SCIM (System for Cross-domain Identity Management) keeps wxrks user accounts in sync with Okta. Once it's configured, your IT team creates and updates wxrks users from Okta instead of a wxrks admin managing every account by hand.
Who is this for? Account Admins, working with the Okta administrator who manages your company's applications.
How SCIM provisioning works
SCIM provisioning is separate from wxrks Single Sign-On (SSO): SSO controls how a user logs in, while SCIM controls whether their wxrks account exists, and which role and Organizational Unit it starts in. You can use one Okta application for both (see Use one Okta application for both SSO and SCIM).
With SCIM provisioning on, Okta can:
create a wxrks account when a user is assigned to the application;
update the user's name, email and phone numbers when they change in Okta;
add a wxrks role from the role value Okta sends;
deactivate the wxrks account when the user is unassigned from the application or deactivated in Okta.
⚠️ Warning — Okta adds roles but never removes them. When Okta sends a role value that has a Role Mapping row, wxrks adds the mapped role and keeps the roles the user already had. A value with no Role Mapping row, or a value cleared in Okta, leaves the user's roles unchanged. To take a role away from a provisioned user, remove it in People > Users.
ℹ️ Note: Use a custom SAML or OIDC app integration, as described below. Okta's app-catalog SCIM apps send deactivation in a form wxrks doesn't support, so users unassigned in Okta would stay active in wxrks.
For every attribute and operation wxrks accepts, see the SCIM user provisioning reference.
Prerequisites
Account Admin access in wxrks.
An Okta administrator account that can create app integrations and enable provisioning.
Usernames in Okta that are the users' email addresses. wxrks looks users up by email.
Find your SCIM credentials in wxrks
Go to Settings > Account Settings > Identity & Security, open the User Provisioning tab, and expand SCIM Provisioning.
SCIM Base URL — copy it with the copy button.
Secret Token — click Generate, then copy the token immediately. It's shown only once, and generating a new one invalidates the old one.
Role Mapping — add one row per role value Okta will send (see Map Okta roles to wxrks roles).
Default Organizational Unit — every user Okta creates is placed here.
Click Save SCIM Settings.
Configure SCIM in Okta
Okta renames screens from time to time. The steps below were checked in the Okta Admin Console in October 2026.
Create the app integration
In the Okta Admin Console, go to Applications and Resources > Applications.
If you already have a wxrks SAML or OIDC app for SSO, open it and skip to step 4.
Otherwise, click Create App Integration, open the Classic experience tab, select SAML 2.0, and click Next. Name the app (for example "wxrks"), enter the SAML settings from Set up SAML 2.0 single sign-on, and click Finish.
On the app's General tab, click Edit under App Settings, set Provisioning to SCIM, and click Save. A Provisioning tab appears.
Configure the Provisioning tab
Open Provisioning > Integration and click Edit next to SCIM Connection.
SCIM connector base URL: paste the SCIM Base URL from wxrks.
Unique identifier field for users:
email.Supported provisioning actions: select Push New Users and Push Profile Updates. Leave Push Groups and Import New Users and Profile Updates off — wxrks doesn't support groups or bulk import.
Authentication Mode: HTTP Header. In the Authorization field, paste only the Secret Token from wxrks. Okta shows a fixed
Bearerprefix before the field and adds it to the header for you: don't typeBeareryourself, or the header carries it twice and the connection fails.Click Test Connector Configuration. Okta should show Connector configured successfully. Then click Save.
Open Provisioning > To App, click Edit, and enable Create Users, Update User Attributes and Deactivate Users. Leave Sync Password off: users sign in to wxrks with SSO or their wxrks password.
Click Save.
Check the attribute mapping
Under Provisioning > To App > Attribute Mappings, confirm that:
Username maps to the user's email, so wxrks can find the user.
Primary email is mapped. wxrks reads only the email flagged as primary.
Given name and Family name are both mapped. wxrks sets the user's name only when it receives both.
Other attributes (title, locale, time zone, and so on) are ignored by wxrks. You can leave them mapped.
Assign users in Okta
Open the app's Assignments tab.
Click Assign > Assign to People or Assign to Groups. Assigning a group assigns its members to the app; wxrks receives users, not the group.
Click Assign next to a person or group, enter the role value in the role attribute (see Map Okta roles to wxrks roles), and click Save and Go Back. A value entered on a group assignment applies to every member of the group. Repeat for each person or group.
Click Done.
Okta creates each assigned user in wxrks right away.
Map Okta roles to wxrks roles
wxrks assigns roles from the roles value the IdP sends, matched against Role Mapping in wxrks.
In Okta, go to Directory > Profile Editor, open the wxrks app's user profile (for example wxrks User), and click Add Attribute. Enter a Display name and a Variable name (for example
wxrksRole), set External name toroles.^[primary==true].valueand External namespace tourn:ietf:params:scim:schemas:core:2.0:User. Under Attribute type, choose Group to set the role on group assignments, or Personal to set it per person. Okta doesn't let you change the type later. Click Save.Set the role value on each assignment on the Assignments tab (for example
pmorvendor): per person with a Personal attribute, or per group with a Group attribute.In wxrks, add a Role Mapping row for each value:
pm→ Project Manager,vendor→ Vendor, and so on. Then click Save SCIM Settings.
ℹ️ Note: A user created without a role value gets no role in wxrks. Assign one in People > Users until the mapping is in place.
Turn on provisioning and check it
Provisioning starts as soon as users are assigned and Create Users is enabled. Assign one test user, then return to the SCIM Provisioning card in wxrks. Last user created at should show the current time, and the user should appear in People > Users in the Default Organizational Unit, with the mapped role.
Use one Okta application for both SSO and SCIM
You can, and it's recommended: use the same Okta app for login and for provisioning, so access and accounts stay in sync. This guide covers provisioning only. For the SSO setup itself, see Set up SAML 2.0 single sign-on.
Troubleshooting
"Test Connector Configuration" fails. Check that the Base URL was pasted in full, that the Authorization field holds only the token, without the word Bearer, and that the token is the latest one generated. A token is invalid as soon as a newer one is generated.
The user wasn't created: "Email already exists". The email already belongs to a wxrks user, possibly in another account. Update that user in wxrks instead.
A user unassigned in Okta can still sign in to wxrks. Check that Deactivate Users is enabled under Provisioning > To App, and that the app is a custom SAML or OIDC integration, not an app-catalog SCIM app.
Related articles
SCIM user provisioning reference — every supported attribute, operation and limit.





![Okta Directory > Profile Editor, Add Attribute dialog for the wxrks app user profile; red box around External name set to roles.^[primary==true].value and External namespace set to urn:ietf:params:scim:schemas:core:2.0:User.](https://wxrks.intercom-attachments-1.com/i/o/ugt38spf/2714063139/64cb5eacf5eeee04efa6184d340a/04-okta-profile-editor-add-attribute-v2.png?expires=1791253800&signature=a6798efde08cdda006dec5f3ef123cd444c3609a44b2b5209b7166fbe0c48c41&req=dicmEsl4noBcUPMW1HO4zWuLwNOKBJQvKExzOHVoO196qJ4XfbeLkwuc63F%2F%0ASDUgomciBl1w6SocxEo%3D%0A)