Summary and recommendation
Harvest, the popular time tracking platform, does not offer native SCIM provisioning on any plan. While Harvest provides SAML SSO integration on its Premium plan ($14/seat/month annually) with major identity providers like Okta, Azure AD, and OneLogin, authentication alone doesn't solve the user lifecycle challenge. IT teams must manually create user accounts in Harvest before SSO can work—the system won't auto-provision users upon first login. OneLogin does offer a proprietary provisioning connector, but this locks you into their specific IdP and doesn't address broader lifecycle automation needs.
This creates a significant operational burden for organizations managing employee onboarding, role changes, and offboarding. Without automated provisioning, IT teams face manual account creation delays, inconsistent access patterns, and the compliance risk of orphaned accounts when employees leave. For a time tracking system that touches most employees, this manual overhead scales poorly as organizations grow.
The strategic alternative
Harvest has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | No |
| SSO available? | Yes |
| SSO protocol | SAML 2.0, Google SSO |
| Documentation | Not available |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | Via third-party | ❌ | SAML SSO only. No SCIM provisioning available. Users must be manually added to Harvest after assignment in Okta. |
| Microsoft Entra ID | Via third-party | ❌ | SAML SSO only. No SCIM provisioning. Users must be manually added to Harvest - SSO does not auto-create accounts. |
| Google Workspace | Via third-party | ❌ | No native support |
| OneLogin | Via third-party | ❌ | No native support |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages Harvest accounts manually. Here's what that costs:
The Harvest pricing problem
Harvest gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Pro | $10.80/seat/mo (annual) | ||
| Premium | $14/seat/mo (annual) |
Pricing structure
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Pro | $10.80/seat/mo (annual) | ||
| Premium | $14/seat/mo (annual) |
OneLogin exception: OneLogin offers a proprietary provisioning connector for Harvest, but this creates vendor lock-in and doesn't help organizations using Okta, Entra ID, or Google Workspace.
What this means in practice
Without SCIM provisioning, IT teams face these operational challenges:
For a 100-person organization using Premium ($1,400/month), these manual processes typically require 2-3 hours of admin work per week.
Additional constraints
Summary of challenges
- Harvest does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What Harvest actually offers for identity
SAML SSO (Premium plan required)
Harvest supports SAML 2.0 integration starting at $14/seat/month on the Premium plan:
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Supported IdPs | Okta, Microsoft Entra ID, OneLogin, generic SAML providers |
| Configuration | Manual setup via IdP metadata exchange |
| User requirement | Users must exist in Harvest before SSO login |
| JIT provisioning | ❌ Not supported |
Critical limitation: SAML SSO requires the Premium plan ($14/seat/month vs $10.80 for Pro) and does not create accounts automatically. You must manually provision every user in Harvest before they can authenticate via SSO.
Google SSO Alternative
Harvest also offers Google Workspace integration:
OneLogin Connector Exception
OneLogin users have access to a proprietary connector that provides basic provisioning capabilities:
| Feature | OneLogin Connector |
|---|---|
| Create users | ✓ Yes |
| Update users | ✓ Yes |
| Deactivate users | ✓ Yes |
| Group management | Limited |
This connector is OneLogin-specific and doesn't help teams using Okta, Entra ID, or Google Workspace.
Bottom line: Harvest charges 30% more for Premium just to get SAML SSO, provides no native SCIM provisioning, and leaves most IdP users with completely manual account management. Only OneLogin customers get any form of automated provisioning.
What IT admins are saying
Harvest's lack of automated provisioning creates operational overhead for IT teams managing time tracking access:
- Manual user creation required even after SSO setup
- No lifecycle management - departing employees must be manually removed
- OneLogin users get provisioning via connector, but other IdPs are left out
- Premium plan required just for basic SAML SSO functionality
User accounts must be manually created in Harvest before SSO authentication will work
We have SSO working but still need to remember to add/remove users in Harvest separately from our identity provider
The recurring theme
Harvest treats SSO as authentication-only, leaving IT teams to manually manage the full user lifecycle. Even organizations paying for Premium plans get no relief from provisioning busywork.
The decision
| Your Situation | Recommendation |
|---|---|
| Small team (<20 users) with low turnover | Manual management is acceptable given no native SCIM |
| Using OneLogin for SSO | Consider OneLogin's Harvest connector for basic provisioning |
| Growing team (20+ users) with regular hires/departures | Use Stitchflow: manual provisioning becomes unwieldy |
| Enterprise with compliance requirements | Use Stitchflow: automation essential for audit trail |
| Multi-project teams with frequent contractor onboarding | Use Stitchflow: automation strongly recommended |
The bottom line
Harvest offers solid time tracking with SAML SSO on Premium plans, but zero native SCIM support means manual user creation for every new hire. For teams that need automated provisioning without the operational overhead of manual account management, Stitchflow provides the missing automation layer.
Make Harvest workflows AI-native
Harvest has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Plan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- No native SCIM provisioning
- SAML SSO requires Premium plan
- OneLogin has provisioning via connector
- Google SSO and 2FA also available
Documentation not available.
Configuration for Okta
Integration type
Okta Integration Network (OIN) app
Where to enable
Docs
SAML SSO only. No SCIM provisioning available. Users must be manually added to Harvest after assignment in Okta.
Use Stitchflow for automated provisioning.
Configuration for Entra ID
Integration type
Microsoft Entra Gallery app
Where to enable
SAML SSO only. No SCIM provisioning. Users must be manually added to Harvest - SSO does not auto-create accounts.
Use Stitchflow for automated provisioning.
Unlock SCIM for
Harvest
Harvest has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.
See how it works


