Directory Sync
Directory sync (SCIM 2.0) adds people to the workspace when you assign them in your identity provider, and removes their access when you unassign them. Roles stay managed in the Console.
https://opencode.ai/console/scim/v2
Before you start
- Set up SSO for the workspace.
- Verify every email domain your people sign in with. Directory sync only adds people on a verified domain; invite anyone else from Members.
Create a token
- Open Settings › Security and click Set up under Directory sync.
- Copy the SCIM base URL and the token. The token is shown only once, so store it in a secrets manager.
Your identity provider sends the token on every request.
Authorization: Bearer <token>
Connect your identity provider
Okta
- Add the SCIM 2.0 Test App (Header Auth) app.
- Set the base URL, and enter
Bearerfollowed by the token in API Token. - Enable Create Users, Update User Attributes, and Deactivate Users. Leave Import Groups and password sync off.
Microsoft Entra ID
- In your enterprise app, open Provisioning and set the mode to Automatic.
- Enter the base URL as Tenant URL and the token as Secret Token.
- Assign users and groups, then start provisioning.
Other providers
Use a SCIM 2.0 app with header token authentication, pointed at the base URL. Console supports the /Users and
/Groups endpoints.
Assign one test person first. Directory sync shows Connected to your identity provider after the first request.
What syncs
| In your identity provider | In the Console |
|---|---|
| Assign a person | Added as Member. Existing members keep their role. |
| Update a name | Profile updated. |
| Unassign or deactivate | Access suspended and shown as Deactivated. API keys they created are revoked. |
| Reassign | Access restored. Revoked keys stay revoked. |
| Delete | Removed from the workspace. Their account and other workspaces are unaffected. |
- Roles and email addresses are not changed by directory sync.
- The last owner cannot be deactivated or deleted.
- Workspaces with a Go subscription cannot add members through directory sync.
Groups
Push groups to tag their members, for example with Okta Push Groups or Entra group assignment. Assign the people before pushing their groups.
Platform Admins → platform-admins
Each group tags its members with a tag named after the group. Under Settings › Security › Group tags you can rename a tag, point several groups at one tag, or stop tagging a group. Leaving a group removes its tag.
Rotate the token
- Click New token and install it in your identity provider.
- Wait until the new token shows a last use.
- Revoke the old token.
Revoking a token stops future updates but does not change existing members. Deleting the SSO connection revokes all tokens.
SSO and directory sync
Once a workspace has issued a token, SSO no longer adds members automatically. The directory decides who belongs, even if the token is later revoked.