Skip to main content
SCIM (System for Cross-domain Identity Management) is an open standard for automating user provisioning. When SCIM is configured, your Identity Provider (IdP) automatically creates, updates, deactivates, and deletes Prizm user accounts whenever changes are made in your directory — no manual user management required.

How it works

  1. Prizm exposes a SCIM Callback URL visible under Profile → Organization → SSO/SAML.
  2. You configure your IdP to send provisioning requests to that URL using a bearer token for authentication.
  3. Whenever a user is added, changed, or removed in your IdP, it pushes a SCIM request to Prizm.
  4. Prizm applies the change — creating the account, updating the profile, or deactivating access.

Supported providers

IBM Security Verify supports user provisioning only. Group synchronization is not available for IBM. Use Okta, Azure AD, or Ping Identity if group-based access management is required.

What SCIM manages

Prerequisites

  • SAML SSO must already be configured in Prizm for your IdP before enabling SCIM.
  • You need admin access to both Prizm (Profile → Organization → SSO/SAML) and your IdP.
  • A static bearer token is required for the IdP to authenticate to Prizm’s SCIM endpoint.

Finding the SCIM Callback URL

  1. In Prizm, navigate to Profile → Organization → SSO/SAML.
  2. Locate the SCIM Callback URL field (read-only).
  3. Copy this URL — paste it into your IdP’s SCIM provisioning configuration as the SCIM Base URL or Tenant URL.

Setup by provider

Prerequisites

  • Okta SAML SSO is already configured for Prizm.
  • You have Okta Administrator access.
  • You have the Prizm SCIM Callback URL.

Step 1 — Open SCIM provisioning in Okta

  1. In the Okta Admin Console, navigate to Applications and open the Prizm SAML application.
  2. Go to the Provisioning tab → Integration section.
  3. Click Configure API Integration and enable API Integration.

Step 2 — Configure the SCIM endpoint

Click Test API Credentials to verify the connection, then Save.

Step 3 — Enable provisioning to app

Under Provisioning → To App, enable:

Step 4 — Map attributes

Step 5 — Push groups (optional)

  1. Go to the Push Groups tab in the Provisioning section.
  2. Click Push Groups and search for the Okta groups to sync.
  3. Select the groups and click Save.
Prizm creates matching groups and keeps membership in sync with Okta.

SCIM endpoints

All IdPs use the same Prizm SCIM endpoints:
IBM Security Verify does not call the Groups endpoints. Group endpoints are used by Okta, Azure AD, and Ping Identity only.