Summary and recommendation
Justworks, the PEO and HR platform, does not support SCIM provisioning or enterprise SSO integration on any plan. Currently, Justworks only offers basic OAuth login through Google and Microsoft accounts, with their documentation noting that "SSO foundation" is still in development. This leaves IT teams with no automated way to provision users, manage group memberships, or enforce consistent access policies across their HR infrastructure—particularly problematic given that Justworks often serves as a source system for employee data and organizational structure.
The lack of proper SSO and SCIM integration creates a significant gap in identity governance for organizations using Justworks as their PEO platform. IT teams must manually manage user accounts and cannot enforce centralized access controls or automated offboarding procedures. This is especially concerning for HR platforms that handle sensitive employee data and payroll information, where proper identity lifecycle management is critical for both security and compliance requirements.
The strategic alternative
Stitchflow provides SCIM-level provisioning through resilient browser automation for Justworks without requiring any plan upgrades or custom development work. Works with any IdP (Okta, Entra, Google Workspace, OneLogin) and integrates seamlessly with your existing identity infrastructure. Flat pricing under $5K/year, regardless of team size.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | No |
| SSO available? | Yes |
| SSO protocol | OAuth (Google, Microsoft) |
| Documentation | Not available |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | Via third-party | ❌ | No Okta OIN integration. Okta Verify supported for MFA only. |
| Microsoft Entra ID | Via third-party | ❌ | Microsoft login via OAuth supported. No native Azure AD SSO/SCIM integration. |
| Google Workspace | Via third-party | ❌ | No native support |
| OneLogin | Via third-party | ❌ | No native support |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages Justworks accounts manually. Here's what that costs:
The Justworks pricing problem
Justworks gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Payroll | $8/employee/month + $50/month base | ||
| PEO Basic | $59-79/employee/month | ||
| PEO Plus | $109/employee/month | ||
| EOR | $599/employee/month |
Current authentication options
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Payroll | $8/employee/month + $50/month base | ||
| PEO Basic | $59-79/employee/month | ||
| PEO Plus | $109/employee/month | ||
| EOR | $599/employee/month |
What this means in practice
No centralized identity management: You can't provision Justworks accounts through your IdP. Every employee needs manual account creation, and there's no way to automatically sync role changes, department moves, or terminations.
Limited SSO options: Only Google Workspace and Microsoft 365 organizations can use federated login. Companies using Okta, OneLogin, or other enterprise IdPs must rely on username/password authentication with mandatory MFA.
HR platform complications: Since Justworks often serves as the HR system of record, the lack of SCIM creates a circular dependency—you can't sync employee data from your IdP to Justworks, but Justworks holds the authoritative employee roster.
Additional constraints
Summary of challenges
- Justworks does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What Justworks actually offers for identity
OAuth Login (Google/Microsoft only)
Justworks currently supports basic OAuth integration with two providers:
| Setting | Details |
|---|---|
| Supported IdPs | Google Workspace, Microsoft 365 |
| Protocol | OAuth 2.0 |
| Configuration | Direct connection to Google/Microsoft accounts |
| User requirement | Manual account creation in Justworks required |
Critical limitation: This is OAuth login, not enterprise SSO. Users must have existing Google or Microsoft accounts, and IT admins cannot control access through their primary IdP (Okta, OneLogin, etc.).
Multi-Factor Authentication
| Feature | Details |
|---|---|
| Required for | Admin accounts (mandatory) |
| Methods | SMS, authenticator apps (Google Authenticator, Okta Verify), voice |
| User coverage | Admin-only requirement |
What's missing for enterprise identity management
Future roadmap: Justworks mentions "SSO foundation in development" but provides no timeline or feature details.
Real-world impact: HR teams must manually onboard every employee in Justworks and remember to remove access when they leave. For a platform that's supposed to streamline HR operations, the identity management is entirely manual.
What IT admins are saying
Justworks's limited SSO options create identity management gaps for IT teams:
- No enterprise SSO integration with major identity providers like Okta or Azure AD
- Manual user provisioning required across all Justworks modules
- Only basic Google and Microsoft OAuth login supported
- MFA management must be handled within Justworks rather than centrally
Login with Google/Microsoft supported. SSO with IdPs in development.
MFA required for admin accounts
The recurring theme
As a PEO platform that often serves as the HR system of record, Justworks forces IT teams to manage user access manually despite handling critical employee data. The lack of enterprise SSO means admins can't centrally control access to payroll, benefits, and HR functions through their existing identity infrastructure.
The decision
| Your Situation | Recommendation |
|---|---|
| Small team (<25 employees) on basic payroll | Manual management is workable given limited SSO |
| Growing HR team needing audit trails | Use Stitchflow: proper identity governance essential |
| Multi-location company using Justworks PEO | Use Stitchflow: automation critical at scale |
| Enterprise with compliance requirements | Use Stitchflow: manual provisioning creates audit gaps |
| Using Justworks as HR system of record | Use Stitchflow: sync from your IdP, not the reverse |
The bottom line
Justworks offers solid PEO services but currently lacks enterprise identity management—no SAML SSO or SCIM provisioning, just basic Google/Microsoft login. For organizations that need proper user lifecycle automation and compliance visibility, Stitchflow bridges the gap until Justworks builds their promised SSO foundation.
Automate Justworks without third-party complexity
Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for Justworks at <$5K/year, flat, regardless of team size.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Plan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- No native SAML/SCIM documented
- Google/Microsoft login only
- SSO foundation mentioned as future feature
- MFA required for admin accounts
Documentation not available.
Unlock SCIM for
Justworks
Justworks doesn't offer SCIM. Get an enterprise-grade SCIM endpoint in your IdP, even without native support.
See how it works


