCH | /scim/v2/Groups/{id} | Add/remove group members |
Okta SCIM Integration Architecture
Okta (IdP) ──SCIM 2.0 over HTTPS──> SCIM Server ──> Application Database
│ │
├── User Assignment ├── Create/Update User
├── User Unassignment ├── Deactivate User
├── Profile Push ├── Sync Attributes
└── Group Push └── Manage Groups
Required SCIM Endpoints
- ServiceProviderConfig (
/scim/v2/ServiceProviderConfig): Advertises SCIM capabilities - ResourceTypes (
/scim/v2/ResourceTypes): Describes supported resource types - Schemas (
/scim/v2/Schemas): Publishes the SCIM schema definitions - Users (
/scim/v2/Users): User lifecycle operations - Groups (
/scim/v2/Groups): Group management operations
Workflow
Step 1: Build SCIM 2.0 API Server
Create a Flask-based SCIM server that implements the core endpoints. The server must handle:
- User CRUD: Create, read, update, delete, and list users
- Filtering: Support
eqfilter onuserName(required by Okta) - Pagination: Return
startIndex,itemsPerPage, andtotalResults - Authentication: Bearer token validation on all endpoints
from flask import Flask, request, jsonify
import uuid
from datetime import datetime
app = Flask(__name__)
# Bearer token for Okta authentication
SCIM_BEARER_TOKEN = "your-secure-token-here"
def require_auth(f):
def wrapper(*args, **kwargs):
auth = request.headers.get("Authorization", "")
if not auth.startswith("Bearer ") or auth[7:] != SCIM_BEARER_TOKEN:
return jsonify({"detail": "Unauthorized"}), 401
return f(*args, **kwargs)
wrapper.__name__ = f.__name__
return wrapper
@app.route("/scim/v2/Users", methods=["POST"])
@require_auth
def create_user():
data = request.json
user_id = str(uuid.uuid4())
user = {
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
"id": user_id,
"userName": data.get("userName"),
"name": data.get("name", {}),
"emails": data.get("emails", []),
"active": True,
"meta": {
"resourceType": "User",
"created": datetime.utcnow().isoformat() + "Z",
"lastModified": datetime.utcnow().isoformat() + "Z",
"location": f"/scim/v2/Users/{user_id}"
}
}
# Persist user to database
return jsonify(user), 201
@app.route("/scim/v2/Users", methods=["GET"])
@require_auth
def list_users():
filter_param = request.args.get("filter", "")
start_index = int(request.args.get("startIndex", 1))
count = int(request.args.get("count", 100))
# Parse filter: userName eq "john@example.com"
# Query database with filter
return jsonify({
"schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
"totalResults": 0,
"startIndex": start_index,
"itemsPerPage": count,
"Resources": []
})
Step 2: Configure Okta Application
Create SCIM App Integration:
- Navigate to Okta Admin Console > Applications > Create App Integration
- Select SWA or SAML 2.0 as sign-on method
- In the General tab, select SCIM for Provisioning
Configure SCIM Connection:
- SCIM connector base URL:
https://your-app.com/scim/v2 - Unique identifier field:
userName - Supported provisioning actions: Push New Users, Push Profile Updates, Push Groups
- Authentication Mode: HTTP Header (Bearer Token)
- SCIM connector base URL:
Enable Provisioning Features:
- To App: Create Users, Update User Attributes, Deactivate Users
- Configure attribute mappings between Okta profile and SCIM schema
Step 3: Map Attributes
Map Okta user profile attributes to your SCIM schema:
| Okta Attribute | SCIM Attribute | Direction |
|---|---|---|
| login | userName | Okta -> App |
| firstName | name.givenName | Okta -> App |
| lastName | name.familyName | Okta -> App |
| emails[type eq "work"].value | Okta -> App | |
| department | urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department | Okta -> App |
Step 4: Implement Error Handling
SCIM specifies standard error response format:
{
"schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"],
"detail": "User already exists",
"status": "409",
"scimType": "uniqueness"
}
Common error codes: 400 (Bad Request), 401 (Unauthorized), 404 (Not Found), 409 (Conflict), 500 (Internal Server Error).
Step 5: Test with Runscope/Okta SCIM Validator
Okta provides an automated SCIM test suite (via Runscope/BlazeMeter) that validates your SCIM implementation against all required operations:
- Import the Okta SCIM 2.0 test suite from the OIN submission portal
- Configure the base URL and authentication token
- Run the full test suite covering user CRUD, filtering, and pagination
- Fix any failing tests before submitting to OIN
Validation Checklist
- SCIM server accessible over HTTPS with valid TLS certificate
- Bearer token authentication enforced on all endpoints
- User creation returns 201 with full user representation
- User search by
userName eq "..."filter works correctly - Pagination parameters (
startIndex,count) handled properly - User deactivation sets
active: false(not hard delete) - PATCH operations support
add,replace,removeops - Group push creates and manages group memberships
- Okta SCIM validator test suite passes all tests
- Error responses conform to SCIM error schema
References
- SCIM 2.0 Protocol RFC 7644
- Okta SCIM Developer Guide
- Build a SCIM API Service - Okta
- SCIM Core Schema RFC 7643
Other files in this skill
- LICENSE
- assets/template.md
- references/api-reference.md
- references/standards.md
- references/workflows.md
- scripts/agent.py
- scripts/process.py
assets/template.md (verbatim)
SCIM Provisioning Implementation Checklist
Project: _______________
Date: _______________
Engineer: _______________
Pre-Implementation
- Okta tenant provisioned with admin access
- Application API supports user CRUD operations
- TLS certificate configured for SCIM endpoint
- Database schema supports SCIM user attributes
- Bearer token generated and securely stored
SCIM Server Configuration
| Setting | Value |
|---|---|
| Base URL | https://______/scim/v2 |
| Auth Method | Bearer Token / OAuth 2.0 |
| SCIM Version | 2.0 |
| Unique ID Field | userName |
Attribute Mapping
| Okta Attribute | SCIM Attribute | Required | Notes |
|---|---|---|---|
| login | userName | Yes | |
| firstName | name.givenName | Yes | |
| lastName | name.familyName | Yes | |
| emails[0].value | Yes | ||
| department | enterprise:department | No | |
| title | title | No |
Endpoint Testing Results
| Endpoint | Method | Status | Notes |
|---|---|---|---|
| /Users | POST | [ ] Pass | Create user |
| /Users | GET | [ ] Pass | List/filter users |
| /Users/{id} | GET | [ ] Pass | Get single user |
| /Users/{id} | PUT | [ ] Pass | Replace user |
| /Users/{id} | PATCH | [ ] Pass | Partial update |
| /Users/{id} | DELETE | [ ] Pass | Delete user |
| /Groups | POST | [ ] Pass | Create group |
| /Groups | GET | [ ] Pass | List groups |
| /Groups/{id} | PATCH | [ ] Pass | Update members |
Okta Configuration
- SCIM app integration created
- Provisioning tab configured with base URL and token
- "To App" provisioning enabled (Create, Update, Deactivate)
- Attribute mappings verified
- Group Push configured (if needed)
- Test user assigned and provisioned successfully
- Test user unassigned and deprovisioned successfully
Validation
- Okta SCIM validator test suite passed
- Error responses return correct SCIM error format
- Pagination works with startIndex and count parameters
- Filter on userName eq works correctly
- Deactivation sets active=false (soft delete)
- PATCH operations handle add/replace/remove
Production Readiness
- SCIM endpoint uses production TLS certificate
- Bearer token rotated from development value
- Rate limiting configured on SCIM endpoints
- Monitoring and alerting set up for provisioning failures
- Provisioning error handling and retry logic tested
- Documentation updated with SCIM integration details
references/api-reference.md (verbatim)
API Reference: Okta SCIM 2.0 Provisioning
Libraries Used
| Library | Purpose |
|---|---|
requests |
HTTP client for SCIM 2.0 and Okta Management API |
json |
Parse SCIM user and group payloads |
os |
Read OKTA_DOMAIN, OKTA_API_TOKEN, SCIM_BASE_URL |
Installation
pip install requests
Authentication
Okta Management API
import requests
import os
OKTA_DOMAIN = os.environ["OKTA_DOMAIN"] # e.g., "dev-12345.okta.com"
OKTA_TOKEN = os.environ["OKTA_API_TOKEN"]
headers = {
"Authorization": f"SSWS {OKTA_TOKEN}",
"Content-Type": "application/json",
"Accept": "application/json",
}
SCIM 2.0 Endpoint (Bearer Token)
SCIM_URL = os.environ["SCIM_BASE_URL"] # e.g., "https://app.example.com/scim/v2"
scim_headers = {
"Authorization": f"Bearer {os.environ['SCIM_TOKEN']}",
"Content-Type": "application/scim+json",
}
SCIM 2.0 Endpoints
| Method | Endpoint | Description |
|---|---|---|
| GET | /scim/v2/Users |
List users with filtering |
| GET | /scim/v2/Users/{id} |
Get a specific user |
| POST | /scim/v2/Users |
Create a new user |
| PUT | /scim/v2/Users/{id} |
Replace a user (full update) |
| PATCH | /scim/v2/Users/{id} |
Partial user update (activate/deactivate) |
| DELETE | /scim/v2/Users/{id} |
Delete a user |
| GET | /scim/v2/Groups |
List groups |
| GET | /scim/v2/Groups/{id} |
Get a specific group |
| POST | /scim/v2/Groups |
Create a group |
| PATCH | /scim/v2/Groups/{id} |
Update group membership |
| GET | /scim/v2/ServiceProviderConfig |
SCIM service capabilities |
| GET | /scim/v2/Schemas |
Supported SCIM schemas |
| GET | /scim/v2/ResourceTypes |
Available resource types |
Core Operations
List SCIM Users with Filtering
resp = requests.get(
f"{SCIM_URL}/Users",
headers=scim_headers,
params={
"filter": 'userName eq "alice@example.com"',
"startIndex": 1,
"count": 100,
},
timeout=30,
)
users = resp.json()
for user in users.get("Resources", []):
print(f"{user['userName']} — active: {user.get('active', True)}")
Create a User
new_user = {
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
"userName": "bob@example.com",
"name": {"givenName": "Bob", "familyName": "Smith"},
"emails": [
{"value": "bob@example.com", "type": "work", "primary": True}
],
"active": True,
}
resp = requests.post(
f"{SCIM_URL}/Users",
headers=scim_headers,
json=new_user,
timeout=30,
)
created = resp.json()
user_id = created["id"]
Deactivate a User (PATCH)
deactivate_payload = {
"schemas": ["urn:ietf:params:scim:api:messages:2.0:PatchOp"],
"Operations": [
{"op": "Replace", "path": "active", "value": False}
],
}
resp = requests.patch(
f"{SCIM_URL}/Users/{user_id}",
headers=scim_headers,
json=deactivate_payload,
timeout=30,
)
Manage Group Membership
add_member = {
"schemas": ["urn:ietf:params:scim:api:messages:2.0:PatchOp"],
"Operations": [
{
"op": "Add",
"path": "members",
"value": [{"value": user_id, "display": "bob@example.com"}],
}
],
}
resp = requests.patch(
f"{SCIM_URL}/Groups/{group_id}",
headers=scim_headers,
json=add_member,
timeout=30,
)
Okta Management API Endpoints
| Method | Endpoint | Description |
|---|---|---|
| GET | /api/v1/apps |
List applications |
| GET | /api/v1/apps/{appId}/users |
List users assigned to an app |
| POST | /api/v1/apps/{appId}/users |
Assign user to app |
| GET | /api/v1/users |
List Okta users |
| POST | /api/v1/users/{userId}/lifecycle/deactivate |
Deactivate user |
List Okta Applications with SCIM Provisioning
resp = requests.get(
f"https://{OKTA_DOMAIN}/api/v1/apps",
headers=headers,
params={"filter": 'status eq "ACTIVE"', "limit": 50},
timeout=30,
)
for app in resp.json():
features = app.get("features", [])
if "PUSH_NEW_USERS" in features or "PUSH_PROFILE_UPDATES" in features:
print(f"SCIM-enabled: {app['label']} — features: {features}")
Output Format
{
"schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
"totalResults": 42,
"startIndex": 1,
"itemsPerPage": 100,
"Resources": [
{
"id": "2819c223-7f76-453a-919d-ab1234567890",
"userName": "alice@example.com",
"name": {"givenName": "Alice", "familyName": "Johnson"},
"active": true,
"emails": [{"value": "alice@example.com", "type": "work", "primary": true}]
}
]
}
references/standards.md (verbatim)
SCIM Provisioning Standards Reference
Protocol Standards
RFC 7644 - SCIM Protocol
- Defines the RESTful API for managing identity resources
- Specifies HTTP methods, headers, and response formats
- Mandates JSON as the data interchange format
- Requires TLS for all communications
RFC 7643 - SCIM Core Schema
- Defines User, Group, and EnterpriseUser schemas
- Specifies attribute types: string, boolean, decimal, integer, dateTime, reference, complex, binary
- Defines mutability: readOnly, readWrite, immutable, writeOnly
- Specifies attribute uniqueness: none, server, global
RFC 7642 - SCIM Definitions, Overview, Concepts, and Requirements
- Provides context for the SCIM specification
- Defines terminology and use cases
- Outlines design requirements for cross-domain provisioning
Okta SCIM Requirements
Mandatory Endpoints
| Endpoint | Methods | Purpose |
|---|---|---|
| /Users | GET, POST | User listing and creation |
| /Users/{id} | GET, PUT, PATCH, DELETE | Individual user operations |
| /Groups | GET, POST | Group listing and creation |
| /Groups/{id} | GET, PATCH, DELETE | Individual group operations |
Required Filter Support
userName eq "value"- Exact match on userNameid eq "value"- Exact match on user IDdisplayName eq "value"- Exact match for groups
Pagination Requirements
- Support
startIndexandcountquery parameters - Return
totalResultsin ListResponse - Default
startIndexis 1 (1-based indexing) - Maximum
countshould be configurable
Compliance Standards
SOC 2 Type II
- Automated provisioning demonstrates access control effectiveness
- Deprovisioning within defined SLA shows timely access removal
- Audit logs of SCIM operations provide evidence for access reviews
ISO 27001 - A.9.2 User Access Management
- A.9.2.1: User registration and deregistration (automated via SCIM)
- A.9.2.2: User access provisioning (role-based assignment)
- A.9.2.5: Review of user access rights (SCIM audit logs)
- A.9.2.6: Removal of access rights (automated deprovisioning)
NIST SP 800-53 - AC (Access Control)
- AC-2: Account Management (automated lifecycle)
- AC-2(1): Automated System Account Management
- AC-2(4): Automated Audit Actions
- AC-6: Least Privilege (role-based provisioning)
references/workflows.md (verbatim)
SCIM Provisioning Workflows
User Provisioning Workflow
1. Admin assigns user to Okta application
│
2. Okta checks if user exists (GET /Users?filter=userName eq "user@domain.com")
│
├── User NOT found → Okta sends POST /Users with user attributes
│ │
│ └── SCIM server creates user → Returns 201 Created
│
└── User found → Okta sends PUT /Users/{id} to update attributes
│
└── SCIM server updates user → Returns 200 OK
User Deprovisioning Workflow
1. Admin unassigns user from Okta application (or user deactivated in Okta)
│
2. Okta sends PATCH /Users/{id}
Body: {"schemas":["urn:ietf:params:scim:api:messages:2.0:PatchOp"],
"Operations":[{"op":"replace","value":{"active":false}}]}
│
3. SCIM server deactivates user (sets active=false, revokes sessions)
│
4. Returns 200 OK with updated user object
Group Push Workflow
1. Admin enables Group Push for Okta group
│
2. Okta sends POST /Groups with group name and initial members
│
3. When group membership changes in Okta:
│
├── Member added → PATCH /Groups/{id}
│ Op: add, path: members, value: [{value: userId}]
│
└── Member removed → PATCH /Groups/{id}
Op: remove, path: members[value eq "userId"]
Profile Sync Workflow
1. User profile updated in Okta (e.g., department change)
│
2. Okta sends PUT /Users/{id} or PATCH /Users/{id}
Body includes updated attributes
│
3. SCIM server updates user attributes in local database
│
4. Returns 200 OK with full updated user representation
Error Recovery Workflow
1. SCIM operation fails (network timeout, server error)
│
2. Okta logs failed task in Provisioning > Tasks
│
3. Admin can retry individual failed tasks
│
4. For persistent failures:
├── Check SCIM server logs for error details
├── Verify network connectivity and TLS certificate
├── Validate bearer token has not expired
└── Review attribute mapping for data format issues
Implementation Testing Workflow
1. Deploy SCIM server to staging environment
│
2. Configure Okta SCIM integration with staging URL
│
3. Run Okta SCIM validator test suite
│
4. Test manual operations:
├── Assign test user → verify account created
├── Update user profile → verify attributes synced
├── Unassign user → verify account deactivated
└── Push group → verify group and members created
│
5. Review provisioning logs in Okta Admin Console
│
6. Promote to production with production SCIM URL
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.