Custom SCIM: Flexible integration of user management with Flexopus
Flexopus supports the open SCIM v2 standard – regardless of the identity provider used. This allows you to automate user management, even if no pre-built connector is available for your system.
What is Custom SCIM synchronization?
SCIM stands for "System for Cross-domain Identity Management" – an open, widely used standard for the automated management of user accounts in cloud applications. Flexopus' SCIM v2 interface allows user profiles, attributes, and groups to be synchronized directly from your Identity Provider (IdP).
Unlike the pre-configured integrations for Microsoft Entra ID or Okta, Custom SCIM is aimed at companies that use a different or self-hosted identity provider. As long as it supports the SCIM v2 standard, a connection to Flexopus is possible. Typically, user data such as name, email address, department, and group memberships are synchronized.
What is the purpose of integration?
Custom SCIM eliminates the need for manual maintenance of user accounts in Flexopus. As soon as an employee is created, modified, or deactivated in the Identity Provider, these changes are automatically reflected in Flexopus.
Typical use cases include:
- Automatic creation of new user accounts during onboarding
- Profile data is updated when changes are made to the IdP (e.g. (Department change)
- Automatic account deactivation upon offboarding
- Synchronization of groups for targeted access management in Flexopus
How easy is the integration?
Setting up the custom SCIM integration does not require in-depth technical knowledge. In Flexopus, a SCIM token is generated, which is then stored in the Identity Provider. After that, the synchronization runs fully automatically in the background.
The only requirement is that your Identity Provider supports the SCIM v2 standard. The exact configuration steps depend on the specific system.
What are the advantages of integration?
- System-independent: Works with any SCIM v2-compatible identity provider
- Less manual effort: User accounts are automatically created, updated, and deactivated.
- Consistent data: User information in Flexopus is always up-to-date and matches the IdP.
- Increased security: Deactivated employees automatically lose their access to Flexopus.
- Data protection compliant: Only the data necessary for synchronization is transferred.
- Included in the Flexopus subscription: No additional costs for SCIM integration.
Categories
Developed By
Flexopus GmbHFurther integrations
questions and answers
Which identity providers are supported?
Custom SCIM works with any Identity Provider that supports the SCIM v2 standard. This includes, for example, self-hosted solutions or less common systems for which no pre-built Flexopus integration exists. Dedicated, pre-configured integrations are available for Microsoft Entra ID and Okta.
What happens when a user is deleted from the Identity Provider?
If a user account is deleted or deactivated in the Identity Provider, it is also automatically deactivated in Flexopus via SCIM. The user thereby loses access to the platform. Existing bookings are generally retained and can be managed by administrators.
What data is synchronized via SCIM?
User data such as name, email address, department and group memberships are synchronized via the SCIM interface. Only the data necessary for the use of Flexopus will be transmitted.
Is SCIM integration compliant with data protection regulations?
Yes. Flexopus only transmits the data actually needed for user management via SCIM. Communication is encrypted and token-based. Flexopus is GDPR-compliant and is operated on servers in Germany.
Can I use SCIM together with Single Sign-On (SSO)?
Yes, SCIM and SSO complement each other perfectly. While SCIM handles the automatic provisioning and management of user accounts, SSO enables convenient and secure login without separate access data for Flexopus. Both functions can be used in parallel.

