Stitchflow
Brex logo

Brex SCIM guide

Native SCIM

How to automate Brex user provisioning, and what it actually costs

Native SCIM requires Premium/Enterprise plan

Summary and recommendation

Brex, the corporate spend management platform, supports SCIM provisioning starting with the Premium plan ($12/user/month), with full integration available for Okta and Microsoft Entra ID users. However, Brex's SCIM implementation comes with several operational complexities that create headaches for IT teams. The most significant is the rigid configuration requirement—SSO and SCIM must be set up in a specific order for Okta, and you cannot configure both Enterprise IdP sign-in and SSO simultaneously. Additionally, Azure users with certain statuses get completely deleted (not just deactivated) when deprovisioned, and SSO users bypass Brex's native MFA entirely.

These limitations create real operational risks for finance teams managing corporate card access. When employees leave, immediate deactivation is critical to prevent unauthorized spending—but the complex setup requirements and deletion behaviors make reliable automated deprovisioning difficult to achieve. The setup complexity also means IT teams often struggle with initial implementation, leading to manual workarounds that defeat the purpose of automated provisioning.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation for Brex without the configuration complexity or deletion risks. Works with any Brex plan and any IdP (Okta, Entra, Google Workspace, OneLogin). Flat pricing under $5K/year with 24/7 human-in-the-loop support to ensure reliable financial controls.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolOIDC, SAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Brex accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Brex pricing problem

Brex gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
EssentialsFree
Premium$12/user/month
EnterpriseCustom pricing

Pricing structure

PlanPriceSCIM
EssentialsFree
Premium$12/user/month✓ Okta/Entra only
EnterpriseCustom pricing✓ Okta/Entra only

What this means in practice

If you're using Google Workspace or OneLogin as your primary IdP, you have no automated provisioning options. Manual user management becomes your only choice for a platform that handles sensitive financial data and corporate card access.

Even with supported IdPs, Brex's SCIM implementation creates operational friction:

SCIM credentials must be obtained through a "secure document" process rather than standard API key generation
Configuration requires specific setup sequences (SSO must be configured before SCIM for Okta)
No self-service setup
requires coordination with Brex support

Additional constraints

Limited IdP coverage
Only 2 of the 4 major enterprise IdPs supported
Manual credential process
No standard API key workflow - credentials come via secure document exchange
Configuration dependencies
SSO and SCIM setup order matters, creating deployment complexity
Deactivation quirks
Azure users with certain statuses get deleted instead of deactivated
Enterprise SSO conflicts
Cannot configure both Enterprise IDP sign-in and SSO simultaneously

For finance teams managing corporate card access, these limitations mean delayed onboarding for new hires and potential security gaps during offboarding - exactly when you need the tightest financial controls.

Summary of challenges

  • Brex supports SCIM but only at Enterprise tier (Custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Brex actually offers for identity

SCIM Provisioning (Premium+)

Brex provides SCIM 2.0 integration with select identity providers, but with significant setup complexity:

FeatureDetails
ProtocolSCIM 2.0
Supported IdPsOkta, Microsoft Entra ID
User creation✓ Yes
User updates✓ Yes
User deactivation✓ Yes
Attribute mapping✓ Yes (Department, Cost Center, Division)
CredentialsVia secure document from Brex support

Critical setup requirement: For Okta users, SSO and SCIM must be configured in a specific order or the integration will fail. This isn't clearly documented and trips up many IT teams.

Data handling quirk: Azure users with "Archived," "Invited," or "Not invited" status are automatically deleted when deactivated through SCIM, rather than simply disabled.

SSO Options (Premium+)

SettingDetails
ProtocolsOIDC, SAML 2.0
JIT provisioning✓ Yes
MFA handlingBypassed for SSO users (Brex doesn't prompt)
LimitationCannot run Enterprise IdP sign-in and SSO simultaneously

The Premium tier reality

Brex Premium costs $12/user/month and includes SCIM, but also bundles:

AI compliance features
Travel concierge services
Custom expense policies
Advanced reporting dashboards
Multi-entity support

The math problem: If you only need SCIM for corporate card provisioning, roughly 80% of Premium features are irrelevant to your use case. You're paying for travel booking tools when you just want automated user lifecycle management.

What IT admins are saying

Brex's SCIM implementation creates configuration headaches for IT teams managing corporate spend access:

  • SSO and SCIM must be configured in a specific order with Okta - get it wrong and you start over
  • Azure users with certain statuses get deleted entirely when deactivated instead of just disabled
  • Enterprise SSO and regular IdP sign-in can't be used simultaneously, forcing all-or-nothing decisions
  • SCIM credentials are only available through "secure document" delivery, adding setup friction

SSO and SCIM must be configured in specific order for Okta

Brex documentation

Azure users with Archived/Invited/Not invited status deleted when deactivated

Brex SCIM limitations

The recurring theme

Brex's SCIM works once properly configured, but the setup process is unnecessarily complex with specific ordering requirements and integration gotchas that waste IT time on what should be straightforward provisioning.

The decision

Your SituationRecommendation
Small finance team (<20 employees)Manual management acceptable with SSO
Growing company with frequent hiringUse Stitchflow: card access needs immediate automation
Enterprise with strict financial controlsUse Stitchflow: auto-deactivation critical for compliance
Multi-entity organizationUse Stitchflow: complex attribute mapping required
High employee turnover environmentUse Stitchflow: manual deprovisioning creates security risk

The bottom line

Brex offers solid SCIM capabilities, but only for Premium/Enterprise customers and with setup complexity that can trip up IT teams. For organizations where corporate card access must be tightly controlled and instantly revoked, Stitchflow eliminates the manual overhead and ensures financial security through automated provisioning.

Automate Brex without the tier upgrade

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for Brex at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • SSO and SCIM must be configured in specific order for Okta
  • Azure users with Archived/Invited/Not invited status deleted when deactivated
  • SSO users not prompted for MFA by Brex
  • Enterprise IDP sign-in and SSO cannot be configured simultaneously

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Brex → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Enterprise required for SCIM

Native SCIM is available on Enterprise. Use Stitchflow if you need provisioning without the tier upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Brex → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Enterprise required for SCIM

Native SCIM is available on Enterprise. Use Stitchflow if you need provisioning without the tier upgrade.

Unlock SCIM for
Brex

Brex gates automation behind Premium/Enterprise plan. Stitchflow delivers the same SCIM outcomes for a flat fee.

See how it works
Admin Console
Directory
Applications
Brex logo
Brex
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Airbase logo

Airbase

SCIM Tax

Spend Management / Corporate Cards

SCIM StatusIncluded
Manual Cost$11,754/yr

Airbase supports SCIM provisioning, but only on Enterprise plans starting around $8,500/year. While SCIM works with all major identity providers (Okta, Entra ID, Google Workspace), the Enterprise requirement creates a significant barrier for smaller finance teams who need automated provisioning for spend management but can't justify enterprise-level spend management software costs. This creates a particular challenge in finance applications where rapid provisioning and deprovisioning is critical for corporate card access and financial controls. Manual user management means delayed access for new employees needing corporate cards, and more critically, potential security gaps when departing employees retain access to spend management systems. For finance teams handling sensitive financial data and corporate spending, these delays and oversights create both operational friction and compliance risks.

View full guide
Airfocus logo

Airfocus

SCIM Tax

Product Management / Roadmapping

SCIM StatusIncluded
Manual Cost$11,754/yr

Airfocus supports SCIM provisioning, but only on Enterprise plans with custom pricing. While it handles basic user lifecycle management (create, update, deactivate), it lacks group provisioning entirely—meaning team assignments and workspace access must be managed manually. The Azure Entra integration also suffers from significant delays (~40 minutes for provisioning), creating gaps where users can't access product roadmaps they need immediately. For product management teams, this creates operational friction. Product managers, executives, and engineering leads need timely access to strategic roadmaps, but manual group assignments slow onboarding and complicate offboarding. Without automated group provisioning, IT teams must coordinate with product leads to ensure the right stakeholders have appropriate workspace access—exactly the kind of manual work SCIM should eliminate.

View full guide