Skip to main content

SCIM Provisioning / Full IdP Integration

We’d love to see full SCIM 2.0 support in Spacelift so that user provisioning and deprovisioning is handled automatically via our IdP (Okta, Azure AD, etc.). Right now we have to manually add/remove users in Spacelift, which slows us down and introduces risk of leaving stale accounts around. Ideally, if someone is added to an IdP group, they’d show up in Spacelift with the right role, and when they’re removed, access should be revoked automatically. This would really help us improve security, reduce admin overhead, and align with how we manage access in the rest of our SaaS tools.

Status: ✅ Completed8 comments

Log in to comment and vote

Comments8

  • Aqua Toast

    •

    Feb 19

    We would also like to see SCIM integration in Spacelift. Setting up SCIM with 3rd party utilities is standard practice for one of our clients. The driving requirement is so they have a single central user database to manage access to all resources across the organization, for both management and auditing purposes.

  • Scarlet Fuelcell

    •

    Jan 16

    Very interested in this as well
    any update on prioritization of this effort?

  • Magenta Volcano

    •

    Jan 16

    We’re heavily interested in SCIM provisioning being available, as right now we are explicitly deleting users who have been offboarded and it leaves a gap where the user still shows as “Active” in Spacelift even though their corresponding IdP account no longer exists or doesn’t have access to Spacelift anymore.

  • Black Breeze

    •

    Aug 28, 2025

    Just FYI one of our engineering teams has this on their radar but I asked them to extend full RBAC to stack roles. Once that’s handled (a few weeks tops), they’ll start diving into SCIM.

    • Brown Mole

      •

      Feb 24

      Any updates on this?

  • Pink Storm

    •

    Aug 28, 2025

    •

    Merged request

    •

    5 votes

    SCIM Support

    We manage privileges via Okta (and Opal). This makes it so that we have to logout/login again to get updated permissions. Recently, during an outage, a new engineer on the team got bit by this “tribal knowledge” and it extended the outage. Having SCIM or at least faster role update times would be amazing!

    • Black Breeze

      •

      May 10, 2025

      Thanks for surfacing this—and especially for calling out that we “extended the outage.” That stings a bit, which probably means it matters. It suggests we didn’t meet expectations when access control was most critical.

      You mentioned that logging out and back in was the workaround. That’s useful context—thank you. Was the problem mainly that you had to do that? Or that it wasn’t obvious that you needed to?

      We’re wondering if the issue is tied to how we evaluate login policies. If group membership is only checked at login, changes in your identity provider wouldn’t be picked up mid-session. That might be expected technically—but definitely surprising in practice.

      We’d love to understand more about what “working access control” looks like for you in those moments. For example:

      • How urgent was the update?

      • What did you expect to happen?

      • What would have made you feel confident the system was in sync?

      And for others watching: if SCIM is something you’ve looked into, is it mostly about automated provisioning? Or about revoking access quickly and reliably?

      We’re open to SCIM support, but want to make sure we’re solving the right problem—not just matching a standard. Appreciate all context you can share.

    • Purple Mustard

      •

      Aug 22, 2025

      Having a SCIM provisioning is an absolute need to have for any tool deployed to employee.
      It allow us to have a proper and accurate lifecycle management. Access granted and revoke automatically without issues with potential ghost account or else.