> For the complete documentation index, see [llms.txt](https://docs.codeocean.com/admin-guide/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.codeocean.com/admin-guide/v2.1/the-admin-dashboard/set-up-an-integration/idp-integration/scim-provisioning-using-okta.md).

# SCIM Provisioning using Okta

The System for Cross-domain Identity Management (SCIM) user management API enables automatic provisioning of users between the Code Ocean platform and Okta.&#x20;

### Requirements

* Administrator or higher for Okta
* Administrator in Code Ocean

> **Note**: There are three Enterprise providers that Code Ocean supports, Okta, [Azure Active Directory](/admin-guide/v2.1/the-admin-dashboard/set-up-an-integration/idp-integration/scim-provisioning-using-azure-active-directory.md) and One Login.

### Creating a Custom Application

1. Navigate to Okta using the the URL provided to you in your activation email for example <https://dev-12345678-admin.okta.com>

2. Sign in with your username/email address and Password

3. Click **Applications** from the main and sub menu

   <img src="/files/jRjp7OFLLfi7loo01NFH" alt="" data-size="original">

4. Code Ocean is not included in the App Catalog, an App Integration must be created

### **Configuring Provisioning**

1. Click **Create App Integration**

![](/files/VdDEpc3sUeSVKrK9KdPo)

2\.  Select the Sign in method

![](/files/f1mwvMTOf7jRSA003nd5)

3\.  Enter the General App Setting information and click **Finish**.

<div align="center"><img src="/files/CKZEvwEllLP0SSO4YiH9" alt=""></div>

4\.  Select and click on the SCIM protocol, to synch the application to the Code Ocean platform

5\.  Click **Provisioning**

6\.  Click **Integration**

![](/files/kwvJUUipepBLe5Va0QQQ)

7\.  To integrate the API click **Edit**

![](/files/fujAubqh3F81ZosaAZuU)

8\.  To enable the API Integration you need to obtain the credentials from Code Ocean

### **Code Ocean Credentials**

1. Sign into your Code Ocean platform
2. Click **Admin**

   ![](/files/LRYvE6al17afd2FCzjW6)
3. Click **Integrations**

   ![](/files/Ti4sRlwBMzWJkQc8FdxB)
4. Scroll down to SCIM
5. Click **Copy to clipboard** to copy the URL and paste it in **Base URL** in Okta
6. Click **Generate new token** to obtain the provisioning token

<div align="left"><img src="/files/ycA8pxmP3TYnrWaURUlm" alt=""></div>

7\.  Copy the Provisioning Token and paste it in **API Token** in Okta

8\.  Click **Test API Credentials**

![](/files/0t3VC4oDjqZAzFefgLbs)

9\.  A confirmation message appears when the SCIM is successfully verified

![](/files/E0JLWLJi15fBmVDybZlC)

10\.  Click **Save**

## Assigning Users and Groups

### Set Up User Provisioning

To assign groups, synch individuals into a group and synch the group's name to the system:

1. Click the **Assignments** tab

   To assign individuals to a group
2. Click **Assign**
3. Click **Assign to Groups**

![](/files/BmW68ObojEZLvIwNsymp)

4\.  To assign users to a group click the name of the group

5\.  Click **Assign People**

6\. Add or Remove members to or from the group by selecting the member,  then click + or -

7\.  Click **Save**

![](/files/ni2XQf2ht1kZiuXj4owW)

8\. To assign the group to the server select the **Push Groups** tab

9\.  Click **Push Groups** will synch the Group in Code Ocean

1&#x30;**.**  Click **Find groups by name**

![](/files/QmSwwVBbL95K59Djcn2A)

11\. Enter the name of the group

12\.  Click **Close**

To view the group in Code ocean navigate to the capsule, click **Share,** in  Set Permissions for capsule click the dropdown, the group will show in the list. Any changes made to the group will synch back to Okta when saved.
