SCIM and OAuth 2.0 Integration Guide

This guide explains configuring **SCIM provisioning** using **OAuth 2.0 authentication** to synchronize users between your Identity Provider (IdP) and our system. Your IdP (such as Okta, Azure AD, or OneLogin) will use **SCIM 2.0** to provision and manage users while authenticating via **OAuth 2.0**.

Updated

1. SCIM API Authentication (OAuth 2.0)

Our system acts as both:

  • SCIM Service Provider (receiving provisioning requests)
  • OAuth 2.0 Authorization Server (providing Bearer tokens for authentication)

Before configuring SCIM, you must obtain OAuth 2.0 client credentials or an Access token by contacting our support team. Once provided, you will enter these credentials in your IdP.

2. Configuring SCIM Provisioning

This section provides a step-by-step guide to configuring SCIM provisioning using OAuth 2.0 or Access token. The following screenshots illustrate the configuration process within an identity provider. Your UI may differ slightly, but the required fields will be similar.

Step 1: Create a New App Integration

A new SAML 2.0 application needs to be created in the identity provider.

SAML 2.0 should be used as the authentication method.

Step 2: Configure General Settings

The application requires a name and optional logo.

FieldValue
App NameEnter a relevant name (e.g., "MuchSkills")
App Logo (Optional)Upload a relevant logo
App VisibilityConfigure whether to display the app icon to users

Step 3: Configure SAML Settings

SAML authentication settings require the correct endpoints.

FieldValue
Single Sign-On URLhttps://app.muchskills.com/auth/saml/{YOUR_ID}
Audience URI (SP Entity ID)https://app.muchskills.com/auth/saml
Application UsernameEmail

Single Sign-On URL is the endpoint from which authentication requests are sent.

Audience URI uniquely identifies the system as a SAML service provider.

Application Username must be set to Email, as our SCIM integration uses email as the unique identifier.

Step 4: Configure SCIM Connection

In your identity provider, navigate to the SCIM connection settings and enter the following details:

FieldValue
SCIM Version2.0
SCIM Connector Base URLhttps://app.muchskills.com/scim/v2
Unique Identifier for Usersemail
Supported Provisioning ActionsEnable: Push New Users, Push Profile Updates

🔹 Note: Group provisioning is not supported in this SCIM implementation, so leave "Push Groups" and "Import Groups" unchecked.

Step 5: Configuring Authentication

SCIM requests can be authenticated using the OAuth 2.0 flow. It is preferred to use the OAuth 2.0 flow as it provides a more secure and dynamic authentication method. However, if your identity provider does not support OAuth 2.0, you can use an access token as described in section 5.2.

5.1. OAuth 2.0 Flow.

The identity provider requires the correct OAuth 2.0 settings to issue Bearer tokens.

FieldValue
Authentication ModeOAuth 2.0
Access Token Endpoint URIhttps://app.muchskills.com/oauth2/token
Authorization Endpoint URIhttps://app.muchskills.com/oauth2/authorize
Client IDProvided by support
Client SecretProvided by support

Click Test Connection or Authenticate to verify the integration. The access token endpoint is used to obtain a Bearer token, which is required for all SCIM API requests. Once configured, the identity provider will automatically request new tokens as needed.‍

5.2. Access token.

The identity provider requires the correct OAuth 2.0 settings to issue Bearer tokens.

FieldValue
Authentication ModeAccess token/Bearer token
Access TokenProvided by support

Click Test Connection or Authenticate to verify the integration.

3. SCIM API Endpoints

SCIM Base URL

All SCIM operations use the following base URL:https://app.muchskills.com/scim/v2

Supported SCIM Operations

GET/scim/v2/UsersRetrieve all users (supports pagination & basic filtering)
GET/scim/v2/Users/{id}Retrieve a specific user
POST/scim/v2/UsersCreate a new user
PUT/scim/v2/Users/{id}Update a user (full replace)
PATCH/scim/v2/Users/{id}Update specific attributes
DELETE/scim/v2/Users/{id}Remove a user from the system

Filtering & Pagination

  • Filtering: Supports eq (equals) on userName (email). Example:filter=userName eq "email@example.com"
  • Pagination: Uses startIndex and count parameters.

Group Management

The/Groups endpoint is available but only returns predefined roles (member, manager, admin).

  • No support for custom groups or group membership management.

4. SCIM Field Mapping

SCIM allows mapping user attributes between your identity provider and MuchSkills. The table below maps SCIM user attributes to our internal system.

SCIM FieldSCIM TypeOur System FieldNotes
idStringUser IDInternal unique identifier
userNameStringEmail/LoginMust be a valid email, used for login
displayNameStringFull NameUsed as primary display name
name.formattedStringFull NameSame as displayName
name.givenNameStringFull NameUsed to construct displayName
name.familyNameStringFull NameUsed to construct displayName
emailsArrayEmail(s)Primary email is required and must match userName
rolesArrayUser role(s)Optional field. Primary role will be assigned to the user. Valid values: Admin, Member, Analyst. Other values will be ignored. Default value is Member
activeBooleanUser Statusfalse triggers deletion from our system
titleStringJob TitleOptional field
photosArrayProfile PictureSupports multiple entries, type can be 'photo' or 'thumbnail'
photos.valueURLProfile PictureIf provided, the image is stored in our system
addresses.regionStringLocationUsed to construct city part of Location
addresses.localityStringLocationUsed to construct country part of Location
addresses.countryStringLocationCan be used instead of addresses.locality to construct country part of Location

Enterprise User Extension

SCIM FieldSCIM TypeOur System FieldNotes
departmentStringDepartmentDepartment name (created if missing)
manager.valueStringManager ID or EmailMust be a valid user ID or email

MuchSkills User Extension

SCIM FieldSCIM TypeOur System FieldNotes
profilePictureStringProfile PictureAn alternative and simpler way to provide a profile picture. Can be used instead of the photos array.

5: Assign Users

  1. Navigate to the Users or Assignments section in your identity provider.
  2. Select users who should be provisioned in MuchSkills.
  3. Click Assign or Enable SCIM Provisioning for selected users.
  4. Enable automatic user provisioning if your identity provider has this setting.
  5. Click Sync Now or Force Sync to trigger the initial synchronization.
  6. Confirm that users appear in [Your App] under the Users section.

Details:

The following JSON schema represents a SCIM user object as used in our system. This example includes core user attributes, enterprise extension and MuchSkills extension fields.

7. Troubleshooting

The table below lists common issues encountered when integrating SCIM provisioning with OAuth 2.0 in identity providers like Okta and OneLogin.

IssuePossible CauseResolution
SCIM requests fail with 401 UnauthorizedInvalid OAuth 2.0 credentials or Access tokenEnsure the token is refreshed every 15 minutes. Verify that the correct Access token or OAuth 2.0 client credentials are used.
User provisioning fails with 409 ConflictUser already exists in the systemCheck if the email is already in use. Ensure that userName is a unique email.
Users are not appearing in the system after being pushed from the IdPThe SCIM response was not processed correctlyCheck provisioning logs in the IdP for errors. Ensure that the userName (email) format is valid and matches the expected format.
Changes to users in IdP are not reflected in the systemSCIM updates are not being sent correctlyVerify that "Push Profile Updates" is enabled in the IdP's SCIM provisioning settings. Check if PUT or PATCH requests are being made successfully.
Error: invalid_filter when retrieving usersUnsupported SCIM filter operatorEnsure filters use only eq for userName
Error: user not found when updating or deleting usersThe user does not exist in the systemVerify that the user ID in the request matches an existing SCIM user. Use GET /scim/v2/Users to check if the user exists.
SCIM request returns 500 Internal Server ErrorUnexpected error on the service sideContact support with the request details. Verify if the issue is due to an incorrect payload format.

Okta example:

JvCypuJwyAf2lnHHwiwiC33nBElhgLOLM8JEpotWdUl8xpyDtcQWKKYHmth6GTHcWobaEMN7tY7cSuiCqh93zX0sTtCHnOl i MJrGS6qHCZgi800fx4
X9FKAxxoAOOUH8Yupne4oanUriSEINMuPTGMubUTVuegLhOossFPc OYKyzixwfoTPdxX hbfH6me5r2e yEVoxOjN 9n6JaCAQ8xXO5tdFwaT4BYS8Q

‍

BlLYW3ypPQ8x yuwFueoU8BgyxyqyFCNn0B8m 3ive3UFy9 a90Mo2 LosKT9rpJXpJ0kuzIQZgsPvpfgJhY q9MWimRV3UZOTZANgTtyqO0gW3Avyw
TE6Bq2FWHbYraXRJqbG1yV7BrlQ6gsM roTDhjpzD3OukHeRHXA B2v7Fu8PmBCk9sGFeM1uwjtSqMpCpfHQttRY0ePPD0EY69IzV0CllmV6bYVW2Zfl
X7AnOw29ffCNkAgIqBIixkkF v8 xbQIcF1zQZ21XcOgYBiESziC0eOKGNZOJAOmuM8WWdz76TNDVquKdY1BX4b1jtxXpGjww7n9wInYPU3QMxiQ2PA
X0axzX6fjO JQZd49m 0OFfUD2Ihmfia3fYs0wpuuEipb4Qb39eNozrxcgMFNx1e0Lg69MNFn giu6cUlv8Dj 2O9TWqpx9ng8MYgoyGVtiKAGnXL4MQ
Ej2RzWKqtl0QpNiANszCNUPR0Ob oKXR97noKqGlgOUD5 V2TuEwCbflRzNuY PjTrPMNl7jq0DCsCC5XxKCtvp0qlikYNwkSQdlSt3B0Y90TH6Jtfe4

OneLogin example:

B7lxZjuLfzMZWCcXSPRAkyBA8FwF Jv ivwYpTlrswF1o7oIYUr WR QomNtmxoxjvuiyHp1e GjMbn5AUTUmDa4KswOYLM1t9 KWRqdRMd8 PyVCYQ1
TYAZaArsyyx3LH5TLa0z0mzxsLYZ4wlqXZFRAZtQiI YA7SwJihqefZeCjAE0suAj1Kia8t6JQPYRHSHDyP42A6FGUUrFz73jhg9k03ODPR6P9fBrZ6
QPwioN5HfyQY3dxDbm7R274nPTJ FWWODX1l6mWYc2FZO5ssQQlkz5V 5VNGMHwzIWj9RDTgCNNM0YUwvAswiuERVC27ffKs1VZWHpLx6ZKSa8CF9u3Q

‍

KHqYpGkTGLI62fgsw9KYNcEEhVQnvsgjkoE0KZRCkQepSFFgvgWEEbD5U fE4Ns8IsmmAH4L6GirKz8T9qF4xd9vUgHziCR9SFU5Pm EK zo3n1DTEtP

‍

Microsoft Entra example:

AfWzZn5xsHQOHc0 G6rMirmuAq82nbG6C3rhwwrOOWUZVayXCau98oFxt3pXJB2qwBaYNOu cFQN6y Uoaa4CTfXgD7uC5iWrfK7uDmRHPVYyRDJpFqw
U3f5J0nwRWkoDpSh ggiX3JMSqg7YVdDwkNRQebmUUmcTcrC98GMNkqXB8 2mVqVy49BHtKLMuF3WY36ZI BgomvIShbX3uKR6KtT92KUVsSYcN6T EA
9xN O2q8 YUIj7zG 7KQVj0JrFD9jZi3ix U2EfM4LaRnHD jFwabs4CRKzzbrnWeSqCJ6PjgxSOaD0sXk2AtP0en W3aFAogyusD ZE46OFneTaIUg
PnYuTqF0KOUSNvkIa5s9x8 xeeFkxHBdUFDnXLIvjnBEeZS9x1LVydvnKkQNoOaHU2piMLFgSD bP8s5tzYEC435HyHB 2Wvmt2t9tLKr1osVsxmCNA

Add credentials using OAuth2 Client Credentials Grant :

697aeff54d25cda58b282bb2 scim 1

Or alternatively with Bearer Authentication :

697af0304451326c24636685 scim 2

Configure attribute mapping:

697af07c9a8688cfa770311d scim 3
697af08bbcda3150c758bf5b scim 4

To set up role field mapping, use the following configuration:

Mapping type: Expression

Expression: SingleAppRoleAssignment([appRoleAssignments])

Target attribute: roles[primary eq "True"].value

697af0d4d04808911124b958 scim 5

To add valid role options for your assignments:

Go to Home > App registrations > Your App > App roles

There, create roles Member, Analyst, Admin

697af133c16d7711317e2efb scim 6

Roles will be available to add/edit app assignments:

697af1555b32e7f9e9751c76 scim 7

‍

FLZfjh0DuB ncgdluf5aY7CBe6tnKFoBnQH jzH E2xpgLpNyB04w3YBmNTJX6f0Iy25Eac2HqphSCaIF8a3Iw73LlVHLBptfyDDMkaU5tfNLbIh9kbD

‍

‍

Checking Daniel’s calendar...

Ask us anything

A real person replies, usually the same working day.

Live webinar · 13 Oct, 17:00 CEST

How to analyse the Skill Gaps in your organisation

MuchSkills allows organisations to conduct an in-depth skills gap analysis in a matter of minutes and uncover the skill gaps that hurt organisational performance In this webinar, you will learn how t…