Enable SCIM on the Command Platform
Copy link

System for Cross-Domain Identity Management (SCIM) automates account creation, updates, and removal across your applications.

Use SCIM with the Command Platform to connect your identity provider (IdP), such as Okta, as the primary source for user account data. The Command Platform provisions your employees based on the roles you define.

Before you begin
Copy link

Before you enable SCIM, you’ll need:

  • A Platform Admin Service Account
  • The Platform Admin role assigned to your account
  • Your Platform Admin User API key for authentication
⚠️

Use a local user account

Use a local user account for your Platform Admin Service Account rather than an SSO-based account to prevent lockout.

Step 1: Configure your IdP
Copy link

Before you enable SCIM on the Command Platform, you must provide connection details to your IdP.

Configure your IdP with these parameters:

ParameterValue
SCIM connector base URLhttps://eu.api.insight.rapid7.com/scim/v2 
Unique identifier fieldEmail
Authentication modeHTTP header
Authentication typeBearer token (API key)
Bearer tokenYour Platform Admin user API key.

Step 2: Enable SCIM on the Command Platform
Copy link

Enabling SCIM allows your IdP to automatically manage accounts on the Command Platform.

To enable SCIM on the Command Platform:

  1. From Command Home, go to Administration > Settings > SSO Settings.
  2. Select Modify Settings.
  3. Select the SCIM provisioning is active radio button. This enables the SCIM endpoints so your IdP can communicate with the Command Platform.
  4. Select Submit and turn on SSO.

Supported SCIM endpoints
Copy link

These SCIM endpoints are supported by the Command Platform.

Supported endpoints for users:

  • GET /Users
  • POST /Users
  • GET /Users/{id}
  • PUT /Users/{id}
  • PATCH /Users/{id}

Supported endpoints for user groups:

  • GET /Groups
  • POST /Groups
  • GET /Groups/{id}
  • PUT /Groups/{id}
  • PATCH /Groups/{id}
  • DELETE /Groups/{id}
ℹ️

SCIM endpoint support varies by vendor

SCIM implementation differs across IdPs, and some vendors require additional endpoints that the Command Platform doesn’t support. Contact Rapid7 Support if this applies to your vendor.