SCIM 2.0 (RFC 7643, RFC 7644, RFC 9865)
The SCIM 2.0 core schema and protocol, why it is the write side of PermDock memberships, and the identifier and tenancy rules PermDock takes from it. The receiver, its protocol subset and IdP dialects are on the SCIM adapter page.
The System for Cross-domain Identity Management defines a schema (RFC 7643) and an HTTP protocol (RFC 7644) for provisioning users and groups from an identity provider into an application. Two core resources matter: User (id, externalId, userName, active, emails, name) and Group (id, externalId, displayName, members[].value). Extension schemas add attributes under their own URN; IdPs send the Enterprise User extension by default. The protocol is REST over application/scim+json with filters, PATCH operations, ListResponse paging, an error body with status, scimType and detail, and discovery endpoints. RFC 9865 adds cursor pagination.
The RFCs leave authentication out of scope. Every IdP supports a static bearer per connection, and the IPSIE AL1 SCIM profile prescribes RFC 7523 JWT bearers so the credential can be scoped and short-lived (watch list). SCIM has no tenant attribute, so tenancy is per endpoint or per credential.
Why it matters for PermDock
- It is the enterprise procurement feature. "Does it support SCIM" is on every security questionnaire.
- It is the write side of memberships. Tenancy reads memberships through a
MembershipSource.permdock/scimwrites exactly what an authenticated IdP sent into aDirectoryStorethe application owns, anddirectoryMembershipSourcereads it back. Deprovisioning (active: falseorDELETE) removes every membership on the next request without waiting for a token to expire. - It fixes the identifier rule at the source. Team ids are the SCIM group
id/value, never the display name, so the token-sidegroupsclaim (JWT authorization claims) and a synced group refer to the same team.
The implemented protocol subset, the urn:permdock:scim:schemas:extension:roles:1.0 group extension, the credential kinds, IdP dialect normalisation and the wire checklist are on the SCIM adapter page.
Related
- SCIM adapter
- JWT authorization claims: the token-side
groupsclaim with the same identifiers - Tenancy and extension interfaces:
Membership,MembershipSource,DirectoryStore - Shared Signals and CAEP: the revocation signal that makes deprovisioning reach cached snapshots
- Standards watch list: IPSIE AL1 and Common Requirements
Last updated on
JWT authorization claims (RFC 9068, SCIM)
How PermDock reads the registered roles, groups and entitlements JWT claims (RFC 9068 section 2.2.3.1, SCIM RFC 7643 encoding) into global roles, team memberships and entitlement roles, how vendor tenant claims map to the active tenant, and the AuthZEN claims draft that makes a PDP a claim source.
FAPI 2.0 Security Profile
What the FAPI 2.0 Security Profile requires of a resource server and how permdock/jwt with profile: 'fapi2' and the OpenAPI emitter enforce those requirements before a permission check runs.