# SCIM 2.0 (RFC 7643, RFC 7644, RFC 9865)

Source: https://permdock.com/docs/standards/scim

The SCIM 2.0 core schema and protocol, why it is the write side of PermDock memberships, and the identifier and tenancy rules PermDock takes from it. The receiver, its protocol subset and IdP dialects are on the SCIM adapter page.

The System for Cross-domain Identity Management defines a schema ([RFC 7643](https://www.rfc-editor.org/rfc/rfc7643.html)) and an HTTP protocol ([RFC 7644](https://www.rfc-editor.org/rfc/rfc7644.html)) for provisioning users and groups from an identity provider into an application. Two core resources matter: `User` (`id`, `externalId`, `userName`, `active`, `emails`, `name`) and `Group` (`id`, `externalId`, `displayName`, `members[].value`). Extension schemas add attributes under their own URN; IdPs send the Enterprise User extension by default. The protocol is REST over `application/scim+json` with filters, `PATCH` operations, `ListResponse` paging, an error body with `status`, `scimType` and `detail`, and discovery endpoints. [RFC 9865](https://www.rfc-editor.org/rfc/rfc9865.html) adds cursor pagination.

The RFCs leave authentication out of scope. Every IdP supports a static bearer per connection, and the IPSIE AL1 SCIM profile prescribes RFC 7523 JWT bearers so the credential can be scoped and short-lived ([watch list](/docs/standards/watch-list)). SCIM has no tenant attribute, so tenancy is per endpoint or per credential.

## Why it matters for PermDock [#why-it-matters-for-permdock]

* **It is the enterprise procurement feature.** "Does it support SCIM" is on every security questionnaire.
* **It is the write side of memberships.** [Tenancy](/docs/concepts/tenancy) reads memberships through a `MembershipSource`. [`permdock/scim`](/docs/adapters/scim) writes exactly what an authenticated IdP sent into a `DirectoryStore` the application owns, and `directoryMembershipSource` reads it back. Deprovisioning (`active: false` or `DELETE`) removes every membership on the next request without waiting for a token to expire.
* **It fixes the identifier rule at the source.** Team ids are the SCIM group `id` / `value`, never the display name, so the token-side `groups` claim ([JWT authorization claims](/docs/standards/jwt-authorization-claims)) and a synced group refer to the same team.

The implemented protocol subset, the `urn:permdock:scim:schemas:extension:roles:1.0` group extension, the credential kinds, IdP dialect normalisation and the wire checklist are on the [SCIM adapter](/docs/adapters/scim) page.

## Related [#related]

* [SCIM adapter](/docs/adapters/scim)
* [JWT authorization claims](/docs/standards/jwt-authorization-claims): the token-side `groups` claim with the same identifiers
* [Tenancy](/docs/concepts/tenancy) and [extension interfaces](/docs/concepts/extension-interfaces): `Membership`, `MembershipSource`, `DirectoryStore`
* [Shared Signals and CAEP](/docs/standards/shared-signals-caep): the revocation signal that makes deprovisioning reach cached snapshots
* [Standards watch list](/docs/standards/watch-list): IPSIE AL1 and Common Requirements
