Enable SCIM on the Command Platform
System for Cross-Domain Identity Management (SCIM) automates account creation, updates, and removal across your applications.
Use SCIM with the Command Platform to connect your identity provider (IdP), such as Okta, as the primary source for user account data. The Command Platform provisions your employees based on the roles you define.
Before you begin
Before you enable SCIM, you’ll need:
- A Platform Admin Service Account
- The Platform Admin role assigned to your account
- Your Platform Admin User API key for authentication
Use a local user account
Use a local user account for your Platform Admin Service Account rather than an SSO-based account to prevent lockout.
Step 1: Configure your IdP
Before you enable SCIM on the Command Platform, you must provide connection details to your IdP.
Configure your IdP with these parameters:
| Parameter | Value |
|---|---|
| SCIM connector base URL | https://eu.api.insight.rapid7.com/scim/v2 |
| Unique identifier field | |
| Authentication mode | HTTP header |
| Authentication type | Bearer token (API key) |
| Bearer token | Your Platform Admin user API key. |
Step 2: Enable SCIM on the Command Platform
Enabling SCIM allows your IdP to automatically manage accounts on the Command Platform.
To enable SCIM on the Command Platform:
- From Command Home, go to Administration > Settings > SSO Settings.
- Select Modify Settings.
- Select the SCIM provisioning is active radio button. This enables the SCIM endpoints so your IdP can communicate with the Command Platform.
- Select Submit and turn on SSO.
Supported SCIM endpoints
These SCIM endpoints are supported by the Command Platform.
Supported endpoints for users:
GET /UsersPOST /UsersGET /Users/{id}PUT /Users/{id}PATCH /Users/{id}
Supported endpoints for user groups:
GET /GroupsPOST /GroupsGET /Groups/{id}PUT /Groups/{id}PATCH /Groups/{id}DELETE /Groups/{id}
SCIM endpoint support varies by vendor
SCIM implementation differs across IdPs, and some vendors require additional endpoints that the Command Platform doesn’t support. Contact Rapid7 Support if this applies to your vendor.