SCIM 2.0 Directory Sync
Automated user provisioning for your customers
RealmSSO implements the SCIM 2.0 protocol for automated user and group provisioning. When your customers configure SCIM, users are automatically created, updated, and deactivated in Keycloak — no manual intervention required.
Why SCIM 2.0 Directory Sync?
Everything you need for enterprise-grade identity federation.
Automatic Provisioning
New users are automatically provisioned in Keycloak when created via SCIM. User lifecycle is fully automated.
Deprovisioning Support
Automatically deactivate or remove users when they are deleted from the identity provider's directory.
Group Sync
Sync groups and group memberships from your customers' identity providers for role-based access control.
Attribute Mapping
Customize how SCIM attributes map to Keycloak user attributes. Supports nested attribute paths.
Bearer Token Auth
Secure SCIM endpoints with customer-generated bearer tokens. Tokens are hashed and never stored in plaintext.
Sync Auditing
Full audit trail for all SCIM provisioning and deprovisioning events with status tracking.
Ready to get started?
Deploy RealmSSO on your infrastructure and give your customers the enterprise SSO experience they expect.