Set up SCIM with Okta
Step-by-step Okta provisioning setup for Joring, including Push Groups and roles on synced groups.
This walkthrough connects Okta provisioning to Joring. You need Okta admin access and the Base URL and a bearer token from Settings → SCIM in Joring (see SCIM provisioning).
1. Create the app integration
- In the Okta Admin Console, go to Applications → Applications.
- Provisioning is configured per app. If you already use SSO, open your existing Joring SAML/OIDC app. Otherwise select Create App Integration and choose SWA.
- On the app's General tab, under App Settings, check Enable SCIM provisioning and save. A Provisioning tab appears on the app.
2. Point Okta at Joring
On Provisioning → Integration, click Edit and fill in:
| Okta field | Value |
|---|---|
| SCIM connector base URL | Your Joring Base URL (https://api.joring.ai/scim/v2/{connection_id}) |
| Unique identifier field for users | userName |
| Supported provisioning actions | Push New Users, Push Profile Updates, Push Groups |
| Authentication mode | HTTP Header |
| Authorization | Bearer, paste your jor_scim_ token |
Click Test Connector Configuration. Okta calls /Users and
/ServiceProviderConfig; both should pass. Then click Save.
3. Enable provisioning to app
On Provisioning → To App, enable:
- Create Users
- Update User Attributes
- Deactivate Users
Okta never deletes users over SCIM; unassigning someone sends a deactivation, which frees their Joring seat and ends their sessions. Reassigning them reactivates the account.
4. Assign people and push groups
- On the Assignments tab, assign the people or groups who should have Joring accounts. Assignment triggers provisioning.
- On the Push Groups tab, add the groups you want mirrored into Joring
(for example
Joring Admins). Pushed groups appear under People → Groups in Joring, marked as synced from Okta.
Assignment provisions, Push Groups mirrors
Assigning a group creates its members as users. Push Groups additionally creates the group itself and keeps its membership in sync, which is what roles on groups are built on.
If a group managed in Joring already has the same name as a pushed group, the push takes it over: Okta's membership replaces the group's members, and the group keeps its description, roles, and managers. See link by name.
5. Assign roles on the groups (optional)
In Joring, open People → Groups, open a pushed group, and assign roles
on it (for example Admin on Joring Admins). From then on, moving someone in
or out of the group in Okta grants or removes those roles on the next sync.
See roles through groups. If Okta
sends the manager attribute, reporting lines sync too; see
reporting lines from your directory.
Verify
- Assign a test user in Okta and confirm they appear in Settings → SCIM → Directory as Active.
- Unassign them and confirm they flip to Deprovisioned and lose access.
- If you pushed groups, move the test user between groups and confirm the group's roles appear and disappear on their sheet under People → Members. Roles that come from a group show as From group.
Capability reference, lifecycle behavior, and troubleshooting.