Set up user provisioning with SCIM

Last updated: October 11, 2026

Connect your identity provider to Layer with SCIM, so people you assign to Layer in Okta or Microsoft Entra ID get a Layer account automatically and lose access as soon as you remove them there.

Before you start

  • Your workspace is on the Enterprise plan. On other plans the User provisioning (SCIM) section is locked behind Upgrade to Enterprise; select Contact Sales to enable it.
  • You have a Layer role that can open Workspace Settings and manage members, such as Admin.
  • In Okta you are a super admin or app admin. In Microsoft Entra ID you are at least an Application Administrator.
  • Single sign-on is usually set up first, so provisioned people can sign in. See Set up single sign-on.

In Layer

  1. Click your workspace name at the bottom left of the sidebar, choose Workspace Settings, then select Security. Scroll to User provisioning (SCIM). The SCIM endpoint URL shown there is the address your identity provider sends changes to.

  2. Under SCIM tokens, select Generate token and give it a Name that says where it is used, for example Okta provisioning. Leave Expires at Never unless your security policy requires rotation: identity providers do not warn you when a token expires, so provisioning stops without notice.

  3. Select Generate token. Layer shows the SCIM endpoint URL and the SCIM token together. Copy both now: the token is shown only once. Keep this dialog open while you work through your identity provider's steps below.

  4. Select Done. The token is listed under SCIM tokens with who created it and when it was Last used. The token belongs to the workspace, not to you, so provisioning keeps working if you change roles or leave.

Now finish the setup in Okta or in Microsoft Entra ID, then come back for the last step under Check that it works.

In Okta

Written against the Okta Admin Console, October 2026.

  1. In the Okta Admin Console, go to Applications > Applications and open the SAML app you use for Layer. If you do not have one, select Create App Integration, choose SAML 2.0, and create it.

  2. On the General tab, under App Settings, select Edit, set Provisioning to SCIM, and select Save.

  3. On the Provisioning tab, open Integration and select Edit. Fill in:

    • SCIM connector base URL: the SCIM endpoint URL from Layer.
    • Unique identifier field for users: userName.
    • Supported provisioning actions: Push New Users, Push Profile Updates and Push Groups.
    • Authentication Mode: HTTP Header, with the SCIM token from Layer pasted as the bearer token.

    Select Test Connector Configuration, then Save.

  4. Still on the Provisioning tab, open To App, select Edit, and turn on Create Users, Update User Attributes and Deactivate Users. Select Save.

  5. On the Assignments tab, assign the people or groups who should have Layer. Okta creates their Layer accounts within a few minutes.

  6. Optionally, on the Push Groups tab, push the Okta groups you want to mirror in Layer. Each pushed group appears in Layer under Groups & Roles, where you set the role its members get.

In Microsoft Entra ID

Written against the Microsoft Entra admin center, October 2026.

  1. Sign in to the Microsoft Entra admin center and go to Entra ID > Enterprise apps. Open the app you use for Layer, or select New application > Create your own application, name it, choose Integrate any other application you don't find in the gallery, and select Create.

  2. In the app, select Provisioning and then New configuration. Set Authentication Method to Bearer Authentication, paste the SCIM endpoint URL from Layer into Tenant URL and the SCIM token into Secret Token.

  3. Select Test Connection. When it succeeds, select Create.

  4. Under Attribute mapping, open the user mapping and check that userName maps to your people's email address. By default it maps to userPrincipalName; if your sign-in names differ from email addresses, map userName to mail instead. Select Save.

  5. Select Users and groups and assign the people or groups who should have Layer. With the default scope, Entra ID provisions only assigned users and groups.

  6. Use Provision on demand to provision one test user straight away. When that works, go to Overview and select Start provisioning. The first cycle can take a while; after that Entra ID syncs about every 40 minutes.

Check that it works

  1. In Layer, open Members and confirm the people you assigned are listed. Back on Security, the token's Last used time shows your identity provider is calling Layer.

  2. Unassign a test user in your identity provider. On the next sync they are suspended in Layer and can no longer sign in. Assign them again and they come back with the role they had.

  3. When provisioning works, let your identity provider be the only way people join or leave. Under User provisioning (SCIM), turn on Only allow provisioning via SCIM and Only allow deprovisioning via SCIM. Admins then cannot invite, suspend or remove members from Layer; Members shows that members are managed by your identity provider. Roles are still set in Layer.

Production tips

  • Assign groups, not individuals. Assign a directory group such as Layer users to the app, and add or remove people from that group. Joiners and leavers then need no change in the Layer app itself.
  • Set roles with pushed groups. Push one group per role (for example Layer artists and Layer leads) and give each its role under Groups & Roles. A group can also be assigned to a child workspace, so one push manages access across your studio's workspaces.
  • Use one token per identity provider connection. Name it after where it is used. To rotate, generate a new token, replace it in your identity provider, check Last used moves on the new one, then revoke the old one with the bin icon on its row.
  • Replace personal tokens. If Layer shows a warning that your identity provider is using a personal token, generate a SCIM token and swap it in. A personal token stops working when its owner leaves or loses access.
  • Turn on the SCIM-only switches last. Turn on the Only allow switches after a full cycle has added and removed a test user correctly.

If something goes wrong

  • The connection test fails with 401 or "Unauthorized". The token was mistyped, revoked or has expired. Generate a new token in Layer and paste it again. In Okta, check Authentication Mode is HTTP Header; in Entra ID, check Authentication Method is Bearer Authentication.
  • The connection test fails with 403. The workspace is not on the Enterprise plan, or the URL names a different workspace from the one the token was generated in. Copy the SCIM endpoint URL again from the same workspace's Security page.
  • A person was provisioned but cannot sign in. Provisioning creates the account; signing in still goes through your login methods. Check single sign-on is Active and that their email is on a verified domain. See Set up single sign-on.
  • "Invites are turned off for this workspace." Only allow provisioning via SCIM is on. Assign the person in your identity provider instead, or turn the switch off.

Related