Stitchflow
One Medical logo

One Medical SCIM guide

Connector Only

How to automate One Medical user provisioning, and what it actually costs

Native SCIM not available

Summary and recommendation

One Medical, Amazon's primary care membership service used by 8,500+ employers for employee healthcare benefits, does not support SCIM provisioning on any plan. While One Medical offers basic SSO integration through Okta's Secure Web Authentication (SWA) method, this only handles authentication for existing users—it cannot provision new accounts or manage user lifecycle. For the majority of enterprise customers using One Medical through employer-sponsored programs, this creates a significant gap between employee onboarding in your IdP and healthcare access provisioning.

This limitation forces IT teams to manually coordinate healthcare benefit enrollment with HR systems, often requiring separate processes outside of standard user provisioning workflows. When employees join or leave, their One Medical access must be managed independently from other business applications, creating compliance risks and administrative overhead. For organizations with hundreds or thousands of employees relying on One Medical as a core healthcare benefit, this manual process becomes a significant operational burden.

The strategic alternative

One Medical has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOne Medical Member Login and OneMedical integrations exist in OIN. SWA (Secure Web Authentication) for SSO. No SCIM provisioning supported.
Microsoft Entra IDVia third-partyNo Microsoft Entra gallery provisioning tutorial found for One Medical.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages One Medical accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The One Medical pricing problem

One Medical gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Individual$199/person/year
Business (via Justworks)$149/person/year
Enterprise (employer-sponsored)Custom quote

Pricing structure

PlanPriceSSOSCIM
Individual$199/person/year
Business (via Justworks)$149/person/year
Enterprise (employer-sponsored)Custom quote

What this means in practice

No automated user lifecycle management: IT teams cannot programmatically create, update, or deactivate One Medical accounts. Every employee onboarding, role change, or termination requires manual intervention or unreliable screen scraping.

SSO limitations: Even Enterprise customers only get Secure Web Authentication (SWA) - a credential-stuffing approach that's less secure and reliable than SAML or OIDC. SWA requires storing and replaying login credentials through the browser.

Additional constraints

Amazon acquisition complexity
One Medical's integration roadmap is uncertain following Amazon's $3.9B acquisition in 2022
Healthcare compliance overhead
Manual provisioning increases audit complexity for HIPAA-covered employers
Employer-sponsored model friction
Enterprise setup requires direct Amazon negotiations, not self-service activation
Limited IdP support
Only basic Okta integration exists; no Microsoft Entra or Google Workspace gallery apps

Summary of challenges

  • One Medical does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What One Medical actually offers for identity

SSO via Secure Web Authentication (SWA)

One Medical provides basic single sign-on through Okta's password vaulting system:

SettingDetails
ProtocolSWA (Secure Web Authentication)
Supported IdPsOkta (via OIN integration)
Authentication methodPassword vaulting/credential injection
User managementManual account creation required

Critical limitation: SWA is not true federated SSO. It's automated password entry - Okta stores One Medical credentials and injects them during login. Users still need individual One Medical accounts created manually.

Okta Integration (via OIN)

The official Okta Integration Network has two One Medical integrations with identical limitations:

FeatureSupported?
SAML SSO❌ No
OIDC SSO❌ No
SWA (password vaulting)✓ Yes
Create users❌ No
Update users❌ No
Deactivate users❌ No
Group push❌ No

Microsoft Entra Integration

FeatureSupported?
Gallery app❌ No
SAML SSO❌ No
Provisioning❌ No

Reality check: One Medical offers no meaningful identity integration. As a healthcare membership service (now owned by Amazon), they've prioritized patient experience over enterprise IT requirements. The SWA integration is a band-aid solution that still requires manual user lifecycle management for all 8,500+ employer customers.

What IT admins are saying

One Medical's lack of SCIM provisioning forces IT teams into manual account management for their primary care benefits platform:

  • Manual user provisioning required even with SSO configured
  • No automated deprovisioning when employees leave the company
  • Limited to SWA-based SSO instead of modern SAML/OIDC protocols
  • Enterprise features require custom pricing negotiations with Amazon

One Medical Member Login and OneMedical integrations exist in OIN. SWA (Secure Web Authentication) for SSO. No SCIM provisioning supported.

Okta Integration Network documentation

User accounts must be manually managed since there's no SCIM API available for user provisioning.

IT admin feedback on healthcare app limitations

The recurring theme

Despite being owned by Amazon and serving 8,500+ employers, One Medical still requires manual user lifecycle management. IT teams must coordinate between their identity provider and One Medical's admin portal for every employee change, creating operational overhead for what should be a seamless employee benefit.

The decision

Your SituationRecommendation
Small company (<25 employees) using One MedicalManual management is acceptable
HR team comfortable with periodic manual onboardingManual management with SSO for authentication
Mid-size organization (50+ employees) with regular turnoverUse Stitchflow: automation essential for efficiency
Enterprise with 500+ employees and One Medical benefitUse Stitchflow: automation critical for scale
Multi-location company with distributed HR managementUse Stitchflow: centralized provisioning strongly recommended

The bottom line

One Medical offers valuable primary care services to 8,500+ employers, but provides zero automation for user lifecycle management. Without SCIM support and only basic SWA authentication, IT teams face endless manual provisioning work. For organizations that want to deliver healthcare benefits without administrative overhead, Stitchflow automates the entire user lifecycle.

Make One Medical workflows AI-native

One Medical has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

Primary care membership service (now owned by Amazon)No SCIM API available for user provisioningSSO via SWA only (not SAML/OIDC)8,500+ employers use One Medical for employee benefitsEnterprise pricing requires direct contact

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • Primary care membership service (now owned by Amazon)
  • No SCIM API available for user provisioning
  • SSO via SWA only (not SAML/OIDC)
  • 8,500+ employers use One Medical for employee benefits
  • Enterprise pricing requires direct contact

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Where to enable

Okta Admin Console → Applications → One Medical → Sign On

One Medical Member Login and OneMedical integrations exist in OIN. SWA (Secure Web Authentication) for SSO. No SCIM provisioning supported.

Use Stitchflow for automated provisioning.

Unlock SCIM for
One Medical

One Medical has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
One Medical logo
One Medical
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide