SCIM Provisioning / Full IdP Integration
We’d love to see full SCIM 2.0 support in Spacelift so that user provisioning and deprovisioning is handled automatically via our IdP (Okta, Azure AD, etc.). Right now we have to manually add/remove users in Spacelift, which slows us down and introduces risk of leaving stale accounts around. Ideally, if someone is added to an IdP group, they’d show up in Spacelift with the right role, and when they’re removed, access should be revoked automatically. This would really help us improve security, reduce admin overhead, and align with how we manage access in the rest of our SaaS tools.
Log in to comment and vote
Comments8
Aqua Toast
Feb 19
We would also like to see SCIM integration in Spacelift. Setting up SCIM with 3rd party utilities is standard practice for one of our clients. The driving requirement is so they have a single central user database to manage access to all resources across the organization, for both management and auditing purposes.
Scarlet Fuelcell
Jan 16
Very interested in this as well
any update on prioritization of this effort?
Magenta Volcano
Jan 16
We’re heavily interested in SCIM provisioning being available, as right now we are explicitly deleting users who have been offboarded and it leaves a gap where the user still shows as “Active” in Spacelift even though their corresponding IdP account no longer exists or doesn’t have access to Spacelift anymore.
Black Breeze
Aug 28, 2025
Just FYI one of our engineering teams has this on their radar but I asked them to extend full RBAC to stack roles. Once that’s handled (a few weeks tops), they’ll start diving into SCIM.
Brown Mole
Feb 24
Any updates on this?
Pink Storm
Aug 28, 2025
•Merged request
•5 votes
SCIM Support
We manage privileges via Okta (and Opal). This makes it so that we have to logout/login again to get updated permissions. Recently, during an outage, a new engineer on the team got bit by this “tribal knowledge” and it extended the outage. Having SCIM or at least faster role update times would be amazing!
Black Breeze
May 10, 2025
Thanks for surfacing this—and especially for calling out that we “extended the outage.” That stings a bit, which probably means it matters. It suggests we didn’t meet expectations when access control was most critical.
You mentioned that logging out and back in was the workaround. That’s useful context—thank you. Was the problem mainly that you had to do that? Or that it wasn’t obvious that you needed to?
We’re wondering if the issue is tied to how we evaluate login policies. If group membership is only checked at login, changes in your identity provider wouldn’t be picked up mid-session. That might be expected technically—but definitely surprising in practice.
We’d love to understand more about what “working access control” looks like for you in those moments. For example:
How urgent was the update?
What did you expect to happen?
What would have made you feel confident the system was in sync?
And for others watching: if SCIM is something you’ve looked into, is it mostly about automated provisioning? Or about revoking access quickly and reliably?
We’re open to SCIM support, but want to make sure we’re solving the right problem—not just matching a standard. Appreciate all context you can share.
Purple Mustard
Aug 22, 2025
Having a SCIM provisioning is an absolute need to have for any tool deployed to employee.
It allow us to have a proper and accurate lifecycle management. Access granted and revoke automatically without issues with potential ghost account or else.