> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting up SCIM provisioning for Okta

> Automatically sync your Okta users with your Base44 enterprise workspace using SCIM.

SCIM provisioning keeps your Base44 enterprise workspace membership in sync with Okta. Because Okta OIDC apps do not support SCIM, you create a separate SCIM app, connect it to Base44, map attributes, and turn on provisioning so members are added, updated, and removed for you. To let your team sign in, set up [SSO for Okta](/Enterprise/Okta-SSO) separately.

<Warning>
  SCIM provisioning is available on enterprise workspaces only. If you do not see this option, contact your Base44 account team.
</Warning>

***

## Before you begin

Make sure you have:

* Owner or admin access to your Base44 enterprise workspace.
* Admin access to your Okta organization.
* Your **SCIM Base URL**, found in **Settings** > **Auth and security**.
* A **Workspace API key**, found in **Settings** > **Secrets**.

***

## Set up SCIM provisioning

Create a SCIM app in Okta, connect it to Base44, map your roles and attributes, then turn on provisioning.

### Step 1: Create a SCIM app

Okta OIDC apps do not support SCIM, so you need a separate SCIM app.

**To create the SCIM app:**

1. In the Okta Admin Console, go to **Applications** > **Browse App Catalog**.
2. Search for **SCIM 2.0 Test App (Header Auth)**.
3. Click **Add Integration**.
4. Name the app (for example, `Base44 - SCIM Provisioning`), then click **Done**.

<Frame caption="Finding the SCIM 2.0 Test App in the Okta App Catalog">
  <img src="https://mintcdn.com/base44/q-0rQebcDVt4yD7e/images/Finding-SCIM.avif?fit=max&auto=format&n=q-0rQebcDVt4yD7e&q=85&s=c5b6dda3e01bfa13782813d4fe9abf57" alt="Okta App Catalog showing the SCIM 2.0 Test App" width="3592" height="2294" data-path="images/Finding-SCIM.avif" />
</Frame>

### Step 2: Connect to Base44

Point Okta at your Base44 workspace using your SCIM Base URL and Workspace API key.

**To configure the API integration:**

1. Open your new SCIM app and go to the **Provisioning** tab.
2. Click **Configure API Integration**, then check **Enable API integration**.
3. Set **SCIM 2.0 Base URL** to your SCIM Base URL from **Settings** > **Auth and security**.
4. Set **API Token** to your Workspace API key, with no `Bearer` prefix.
5. Click **Test API Credentials**. You should see a success confirmation.
6. Click **Save**.

<Frame caption="Entering your Base44 SCIM Base URL and API key in Okta">
  <img src="https://mintcdn.com/base44/uvqvolhCRiuXC-Fl/images/Entering-Base44-SCIM.png?fit=max&auto=format&n=uvqvolhCRiuXC-Fl&q=85&s=73db325f7ad270887dc3294622772e95" alt="Okta SCIM API integration settings with the Base44 Base URL and API token" width="2066" height="952" data-path="images/Entering-Base44-SCIM.png" />
</Frame>

### Step 3: Enable provisioning actions

Choose which actions Okta can perform on your Base44 workspace members.

**To enable provisioning:**

1. In the **Provisioning** tab, click **To App**, then **Edit**.
2. Enable **Create Users**, **Update User Attributes**, and **Deactivate Users**.
3. Click **Save**.

<Frame caption="Enabling Create, Update, and Deactivate in Okta">
  <img src="https://mintcdn.com/base44/hlI9x1XC8FbBhXd9/images/scim-okta-app-provisioning.png?fit=max&auto=format&n=hlI9x1XC8FbBhXd9&q=85&s=37b3191240919cbbce0f6a2adab6905e" alt="Okta provisioning To App settings with create, update, and deactivate enabled" width="1400" height="1290" data-path="images/scim-okta-app-provisioning.png" />
</Frame>

### Step 4: Add custom attributes

Base44's role and credit limit fields are not in Okta's default profile, so add them first. In the Profile Editor you can also remove attributes Base44 does not use, keeping `userName`, `givenName`, and `familyName`.

**To add the `role` attribute:**

1. Go to **Directory** > **Profile Editor** and open your SCIM app.
2. Click **Add Attribute** and set:
   * **Data type:** String
   * **Display name:** Role
   * **Variable name:** `role`
   * **External name:** `role`
   * **External namespace:** `urn:base44:params:scim:schemas:extension:user:2.0`
   * **Enum:** Check **Define enumerated list of values** and add `admin`, `editor`, and `viewer`.
   * **Attribute required:** No
3. Click **Save**.

**To add the `creditLimit` attribute (optional):**

Skip this if you do not want per-member credit caps. The default is no cap.

1. In the same Profile Editor, click **Add Attribute** and set:
   * **Data type:** Integer
   * **Display name:** Credit Limit
   * **Variable name:** `creditLimit`
   * **External name:** `creditLimit`
   * **External namespace:** `urn:base44:params:scim:schemas:extension:user:2.0`
   * **Attribute required:** No
2. Click **Save**.

<Frame caption="Adding the Base44 attributes in the Okta Profile Editor">
  <img src="https://mintcdn.com/base44/hlI9x1XC8FbBhXd9/images/scim-okta-profile-editor.png?fit=max&auto=format&n=hlI9x1XC8FbBhXd9&q=85&s=c1e47735ca5e6ac5d8e7a6de9dd4e4fe" alt="Okta Profile Editor showing the Base44 SCIM app custom attributes" width="1400" height="1094" data-path="images/scim-okta-profile-editor.png" />
</Frame>

### Step 5: Map attributes and assign users

Map the Base44 attributes, then assign users so they are provisioned.

**To map the attributes:**

1. Go to your SCIM app > **Provisioning** > **To App** > **Attribute Mappings**.
2. Set:
   * `userName` to `user.email`
   * `role` to `"editor"`, or map it from your IdP's role attribute
   * `creditLimit` to your preferred value or IdP attribute, if you added it
3. Remove any unsupported mappings, such as `firstName`, `lastName`, and `displayName`.
4. Click **Save**.

**To assign and test a user:**

1. Go to the **Assignments** tab, click **Assign**, then **Assign to People**.
2. Select a user, set their `role` and optionally their `creditLimit`, then click **Save and Go Back** and **Done**.
3. Check your Base44 workspace members to confirm the user appears.

<Frame caption="A user assigned to both the SSO and SCIM apps in Okta">
  <img src="https://mintcdn.com/base44/P9saERX5zek6x00T/images/assign.png?fit=max&auto=format&n=P9saERX5zek6x00T&q=85&s=ed3abc4e3219a412ad0a3a632c0a010c" alt="Okta showing a user assigned to both the Base44 SSO and SCIM apps" width="2130" height="1208" data-path="images/assign.png" />
</Frame>

**To test deactivation:**

1. On the **Assignments** tab, click **Unassign** next to the user, then confirm.
2. Check that the user is no longer an active member in Base44 and their seat is released.

<Note>
  Assign each user to both your Okta SSO app and your SCIM app. Assigning to the SCIM app only provisions the user but does not let them sign in.
</Note>

***

## Roles and credit limits

Base44 accepts only the following roles via SCIM. Map your Okta `role` attribute to these exact values.

| Role     | What they can do                                                |
| -------- | --------------------------------------------------------------- |
| `admin`  | Manage members, billing, and workspace settings                 |
| `editor` | Build, edit, and run apps; uses credits from the workspace pool |
| `viewer` | Read-only access to apps; does not consume credits              |

`owner`, `member`, and `guest` cannot be assigned via SCIM. Credit limits apply only to `admin` and `editor` roles, since viewers do not consume credits. Setting a credit limit of `0` is treated as no cap. You can also set credit limits directly in your workspace, without SCIM. See [Managing enterprise workspace members](/Enterprise/managing-enterprise-members#per-member-credit-limits).

<Note>
  Workspace owners cannot be updated or deactivated through SCIM. Promote or demote owners from your workspace settings instead.
</Note>

***

## FAQs

Select a question below to learn more about Okta SCIM provisioning.

<AccordionGroup>
  <Accordion title="The API credentials test failed">
    Check that your API token is your Workspace API key with no `Bearer` prefix, and that the SCIM Base URL was copied from **Settings** > **Auth and security** with the correct workspace ID.
  </Accordion>

  <Accordion title="The Deactivate Users option is missing">
    Okta OIDC apps do not support SCIM. Use the **SCIM 2.0 Test App (Header Auth)** from the App Catalog instead.
  </Accordion>

  <Accordion title="A user is not being provisioned">
    Check your Okta provisioning logs for errors, and confirm `role` is one of `admin`, `editor`, or `viewer`. `owner`, `member`, and `guest` are rejected.
  </Accordion>

  <Accordion title="Why must I assign users to both apps?">
    The SCIM app provisions the member, and the SSO app lets them sign in. Assigning to only one means they either cannot sign in or are not provisioned.
  </Accordion>
</AccordionGroup>
