SCIM User Provisioning
Overview of SCIM user and group provisioning in Statsig, supported identity providers, and how automated sync works for Enterprise customers.
How SCIM works
SCIM (System for Cross-domain Identity Management) is a standardized protocol that automates user provisioning and management across multiple platforms. By integrating SCIM with your preferred Identity Provider (IdP), such as Okta, you can manage user creation, updates, and de-provisioning within Statsig. Statsig currently offers an Okta SCIM integration.
How to obtain SCIM auth key
You must be a Statsig Organization Admin to enable SCIM. The SCIM key includes the scim prefix.

- Navigate to Organization Access Management: Go to Settings > Organization > Organization Info > Access Management.
- Generate a Key: If SCIM isn't yet enabled, generate a new authentication key.
- Deactivate the Key: To disable the key, select Deactivate.
- Regenerate the Key: If you suspect the key has been compromised, you can regenerate a new one to replace it.
Current SCIM Offering
Okta
- Push Users. Assigning users to the Statsig application in Okta automatically adds them as members of your organization in Statsig. Unassigning users deactivates them and wipes all roles/permissions.
- Import Users. Statsig can import users into Okta and either match them to existing Okta users, or create them as new Okta users.
- Import Groups. Import project/team roles as groups in Okta. You can't modify imported groups in Okta.
- Push Groups. Push groups to Statsig to update user project/team roles.
Was this helpful?