SCIM 2.0 Directory Sync

Automated user provisioning for your customers

RealmSSO implements the SCIM 2.0 protocol for automated user and group provisioning. When your customers configure SCIM, users are automatically created, updated, and deactivated in Keycloak — no manual intervention required.

Why SCIM 2.0 Directory Sync?

Everything you need for enterprise-grade identity federation.

Automatic Provisioning

New users are automatically provisioned in Keycloak when created via SCIM. User lifecycle is fully automated.

Deprovisioning Support

Automatically deactivate or remove users when they are deleted from the identity provider's directory.

Group Sync

Sync groups and group memberships from your customers' identity providers for role-based access control.

Attribute Mapping

Customize how SCIM attributes map to Keycloak user attributes. Supports nested attribute paths.

Bearer Token Auth

Secure SCIM endpoints with customer-generated bearer tokens. Tokens are hashed and never stored in plaintext.

Sync Auditing

Full audit trail for all SCIM provisioning and deprovisioning events with status tracking.

Ready to get started?

Deploy RealmSSO on your infrastructure and give your customers the enterprise SSO experience they expect.