SCIM lets Microsoft Entra create, update, and deactivate Stackyapper workspace
users. It is available on Business and is configured by a workspace owner.
Configure Entra
In Stackyapper, open Settings → Identity & access.
Under SCIM provisioning, select Generate token.
Copy the Tenant URL and bearer token immediately.
In the Entra enterprise application, set provisioning mode to
Automatic.
Enter the Stackyapper Tenant URL and use the generated value as the Secret
Token.
Test the connection in Entra before enabling provisioning.
Start with a small assigned group and confirm the resulting users in
Users & Groups.
The bearer token is displayed when generated. Store it in Entra and an approved
secret manager; do not put it in tickets, chat, or documentation.
Rotate the token
Select Rotate token in Stackyapper.
Replace the Secret Token in Entra immediately.
Test the Entra connection.
Confirm a provisioning cycle completes.
Rotation invalidates the previous credential. Coordinate both sides to avoid a
provisioning interruption.
Deactivation and access
SCIM controls workspace identity lifecycle. It does not grant app or tool
access. Use groups and policy for authorization.
Review deactivated users, AI clients, and personal app authorizations as part
of offboarding. To remove organization SCIM rather than rotate its token,
contact support after confirming how users will be
maintained afterward.