Skip to content

Works with account required

SCIM 2.0

SCIM 2.0 inbound Users and Groups: create, update, deactivate. Tokens are hashed at rest.

Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.

No external SCIM client is configured; contract tests use the mock SCIM client.

What sslcertificates.io can do

SCIM 2.0 inbound Users and Groups: create, update, deactivate. Tokens are hashed at rest. Capabilities: create, update, deactivate, groups. Authentication uses bearer.

Required permissions

SCIM client token issued per organization. Inbound SCIM is authenticated with a stored bearer token.

Setup

Open Dashboard → Integrations → SCIM 2.0. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.

Known limitations

Deactivate does not delete audit history. Break-glass owners cannot be deactivated via SCIM.

Official sources

Fact checked 2026-09-20. https://datatracker.ietf.org/doc/html/rfc7644 SCIM 2.0 is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.

Capabilities

create update deactivate groups

Connect

Create an account to connect

SCIM 2.0 is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.