PermDock
Standards

SCIM 2.0 (RFC 7643, RFC 7644, RFC 9865)

The SCIM 2.0 core schema and protocol, why it is the write side of PermDock memberships, and the identifier and tenancy rules PermDock takes from it. The receiver, its protocol subset and IdP dialects are on the SCIM adapter page.

The System for Cross-domain Identity Management defines a schema (RFC 7643) and an HTTP protocol (RFC 7644) for provisioning users and groups from an identity provider into an application. Two core resources matter: User (id, externalId, userName, active, emails, name) and Group (id, externalId, displayName, members[].value). Extension schemas add attributes under their own URN; IdPs send the Enterprise User extension by default. The protocol is REST over application/scim+json with filters, PATCH operations, ListResponse paging, an error body with status, scimType and detail, and discovery endpoints. RFC 9865 adds cursor pagination.

The RFCs leave authentication out of scope. Every IdP supports a static bearer per connection, and the IPSIE AL1 SCIM profile prescribes RFC 7523 JWT bearers so the credential can be scoped and short-lived (watch list). SCIM has no tenant attribute, so tenancy is per endpoint or per credential.

Why it matters for PermDock

  • It is the enterprise procurement feature. "Does it support SCIM" is on every security questionnaire.
  • It is the write side of memberships. Tenancy reads memberships through a MembershipSource. permdock/scim writes exactly what an authenticated IdP sent into a DirectoryStore the application owns, and directoryMembershipSource reads it back. Deprovisioning (active: false or DELETE) removes every membership on the next request without waiting for a token to expire.
  • It fixes the identifier rule at the source. Team ids are the SCIM group id / value, never the display name, so the token-side groups claim (JWT authorization claims) and a synced group refer to the same team.

The implemented protocol subset, the urn:permdock:scim:schemas:extension:roles:1.0 group extension, the credential kinds, IdP dialect normalisation and the wire checklist are on the SCIM adapter page.

Last updated on

On this page