> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create SCIM Configuration

> Creates a new SCIM configuration for automated user provisioning.

`Unary` · [`Organizations`](/docs/api-reference/generated/organization/overview)

Creates a new SCIM configuration for automated user provisioning.

Use this method to:

* Set up SCIM 2.0 provisioning from an identity provider
* Generate a bearer token for SCIM API authentication
* Link SCIM provisioning to an existing SSO configuration

### Examples

* Create basic SCIM configuration:

  Creates a SCIM configuration linked to an SSO provider with default 1 year token expiration.

  ```yaml theme={null}
  organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047"
  ssoConfigurationId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
  ```

* Create SCIM configuration with custom token expiration:

  Creates a SCIM configuration with a 90-day token expiration.

  ```yaml theme={null}
  organizationId: "b0e12f6c-4c67-429d-a4a6-d9838b5da047"
  ssoConfigurationId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
  tokenExpiresIn: "7776000s"
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.OrganizationService/CreateSCIMConfiguration
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.OrganizationService/CreateSCIMConfiguration" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "organizationId": "<organization-id>",
    "ssoConfigurationId": "<sso-configuration-id>"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.organization_pb2 as organization_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = organization_pb2.CreateSCIMConfigurationRequest(
      organization_id="<organization-id>",
      sso_configuration_id="<sso-configuration-id>",
  )
  response = ona.services.organization.create_scim_configuration(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { CreateSCIMConfigurationRequestSchema } from "@gitpod/sdk/gitpod/v1/organization_pb";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(CreateSCIMConfigurationRequestSchema, {
      organizationId: "<organization-id>",
      ssoConfigurationId: "<sso-configuration-id>",
    });
    const response = await ona.services.organization.createSCIMConfiguration(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.CreateSCIMConfigurationRequest{
  		OrganizationId: "<organization-id>",
  		SsoConfigurationId: "<sso-configuration-id>",
  	})
  	response, err := ona.Services.Organization.CreateSCIMConfiguration(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "organizationId": "<organization-id>",
    "ssoConfigurationId": "<sso-configuration-id>"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.CreateSCIMConfigurationRequest`

| Field                                | Type            | Required | Description                                                                                                                                                                               |
| ------------------------------------ | --------------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `organizationId`                     | string          | Yes      | organization\_id is the ID of the organization to create the SCIM configuration for Constraints: `required=true, string.uuid=true`.                                                       |
| `name`                               | string          | No       | name is a human-readable name for the SCIM configuration Constraints: `string.max_len=128`.                                                                                               |
| `ssoConfigurationId`                 | string          | Yes      | sso\_configuration\_id is the SSO configuration to link (required for user provisioning) Constraints: `required=true, string.uuid=true`.                                                  |
| `tokenExpiresIn`                     | duration string | No       | token\_expires\_in is the duration until the token expires. Defaults to 1 year. Minimum 1 day, maximum 2 years. Constraints: `duration.gte.seconds=86400, duration.lte.seconds=63072000`. |
| `allowUnverifiedEmailAccountLinking` | boolean         | No       | allow\_unverified\_email\_account\_linking allows SCIM to link provisioned users to existing accounts when the identity provider does not mark the email address as verified              |

## Response

`gitpod.v1.CreateSCIMConfigurationResponse`

| Field               | Type                                                    | Required | Description                                                                                                                                          |
| ------------------- | ------------------------------------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| `scimConfiguration` | [SCIMConfiguration](#type-gitpod-v1-scim-configuration) | Yes      | scim\_configuration is the created SCIM configuration Constraints: `required=true`.                                                                  |
| `token`             | string                                                  | Yes      | token is the bearer token for SCIM API authentication. This is only returned once during creation - store it securely. Constraints: `required=true`. |
| `tokenExpiresAt`    | RFC 3339 timestamp                                      | Yes      | token\_expires\_at is when the token will expire Constraints: `required=true`.                                                                       |

## Related types

<a id="type-gitpod-v1-scim-configuration" />

<Accordion title="SCIMConfiguration">
  SCIMConfiguration represents a SCIM 2.0 provisioning configuration

  `gitpod.v1.SCIMConfiguration`

  | Field                                | Type               | Required | Description                                                                                                                                                                  |
  | ------------------------------------ | ------------------ | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | `id`                                 | string             | Yes      | id is the unique identifier of the SCIM configuration Constraints: `required=true, string.uuid=true`.                                                                        |
  | `organizationId`                     | string             | Yes      | organization\_id is the ID of the organization this SCIM configuration belongs to Constraints: `required=true, string.uuid=true`.                                            |
  | `name`                               | string             | No       | name is a human-readable name for the SCIM configuration Constraints: `string.max_len=128`.                                                                                  |
  | `enabled`                            | boolean            | No       | enabled indicates if SCIM provisioning is active                                                                                                                             |
  | `ssoConfigurationId`                 | string             | No       | sso\_configuration\_id is the linked SSO configuration (optional) Constraints: `string.uuid=true`.                                                                           |
  | `createdAt`                          | RFC 3339 timestamp | Yes      | created\_at is when the SCIM configuration was created Constraints: `required=true`.                                                                                         |
  | `updatedAt`                          | RFC 3339 timestamp | Yes      | updated\_at is when the SCIM configuration was last updated Constraints: `required=true`.                                                                                    |
  | `tokenExpiresAt`                     | RFC 3339 timestamp | Yes      | token\_expires\_at is when the current SCIM token expires Constraints: `required=true`.                                                                                      |
  | `allowUnverifiedEmailAccountLinking` | boolean            | No       | allow\_unverified\_email\_account\_linking allows SCIM to link provisioned users to existing accounts when the identity provider does not mark the email address as verified |
</Accordion>
