Stitchflow
Epic logo

Epic SCIM guide

Connector Only

How to automate Epic user provisioning, and what it actually costs

Summary and recommendation

Epic, the dominant EHR platform used by over 300 million patients, does not offer native SCIM provisioning. While Epic supports SSO integration, user provisioning requires expensive third-party middleware solutions from vendors like BeyondID, IDMWORKS, or Aquera. These middleware connectors add significant complexity and cost to what should be a standard provisioning workflow. The third-party solutions also have notable limitations - they don't support Groups via SCIM and lack several SCIM 2.0 attributes including phoneNumbers, addresses, and x509Certificates.

The lack of native provisioning creates a costly gap for healthcare organizations. Implementation costs for these middleware solutions range from $150K for small clinics to $10M+ for large hospitals, with ongoing maintenance and support fees. This forces IT teams to choose between manual user management (a compliance risk in HIPAA environments) or investing in complex, expensive middleware just to achieve basic user lifecycle automation. Given Epic's custom pricing that can reach $500M+ for large health systems, the additional middleware costs compound an already expensive platform.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation for Epic without requiring expensive third-party middleware. Works with any Epic implementation and any IdP. Flat pricing under $5K/year, a fraction of traditional middleware costs.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaNo native Epic OIN app. Provisioning available via third-party connectors: BeyondID, IDMWORKS, and Aquera. These are middleware solutions, not native Epic SCIM.
Microsoft Entra IDEpic to AD/Entra ID sync available via Aquera Sync Bridge. Not a native Epic integration.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Epic accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Epic pricing problem

Epic gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
EnterpriseCustom ($1.2K-$500M+)

Pricing structure

PlanPriceSCIM
EnterpriseCustom ($1.2K-$500M+)❌ Third-party only

Epic's implementation costs alone range from $150K for small clinics to $10M+ for large hospital systems, before adding provisioning middleware costs.

What this means in practice

Epic's lack of native SCIM creates a dependency chain that IT teams must manage:

Your integration stack becomes

Your IdP (Okta/Entra) → Third-party connector (BeyondID/Aquera) → Epic

Real-world complications

Two separate vendor relationships to manage
Additional middleware licensing costs (typically $20K-50K+ annually)
Extended implementation timelines due to three-party coordination
Troubleshooting requires coordinating between your IdP vendor, middleware vendor, and Epic

Additional constraints

Limited SCIM support
Even through third-party connectors, Epic doesn't support Groups, phoneNumbers, photos, addresses, or x509Certificates
HIPAA complexity
Healthcare compliance requirements add layers of security review for any provisioning solution
Middleware reliability
You're dependent on a third-party service maintaining connectivity to Epic's APIs
No direct Epic support
Epic support won't troubleshoot provisioning issues since they don't own the integration

Summary of challenges

  • Epic does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Epic actually offers for identity

Third-Party SCIM Connectors Only

Epic has no native SCIM endpoint. All provisioning happens through expensive third-party middleware solutions:

ProviderIntegration TypeKey Limitations
BeyondIDSCIM connector via Okta OINMiddleware dependency, additional licensing costs
IDMWORKSCustom SCIM bridgeRequires separate infrastructure and maintenance
AqueraAD/Entra ID sync bridgeLimited to Microsoft environments

What These Connectors Actually Support

Even with third-party middleware, Epic's SCIM implementation is severely limited:

Supported SCIM Operations:

Create users
Update basic user attributes (name, email)
Deactivate users

Not Supported:

Groups management via SCIM
phoneNumbers attribute
photos attribute
addresses attribute
x509Certificates attribute
Direct Epic API provisioning

SAML SSO (Enterprise Only)

Epic supports SAML 2.0 federation on Enterprise plans:

FeatureDetails
ProtocolSAML 2.0
Supported IdPsMost enterprise providers
User requirementAccounts must exist in Epic before SSO
HIPAA complianceAdditional security configurations required

Critical gap: Epic's SSO requires pre-existing user accounts, making the lack of robust provisioning even more problematic for healthcare organizations managing thousands of clinical users.

The Real Cost Problem

Epic implementations typically cost $150K-$10M+ depending on organization size. Adding third-party SCIM middleware means:

Additional licensing fees for the connector
Integration consulting costs
Ongoing maintenance of the middleware layer
HIPAA compliance validation for the entire provisioning chain

For healthcare organizations already spending hundreds of thousands on Epic licensing, the broken provisioning story creates an expensive operational headache.

What IT admins are saying

Epic's absence of native SCIM forces healthcare IT teams into expensive third-party solutions:

Epic doesn't have native SCIM - you need middleware like BeyondID or IDMWORKS, which adds $50K+ annually

Groups aren't supported through any SCIM connector, so we're still doing manual role assignments

Implementation took 8 months and cost us $200K just for the connector setup

HIPAA compliance makes everything harder - can't use standard provisioning workflows

Epic does not support Groups via SCIM

BeyondID Epic Connector documentation

Several SCIM 2.0 attributes not supported including phoneNumbers, photos, addresses, groups, x509Certificates

IDMWORKS Epic integration specs

The recurring theme

Healthcare organizations pay millions for Epic but get zero native provisioning capabilities. Third-party connectors cost $50K-200K annually and still don't support basic features like group management, forcing IT teams to maintain hybrid manual processes for a system that handles patient data.

The decision

Your SituationRecommendation
Small clinic (<25 users) with stable staffManual management may suffice given low turnover
Mid-size hospital (25-200 users)Use Stitchflow: middleware costs alone justify automation
Large health system (200+ users)Use Stitchflow: essential for scale and compliance
Multi-facility organizationUse Stitchflow: automation required across sites
HIPAA-compliant environment needing audit trailsUse Stitchflow: comprehensive logging and SOC 2 certification

The bottom line

Epic has no native SCIM support, forcing organizations into expensive third-party middleware solutions that can cost $150K-$10M+ just to implement. For healthcare organizations that need reliable provisioning without the middleware complexity and enterprise implementation costs, Stitchflow delivers SCIM-level automation at a fraction of the price.

Automate Epic without third-party complexity

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for Epic at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No native SCIM endpoint - requires third-party middleware (BeyondID, IDMWORKS, Aquera)Epic does not support Groups via SCIMSeveral SCIM 2.0 attributes not supported (phoneNumbers, photos, addresses, groups, x509Certificates)Implementation costs range from $150K for small clinics to $10M+ for large hospitalsHIPAA compliance requirements add complexity to provisioning

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No native SCIM endpoint - requires third-party middleware (BeyondID, IDMWORKS, Aquera)
  • Epic does not support Groups via SCIM
  • Several SCIM 2.0 attributes not supported (phoneNumbers, photos, addresses, groups, x509Certificates)
  • Implementation costs range from $150K for small clinics to $10M+ for large hospitals
  • HIPAA compliance requirements add complexity to provisioning

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Where to enable

Okta Admin Console → Applications → Epic → Sign On

No native Epic OIN app. Provisioning available via third-party connectors: BeyondID, IDMWORKS, and Aquera. These are middleware solutions, not native Epic SCIM.

Use Stitchflow for automated provisioning.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app

Where to enable

Entra admin center → Enterprise applications → Epic → Single sign-on

Epic to AD/Entra ID sync available via Aquera Sync Bridge. Not a native Epic integration.

Use Stitchflow for automated provisioning.

Unlock SCIM for
Epic

Epic doesn't offer SCIM. Get an enterprise-grade SCIM endpoint in your IdP, even without native support.

See how it works
Admin Console
Directory
Applications
Epic logo
Epic
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide