Works with
account required
SCIM 2.0
SCIM 2.0 inbound Users and Groups: create, update, deactivate. Tokens are hashed at rest.
Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.
No external SCIM client is configured; contract tests use the mock SCIM client.
What sslcertificates.io can do
SCIM 2.0 inbound Users and Groups: create, update, deactivate. Tokens are hashed at rest. Capabilities: create, update, deactivate, groups. Authentication uses bearer.
Required permissions
SCIM client token issued per organization. Inbound SCIM is authenticated with a stored bearer token.
Setup
Open Dashboard → Integrations → SCIM 2.0. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.
Known limitations
Deactivate does not delete audit history. Break-glass owners cannot be deactivated via SCIM.
Official sources
Fact checked 2026-09-20. https://datatracker.ietf.org/doc/html/rfc7644 SCIM 2.0 is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.
Capabilities
Connect
SCIM 2.0 is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.