Stitchflow
Mandrill logo

Mandrill SCIM guide

Connector Only

How to automate Mandrill user provisioning, and what it actually costs

Summary and recommendation

Mandrill (now Mailchimp Transactional Email) does not support SCIM provisioning as it's primarily an API service rather than a traditional SaaS application. User access is managed through the parent Mailchimp account, which requires a Standard or Premium plan (starting at $10-20/month plus pay-as-you-go email blocks at $20 per 25,000 emails). While SAML 2.0 SSO is available through Mailchimp's identity management, there's no automated provisioning - IT admins must manually create and manage developer API keys and user accounts through the Mailchimp interface.

This creates a significant operational burden for IT teams managing transactional email access. Unlike typical SaaS applications, Mandrill's API-centric nature means developers need specific API keys and permissions that can't be automatically provisioned based on group membership or role changes. When developers join, leave, or change teams, IT must manually coordinate with Mailchimp account administrators to provision or deprovision access, creating security gaps and compliance risks around API key management.

The strategic alternative

Mandrill has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0 (via Mailchimp)
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaVia third-partyMandrill is an add-on to Mailchimp. SSO and user management handled via parent Mailchimp account. Mandrill-specific Okta app exists but provisioning managed through Mailchimp.
Microsoft Entra IDVia third-partyNo direct Entra integration. Access managed via Mailchimp parent account. SSO configuration through Mailchimp's SAML settings.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Mandrill accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Mandrill pricing problem

Mandrill gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
DemoFree (500 emails to verified domain)
Block pricing$20/block (25,000 emails)
Dedicated IP+$29.95/month

Pricing structure

PlanPricingSCIMSSO
DemoFree (500 emails to verified domain)❌ Not availableVia Mailchimp
Block pricing$20/block (25,000 emails)❌ Not availableVia Mailchimp
Dedicated IP+$29.95/month❌ Not availableVia Mailchimp

Required dependency: Mandrill requires a Mailchimp Standard or Premium plan ($20-$350/month) - it's not available with Mailchimp Essentials.

What this means in practice

Since Mandrill has no direct user management, IT teams must:

Manage users through Mailchimp
All SSO configuration and user access happens in the parent Mailchimp account
Handle API key distribution manually
Developers need API keys distributed through secure channels
Coordinate with marketing teams
Mailchimp account owners (typically marketing) control developer access
Maintain dual governance
Security policies must cover both Mailchimp account access and API key management

Additional constraints

API-first architecture
Most Mandrill usage is programmatic, making traditional user provisioning less relevant
Mailchimp dependency
Any SSO issues with the parent Mailchimp account affect Mandrill access
Limited granular permissions
User access control is constrained by Mailchimp's permission model
Cross-team coordination required
IT, marketing, and development teams must align on access management

Summary of challenges

  • Mandrill does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Mandrill actually offers for identity

No Direct Identity Management

Mandrill (now Mailchimp Transactional) is an API-only service for sending transactional emails. It doesn't have its own user management system or identity features:

FeatureSupported?
Native SCIM❌ No
Direct SSO❌ No
User provisioning❌ No
Team management❌ No

The reality: Mandrill access is controlled entirely through your Mailchimp parent account. There's no separate user interface or team management for Mandrill itself.

Access via Mailchimp Account

Since Mandrill is a Mailchimp add-on, any identity management happens at the Mailchimp level:

RequirementDetails
Mailchimp planStandard ($20/month) or Premium ($350/month) minimum
SSO methodSAML 2.0 through Mailchimp's settings
User managementVia Mailchimp's team features
API accessControlled by Mailchimp account permissions

The problem: You're paying for a full Mailchimp marketing platform ($240-$4,200/year) just to get basic identity management for an email API. Most development teams using Mandrill don't need Mailchimp's marketing automation features.

What's Missing

Direct API key management
No automated provisioning of Mandrill API keys
Developer-focused access controls
No granular permissions for different API endpoints
Audit logging
Limited visibility into who's accessing Mandrill resources
Cost efficiency
Forced to maintain expensive Mailchimp subscription for simple transactional email API

What IT admins are saying

Mandrill's integration into the Mailchimp ecosystem creates confusion for IT teams managing transactional email access:

  • Indirect access management - Users must be provisioned through Mailchimp accounts rather than directly in Mandrill
  • API-first complexity - Primary interface is developer-focused, making user management less intuitive for IT admins
  • Documentation gaps - Limited direct SSO/provisioning guidance for Mandrill specifically vs. parent Mailchimp product
  • Dependency on parent account - Cannot manage Mandrill users independently from broader Mailchimp organization settings

Mandrill is an add-on to Mailchimp. SSO and user management handled via parent Mailchimp account.

Okta Integration Documentation

Requires Mailchimp Standard or Premium plan (not available with Essentials)

Mandrill Pricing Requirements

The recurring theme

IT teams must navigate Mailchimp's broader user management system to control access to what is essentially a developer API tool, creating an extra layer of complexity for transactional email operations.

The decision

Your SituationRecommendation
Small development team (<10 users) using API keysManual management is acceptable
Stable team with existing Mailchimp account setupContinue manual management via Mailchimp
Large organization with frequent developer onboarding/offboardingUse Stitchflow: automation essential for API access control
Enterprise with compliance requirements for email infrastructureUse Stitchflow: automation essential for audit trail
Multi-team environment with separate transactional email needsUse Stitchflow: automation strongly recommended

The bottom line

Mandrill operates as part of the Mailchimp ecosystem without direct SCIM support, requiring all user management through your parent Mailchimp account. For organizations that need automated provisioning for their transactional email infrastructure without the complexity of managing nested account hierarchies, Stitchflow provides the streamlined automation you need.

Make Mandrill workflows AI-native

Mandrill has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

Primarily an API serviceAccess via Mailchimp accountSSO managed through Mailchimp parent accountNo direct SCIM documentation for Mandrill itself

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • Primarily an API service
  • Access via Mailchimp account
  • SSO managed through Mailchimp parent account
  • No direct SCIM documentation for Mandrill itself

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Mandrill → Sign On

Mandrill is an add-on to Mailchimp. SSO and user management handled via parent Mailchimp account. Mandrill-specific Okta app exists but provisioning managed through Mailchimp.

Use Stitchflow for automated provisioning.

Unlock SCIM for
Mandrill

Mandrill has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
Mandrill logo
Mandrill
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

6sense logo

6sense

No SCIM

B2B Revenue Intelligence / ABM

ProvisioningNot Supported
Manual Cost$11,754/yr

6sense, the B2B revenue intelligence platform, has paused SCIM provisioning for new customers until Q4 2026. While existing customers with SCIM enabled can continue using it, new implementations are limited to JIT (Just-In-Time) provisioning through SAML SSO. This creates a significant gap for IT teams managing revenue intelligence access, as JIT only creates users on first login and provides minimal attribute mapping (email, first name, last name only). For an enterprise platform with typical pricing of $55,000-$130,000 annually, the absence of automated user lifecycle management is a substantial limitation. The lack of SCIM until Q4 2026 forces IT teams into manual provisioning workflows for a platform handling sensitive revenue data. While SAML SSO handles authentication, it doesn't address user lifecycle events like role changes, department transfers, or offboarding. This creates compliance risks in revenue teams where access to prospect data and sales intelligence must be tightly controlled. The nearly two-year wait for SCIM restoration means organizations implementing 6sense today face manual user management for the foreseeable future.

View full guide
Aha! logo

Aha!

No SCIM

Product Management / Roadmapping

ProvisioningNot Supported
Manual Cost$11,754/yr

Aha! Roadmaps, the product roadmapping platform, does not support SCIM provisioning on any plan. While Aha! offers SAML 2.0 SSO integration with identity providers like Okta, Entra ID, and OneLogin, this only handles authentication through JIT (Just-In-Time) provisioning. The critical limitation: JIT provisioning creates user accounts with no default role or access permissions, requiring administrators to manually configure access for each user after they first sign in. For product teams managing strategic roadmaps and stakeholder access, this creates significant operational overhead. Since product roadmaps contain sensitive strategic information and stakeholder access typically varies by product area, IT administrators must manually assign appropriate roles and workspace permissions after each user is provisioned. There's no automatic deprovisioning when users leave the organization, creating potential security gaps. This manual process becomes particularly problematic for larger product organizations where dozens of stakeholders across different business units need carefully managed access to specific roadmaps.

View full guide
Appcues logo

Appcues

No SCIM

Product Adoption / User Onboarding

ProvisioningNot Supported
Manual Cost$11,754/yr

Appcues, the product adoption platform used by product managers and growth teams, explicitly does not support SCIM provisioning on any plan—not even Enterprise. While Appcues offers SAML 2.0 SSO integration starting at the Enterprise tier with just-in-time (JIT) provisioning, this only creates users during first login and provides no automated deprovisioning capabilities. For product teams where access needs change frequently as people move between projects or leave the company, this creates a significant security gap. The lack of SCIM means IT teams must manually manage user lifecycle for Appcues accounts, even though the platform handles sensitive product analytics and user flow data. When employees leave or change roles, their Appcues access remains active until manually revoked—a compliance risk that's particularly problematic given Appcues' role in tracking user behavior and product metrics. With MAU-based pricing starting at $300/month and scaling significantly with usage, paying for orphaned accounts also creates unnecessary cost bloat.

View full guide