SCIM provisioning
Set up
- In DigitalSign, open Settings → Security and click Generate token under Automatic provisioning. Copy the token now; it is shown once.
- In your identity provider, set the SCIM base URL to
https://app.digitalsign.co/scim/v2and the authentication to a bearer token (HTTP header) with that token. - Map the provider's email (or user principal name) to
userName. Enable create, update and deactivate.
Rotating the token stops the old one immediately. Turning provisioning off leaves existing members in place.
Okta
In your app integration, enable SCIM provisioning. On Provisioning → Integration: SCIM connector base URL as above, unique identifier field userName, supported actions Push New Users and Push Profile Updates, authentication mode HTTP Header. Then under To App, enable Create Users, Update User Attributes and Deactivate Users.
Microsoft Entra ID
Open your enterprise application → Provisioning → mode Automatic. Tenant URL is the SCIM base URL, Secret Token is the token. Test the connection, check that userPrincipalName (or mail) maps to userName, then start provisioning.
What happens to people
| In your provider | In DigitalSign |
|---|---|
| Assign someone | They become a member with the role you send, or your default single sign-on role, or Viewer. Someone already invited keeps their current role. |
| Change their role | Their role changes. Send a roles value of admin, designer, publisher, location_manager or viewer. |
| Change their email | Access moves to the new address. |
| Deactivate or unassign them | Their access is removed and they are signed out immediately. Single sign-on won't let them back in until they are reactivated. |
| Reactivate them | Access returns with their previous role. |
| Delete them | Their access is removed and the SCIM record is deleted. |
Owners are never changed over SCIM, and nobody can be made an owner over SCIM, so a provisioning mistake can't lock you out. Every change is recorded in the audit log as made by your identity provider.
Reference
Base URL https://app.digitalsign.co/scim/v2, header Authorization: Bearer ds_scim_…, content type application/scim+json. Up to 600 requests a minute.
| Endpoint | Notes |
|---|---|
GET /ServiceProviderConfig, /ResourceTypes, /Schemas | Discovery |
GET /Users | Filters: userName eq "…", externalId eq "…", emails eq "…". Paging with startIndex and count (up to 200). |
POST /Users | Create. userName must be an email address. Returns 409 if the person is already provisioned. |
GET /Users/:id | Read one user |
PUT /Users/:id | Replace |
PATCH /Users/:id | PatchOp with add, replace or remove on active, userName, name.givenName, name.familyName, emails, externalId and roles, with or without a path |
DELETE /Users/:id | Remove access and delete the record (204) |
GET /Groups | Returns an empty list; groups are not used for access |
curl https://app.digitalsign.co/scim/v2/Users \
-H "Authorization: Bearer ds_scim_…" \
-H "Content-Type: application/scim+json" \
-d '{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
"userName": "[email protected]",
"name": { "givenName": "Jane", "familyName": "Doe" },
"active": true,
"roles": [{ "value": "publisher" }]
}'Errors use the SCIM error format: { "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"], "status": "400", "scimType": "invalidFilter", "detail": "…" }