Okta SCIM Configuration Guide
This article explains admin steps to configure Okta SCIM integration with Staircase AI to enable automated user provisioning—covering the steps for setting up push actions for new users, profile updates, deactivation, and reactivation—while noting that the integration does not support email address updates and deactivates (but does not delete) users when unassigned in Okta.
This guide provides step-by-step instructions for configuring a System for Cross-domain Identity Management (SCIM) integration between Okta and Staircase AI. This integration enables seamless user provisioning and attribute synchronization between the two platforms, streamlining user management and access control.
This guide is intended for Okta and Staircase AI administrators who are familiar with SCIM concepts and user management within their respective platforms.
Supported Features
The following provisioning features are supported:
- Push New Users
- Push Profile Updates
- Push User Deactivation
- Reactivate Users
Requirements
- Log into Staircase and click the cog symbol in the left-hand bar to open up your
- Click on the "Okta" card within the "Integrations" panel.
- Locate the SCIM token field and copy the current value.
Configuration Steps
As an Okta admin
- Navigate to the "Applications" page. Click the "Browse App Catalog" button and find the "Staircase AI" application. Install the application.
- On the Sign On application tab in Okta select Email for the Application username format.
- Go to the "Provisioning" tab on the application page and click the "Configure API Integration" button. Base URL must be set to the "https://app.staircase.ai/api/scim" value. Paste your SCIM token from Staircase AI into the "API Token" input field and click "Save".
- Go to the "To App" tab and click the "Edit" button to be able to enable provisioning features. Configure it as shown below and click "Save".
- In the features section, you can configure user attributes as shown in the image below. Additionally, you can also optionally map the user's title
Limitations
- The integration doesn't support updating a user's email address