Stitchflow
HiBob logo

HiBob SCIM guide

Native SCIM

How to automate HiBob user provisioning, and what it actually costs

Native SCIM requires All plans plan

Summary and recommendation

HiBob includes native SCIM support across all plans at no additional cost, with bidirectional sync capabilities for Okta, Entra ID, and other major identity providers. However, HiBob creates a unique challenge: as an HRIS platform, it's typically the authoritative source for employee data, meaning it pushes user information TO your IdP rather than receiving it. This reverses the normal provisioning flow and can create complex sync conflicts when managing users across multiple systems.

The bidirectional sync complexity becomes particularly problematic when HiBob and your IdP disagree on employee status, department changes, or termination dates. IT teams often struggle with determining which system should be the ultimate source of truth for different attributes, leading to manual intervention and potential security gaps during employee transitions.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation that handles the complex bidirectional sync logic, ensuring clean data flow between HiBob and your identity provider without manual intervention. Works with any HiBob plan and any IdP. Flat pricing under $5K/year, regardless of employee count.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredFree
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages HiBob accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The HiBob pricing problem

HiBob gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Standard$16-25/employee/mo (custom pricing)

Plan Structure

PlanPriceSCIM
Standard$16-25/employee/mo (custom pricing)

All HiBob plans include SCIM capabilities, but pricing requires sales contact and custom quoting based on company size and module requirements.

What this means in practice

The challenge isn't cost—it's architectural complexity:

Source of truth conflicts: Most organizations use HiBob as their HR system of record, meaning employee data flows FROM HiBob TO your IdP (Okta, Entra ID), not the reverse. This creates questions about which system manages what attributes.

Bidirectional sync complexity: When you need true bidirectional sync (HiBob updates IdP, IdP manages app access), you're coordinating two provisioning systems that can conflict or create data loops.

Implementation overhead: Custom pricing typically includes 10-20% implementation fees, and setup requires careful mapping of data flows, attribute ownership, and conflict resolution rules.

Additional constraints

Sales-gated pricing
No self-serve options; all pricing requires sales engagement and custom quoting.
Implementation complexity
Bidirectional SCIM setups require extensive planning to avoid data conflicts and sync loops.
Multi-year commitments
Discounts (30-35%) typically require multi-year contracts, limiting flexibility.
Source system dependencies
If HiBob goes down or has sync issues, it can cascade to your entire identity infrastructure.

Summary of challenges

  • HiBob supports SCIM but only at Free tier (custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What HiBob actually offers for identity

HiBob includes SCIM provisioning on all plans, but there's a key distinction: HiBob is designed to be your HR source of truth, not just another app receiving provisioning data.

SCIM 2.0 bidirectional sync with Okta, Azure AD, and other IdPs
SAML 2.0 single sign-on across all plans
Push employee data FROM HiBob TO your identity provider
Automated onboarding/offboarding workflows
Department and organizational unit sync as groups
Custom attribute mapping for job titles, locations, departments
JIT (Just-in-Time) provisioning support

The challenge isn't feature limitations—it's architectural complexity. HiBob's SCIM works in reverse from most SaaS apps. Instead of your IdP pushing users to HiBob, HiBob pushes employee records to your IdP when someone is hired, transferred, or terminated. This creates bidirectional sync scenarios that require careful planning to avoid data conflicts and determine the authoritative source for different attributes.

Most IT teams struggle with the "source of truth" question: should employee data live in HiBob (HR-driven) or your IdP (IT-driven)? The answer determines your entire provisioning architecture.

What IT admins are saying

Community sentiment on HiBob's SCIM implementation is mixed, with most concerns centered around complexity rather than availability. Common challenges:

  • Determining the correct source of truth between HiBob and the IdP
  • Managing bidirectional sync without creating data conflicts
  • Understanding which direction data should flow for different attributes
  • Configuring sync logic when HiBob serves as the HR master

The trickiest part with HiBob is figuring out who owns what data. You don't want employee updates in your IdP overwriting HR changes in Bob, but you also need identity changes to flow back.

IT Admin, Reddit

Bidirectional SCIM sounds great until you realize you need to map out every possible conflict scenario. What happens when someone updates a user's department in both systems?

SysAdmin Forum

The recurring theme

HiBob's SCIM works well technically, but the complexity of managing bidirectional sync between HR and identity systems creates operational headaches that require careful planning.

The decision

Your SituationRecommendation
Using HiBob as HR source, need automated sync to IdPUse Stitchflow: simplifies bidirectional sync without custom implementation
Have native SCIM but struggling with sync direction/conflictsUse Stitchflow: eliminates source-of-truth confusion with managed rules
Small HR team, infrequent employee changesNative SCIM may work: you're already paying for it on all plans
Complex org structure, multiple sync requirementsUse Stitchflow: handles nuanced mapping without IT overhead
Basic setup, clear data flow requirementsNative SCIM is viable: HiBob's implementation is reasonably robust

The bottom line

While HiBob includes SCIM on all plans, its role as an HR source system creates bidirectional sync complexity that IT teams often underestimate. Stitchflow eliminates the architectural headaches and provides managed automation for under $5K/year.

Automate HiBob without the tier upgrade

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for HiBob at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Free

Prerequisites

SSO must be configured first

Key limitations

  • Often acts as HR source system (pushes TO IdP)
  • Can push data to Azure AD/Okta
  • Bidirectional sync available
  • Custom pricing requires sales contact

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → HiBob → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Full SCIM integration. Imports users from Bob to Okta, syncs departments/sites/lists as groups, handles terminations and rehires. Also available: Aquera User Mastering connector.

Native SCIM is available on Free. Use Stitchflow if you need provisioning without the tier upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → HiBob → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Bidirectional sync with Entra ID. Can push employee data from Bob to Entra ID. Third-party solutions (Aquera, RoboMQ) also available for enhanced sync.

Native SCIM is available on Free. Use Stitchflow if you need provisioning without the tier upgrade.

Unlock SCIM for
HiBob

Stop paying the SCIM Tax for HiBob. Get enterprise-grade SCIM at a fraction of the enterprise plan cost.

See how it works
Admin Console
Directory
Applications
HiBob logo
HiBob
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

15Five logo

15Five

Has SCIM

Performance Management / Employee Engagement

SCIM StatusIncluded
Manual Cost$11,754/yr

15Five includes SCIM provisioning on all plans starting at $4/user/month, with full support for creating, updating, and deactivating users across Okta, Entra ID, Google Workspace, and OneLogin. However, 15Five's SCIM implementation has a critical prerequisite: SSO must be configured first, and their documentation explicitly warns against using JIT provisioning alongside SCIM due to duplicate user creation risks. This creates operational friction for IT teams managing performance management rollouts. The SSO-first requirement means you can't test SCIM provisioning in isolation, and the JIT conflict forces you to choose between automated onboarding convenience and reliable user lifecycle management. For HR-driven tools like 15Five that need to maintain accurate manager hierarchies and team structures, these provisioning gaps can disrupt performance review cycles and employee engagement tracking.

View full guide
Dropbox logo

Dropbox

Has SCIM
SCIM StatusIncluded
Manual Cost$11,754/yr

Dropbox Business supports SCIM 2.0 provisioning on Standard plans and above ($15/user/month), with solid integration across major identity providers including Okta, Azure AD, and Google Workspace. However, there's a critical architectural limitation: Dropbox Sign (formerly HelloSign) operates as a separate product that doesn't support SCIM at all, despite being a core part of many organizations' document workflows. This creates a significant provisioning gap for IT teams. While your main Dropbox storage accounts can be automatically managed, any users who need access to Dropbox Sign must be manually provisioned and deprovisioned. For organizations relying on both products, this means maintaining hybrid workflows where some users are automated and others require manual intervention—exactly the kind of inconsistency that leads to compliance issues and security gaps during employee transitions.

View full guide
Ramp logo

Ramp

Has SCIM

Corporate Cards / Expense Management

SCIM StatusIncluded
Manual Cost$11,754/yr

Ramp offers excellent native SCIM support across all plans, including their free tier. Users are automatically created, updated, and deactivated through standard SCIM protocols with major IdPs like Okta and Microsoft Entra. However, several operational limitations create gaps: SCIM deactivation doesn't actually delete users (they remain as "inactive"), corporate card termination requires manual intervention, and you can't run both SCIM and HRIS integrations simultaneously. These limitations matter most for financial compliance and offboarding workflows. When employees leave, their Ramp accounts stay in the system indefinitely, and any active corporate cards remain functional until manually terminated. For finance teams managing hundreds of users and cards, this creates audit trail concerns and potential security exposure from dormant accounts.

View full guide