Stitchflow
Figma logo

Figma SCIM guide

Native SCIM

How to automate Figma user provisioning, and what it actually costs

Native SCIM requires Organization or Enterprise plan

Summary and recommendation

Figma supports SCIM provisioning, but only starting with the Organization plan at $55/user/month—a 244% increase from Professional ($16/user/month). Even then, Organization only provides basic SCIM functionality. Full seat management via SCIM (automatically assigning Editor vs. Admin permissions) requires Enterprise at $90/user/month. This means teams upgrading from Professional face a $74/user/month jump to get complete provisioning automation.

The March 2025 billing model changes add another complication: existing SCIM configurations may require migration, creating unexpected technical debt for IT teams who thought their provisioning was settled. For a 100-person Professional team, accessing full SCIM seat management means paying an extra $88,800/year—often just to automate what could be simple user lifecycle management.

The strategic alternative

Figma gates SCIM behind Organization or Enterprise. Skip the Organization or Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Figma accounts manually. Here's what that costs:

Source: Stitchflow customers using Figma, normalized to 500 employees:
Orphaned accounts (ex-employees with access)3
Unused licenses12
IT hours spent on manual management/year112 hours
Unused license cost/year$3,976
IT labor cost/year$6,714
Cost of compliance misses/year$657
Total annual financial impact$11,347

The Figma pricing problem

Figma gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure (Full Seats, Billed Annually)

PlanPriceSSOSCIM
Professional$16/user/mo
Organization$55/user/mo
Basic
Enterprise$90/user/mo
Full

Key distinction: Organization provides basic SCIM (create/update/deactivate users) but all provisioned users receive View-only seats by default. Upgrading to Editor/Admin requires manual intervention. Enterprise enables automatic seat type assignment via SCIM attributes.

What this means in practice

Using current list prices for SCIM access:

Team SizeUpgrade to OrganizationUpgrade to Enterprise
50 users+$23,400/year+$44,400/year
100 users+$46,800/year+$88,800/year
200 users+$93,600/year+$177,600/year

Calculation: (New tier price - $16) × users × 12 months

For teams that need true automated seat management (not just user lifecycle), Enterprise is effectively required, making the real SCIM tax $74/user/month.

Additional constraints

March 2025 migration
Existing SCIM customers may need to reconfigure seat management workflows due to billing model changes.
Annual commitment
Both Organization and Enterprise require yearly contracts—no monthly flexibility.
Manual seat upgrades
Organization tier SCIM creates users but requires separate processes for Editor/Admin seat assignments.
IdP complexity
Multiple IdP support (Governance+) only available on Enterprise, limiting hybrid identity scenarios.

Summary of challenges

  • Figma supports SCIM but only at Enterprise tier ($90/user/mo (annual only))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Figma doesn't sell SCIM à la carte. It's bundled with Organization/Enterprise features:

SCIM automated provisioning (basic on Organization, full seat management on Enterprise)
SAML single sign-on (SSO)
Advanced workspace administration
Guest access controls
Enhanced security settings
Design system analytics and libraries (Enterprise)
Multiple IdP support for governance (Enterprise only)
Dedicated support channels

The catch: Figma's March 2025 billing model changes are forcing existing SCIM users to potentially migrate their setup, adding unexpected complexity to what should be straightforward provisioning.

Stitchflow Insight

If you need advanced design collaboration features anyway, the Organization upgrade may make sense. If you just want automated user provisioning, you're paying for design-specific features your IT team won't use. We estimate ~65% of Organization/Enterprise features are irrelevant for teams that only need SCIM provisioning.

What IT admins are saying

Community sentiment on Figma's SCIM implementation is mixed, with growing frustration over the 2025 billing changes. Common complaints:

  • Confusion over Organization vs Enterprise plan differences for SCIM features
  • Concern about March 2025 billing model changes disrupting existing SCIM setups
  • Full seat management requiring Enterprise tier at $90/user/month
  • Uncertainty about migration requirements for current SCIM users

The billing model changes in 2025 are going to be a nightmare for our SCIM setup - nobody knows exactly what we'll need to migrate.

Reddit r/sysadmin

Why does full SCIM seat management require Enterprise when basic provisioning works on Organization? The feature differentiation makes no sense.

Figma Community Forum

The recurring theme

Figma's SCIM works well technically, but the upcoming billing changes and confusing plan tiers are creating uncertainty for IT teams who need reliable, long-term provisioning solutions.

The decision

Your SituationRecommendation
On Professional, need SCIMUse Stitchflow: avoid the $39/user/month Organization upgrade
On Organization, need full seat managementUse Stitchflow: skip the $35/user/month Enterprise jump
Already on Enterprise with SCIMUse native SCIM: you're paying for it, but prepare for March 2025 migration
Worried about March 2025 billing changesUse Stitchflow: skip the migration complexity entirely
Small team, minimal user changesManual may work: but watch for access sprawl as design teams grow

The bottom line

Figma gates SCIM behind Organization or Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Make Figma workflows AI-native

Figma gates SCIM behind Organization or Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Organization or Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • Only Organization Admins can set up SAML SSO
  • Enterprise plan required for full seat management via SCIM
  • March 2025 billing changes may require SCIM migration steps

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Figma → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Enterprise required for SCIM

Figma gates SCIM behind Organization or Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Figma → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Enterprise required for SCIM

Figma gates SCIM behind Organization or Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Figma

Figma gates SCIM behind Organization or Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade, avoiding a 244% markup.

See how it works
Admin Console
Directory
Applications
Figma logo
Figma
via Stitchflow

Last updated: 2026-01-02

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

1Password logo

1Password

SCIM Tax
SCIM StatusIncluded
Manual Cost$11,167/yr

1Password supports SCIM provisioning on its Business plan ($7.99/user/month), but requires deploying and managing the 1Password SCIM Bridge on your own infrastructure. This self-hosted approach means you're responsible for maintaining servers, handling updates, and troubleshooting connectivity issues between your identity provider and 1Password's systems. The SCIM Bridge also operates separately from SSO (which uses OIDC only), requiring you to configure and maintain two distinct integrations. This architecture creates operational overhead that many IT teams don't want to manage. Unlike cloud-native SCIM implementations, you're essentially running 1Password's provisioning infrastructure for them. When the SCIM Bridge goes down, provisioning stops working. When 1Password updates their API, you need to update your Bridge deployment. For teams that just want automated user lifecycle management, this becomes an ongoing maintenance burden.

View full guide
Amplitude logo

Amplitude

SCIM Tax

Product Analytics

SCIM StatusIncluded
Manual Cost$11,754/yr

Amplitude supports SCIM provisioning, but only on Growth plans (starting around $36K/year) or Enterprise plans with custom pricing. While Amplitude's SCIM implementation covers the core functionality—creating, updating, and deactivating users—it requires SCIM to be specifically enabled for your organization, and regenerating the SCIM key immediately invalidates existing integrations without warning. For product teams on Plus plans ($49/month), upgrading to Growth just to unlock SCIM means jumping from under $600/year to $36,000+/year—a 60x increase. That's often more than the entire analytics budget for smaller product teams. The gap becomes particularly problematic for cross-functional product teams where analysts, PMs, and engineers need varying levels of access to user behavior data, but manual provisioning creates security risks around sensitive analytics permissions.

View full guide
Bugsnag logo

Bugsnag

SCIM Tax

Error Monitoring / Observability

SCIM StatusIncluded
Manual Cost$11,754/yr

Bugsnag supports native SCIM provisioning, but only on Enterprise plans with custom pricing. This creates a significant cost barrier since you must upgrade from Business ($475/month for 1M events) to Enterprise just to unlock automated user provisioning. For many engineering teams, this represents a substantial price jump for provisioning features that should be standard across all paid plans. The Enterprise requirement is particularly problematic for mid-size development teams who need error monitoring automation but don't require Enterprise-level features. Without SCIM, IT teams must manually provision developer accounts and manage team memberships for project access—creating security gaps when developers change teams or leave the company. OneLogin users face an additional limitation: SCIM isn't supported on Enterprise instances, forcing a workaround through the standard Bugsnag app.

View full guide