Skip to content
digitalsign.co

SCIM provisioning

Your identity provider adds people, sets their roles and removes their access the moment they leave. SCIM 2.0, on the Enterprise plan.

Set up

  1. In DigitalSign, open Settings → Security and click Generate token under Automatic provisioning. Copy the token now; it is shown once.
  2. In your identity provider, set the SCIM base URL to https://app.digitalsign.co/scim/v2 and the authentication to a bearer token (HTTP header) with that token.
  3. Map the provider's email (or user principal name) to userName. Enable create, update and deactivate.

Rotating the token stops the old one immediately. Turning provisioning off leaves existing members in place.

Okta

In your app integration, enable SCIM provisioning. On Provisioning → Integration: SCIM connector base URL as above, unique identifier field userName, supported actions Push New Users and Push Profile Updates, authentication mode HTTP Header. Then under To App, enable Create Users, Update User Attributes and Deactivate Users.

Microsoft Entra ID

Open your enterprise application → Provisioning → mode Automatic. Tenant URL is the SCIM base URL, Secret Token is the token. Test the connection, check that userPrincipalName (or mail) maps to userName, then start provisioning.

What happens to people

In your providerIn DigitalSign
Assign someoneThey become a member with the role you send, or your default single sign-on role, or Viewer. Someone already invited keeps their current role.
Change their roleTheir role changes. Send a roles value of admin, designer, publisher, location_manager or viewer.
Change their emailAccess moves to the new address.
Deactivate or unassign themTheir access is removed and they are signed out immediately. Single sign-on won't let them back in until they are reactivated.
Reactivate themAccess returns with their previous role.
Delete themTheir access is removed and the SCIM record is deleted.

Owners are never changed over SCIM, and nobody can be made an owner over SCIM, so a provisioning mistake can't lock you out. Every change is recorded in the audit log as made by your identity provider.

Reference

Base URL https://app.digitalsign.co/scim/v2, header Authorization: Bearer ds_scim_…, content type application/scim+json. Up to 600 requests a minute.

EndpointNotes
GET /ServiceProviderConfig, /ResourceTypes, /SchemasDiscovery
GET /UsersFilters: userName eq "…", externalId eq "…", emails eq "…". Paging with startIndex and count (up to 200).
POST /UsersCreate. userName must be an email address. Returns 409 if the person is already provisioned.
GET /Users/:idRead one user
PUT /Users/:idReplace
PATCH /Users/:idPatchOp with add, replace or remove on active, userName, name.givenName, name.familyName, emails, externalId and roles, with or without a path
DELETE /Users/:idRemove access and delete the record (204)
GET /GroupsReturns an empty list; groups are not used for access
curl https://app.digitalsign.co/scim/v2/Users \
  -H "Authorization: Bearer ds_scim_…" \
  -H "Content-Type: application/scim+json" \
  -d '{
    "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
    "userName": "[email protected]",
    "name": { "givenName": "Jane", "familyName": "Doe" },
    "active": true,
    "roles": [{ "value": "publisher" }]
  }'

Errors use the SCIM error format: { "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"], "status": "400", "scimType": "invalidFilter", "detail": "…" }