Automate User Provisioning with SCIM Directory Sync
For the complete documentation index, see llms.txt. For a full content snapshot, see llms-full.txt. Append.mdto anykestra.io/docs/*URL for plain Markdown.
Available on:Enterprise EditionCloud
Sync users and groups from your Identity Provider (IdP) to Kestra using SCIM.
SCIM (System for Cross-domain Identity Management) is an open-standard protocol that automates user provisioning, de-provisioning, and group synchronization between identity providers (IdPs) such as Microsoft Entra ID or Okta and service providers such as Kestra. Kestra uses the SCIM 2.0 protocol.

How SCIM provisioning works
- Automated provisioning and de-provisioning: Users and groups are created, updated, and removed in Kestra automatically when they change in the IdP, keeping the IdP as the single source of truth for identity data.
- Consistency and compliance: Identity information stays consistent across systems, supporting security and regulatory requirements without manual reconciliation.
- Group synchronization: IdP group memberships map to Kestra groups, so role assignments follow the IdP structure without per-user configuration in Kestra.
Supported identity providers
For setup guides by provider, see the pages below.
authentik SCIM Provisioning in Kestra
Configure SCIM provisioning with authentik. Learn how to automatically sync users and groups from authentik to your Kestra Enterprise instance.
Keycloak SCIM Provisioning in Kestra
Configure SCIM provisioning with Keycloak. Synchronize users and groups from Keycloak to Kestra Enterprise for centralized identity management.
Microsoft Entra ID SCIM Provisioning in Kestra
Set up SCIM provisioning with Microsoft Entra ID. Automatically sync users and groups from Entra ID to Kestra for streamlined user management.
Okta SCIM Provisioning in Kestra Enterprise
Enable SCIM provisioning with Okta. Learn how to automatically synchronize Okta users and groups with your Kestra Enterprise instance.
Was this page helpful?