Stitchflow
PayPal logo

PayPal SCIM guide

Native SCIM

How to automate PayPal user provisioning, and what it actually costs

Native SCIM requires Enterprise (Braintree) plan

Summary and recommendation

PayPal supports SCIM through its Braintree platform, but only on Enterprise accounts with transaction-based pricing starting at 2.59% + $0.49 per transaction. The bigger issue: SCIM onboarding is irreversible—once enabled, you can never revert to manual user management in the control panel. You also can't create or delete groups via SCIM (only update existing ones), and all non-SSO users must be converted to SSO before SCIM activation.

This creates a significant deployment risk for payment operations teams. The irreversible nature means you're locked into SCIM management permanently, while the group limitations force manual administration for new merchant access patterns. For finance teams managing payment platform access, this inflexibility conflicts with the dynamic nature of payment operations where user roles and merchant account access frequently change.

The strategic alternative

PayPal gates SCIM behind Enterprise (Braintree). Skip the Enterprise (Braintree) plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages PayPal accounts manually. Here's what that costs:

Source: Stitchflow customers using PayPal, normalized to 500 employees:
Orphaned accounts (ex-employees with access)10
Unused licenses10
IT hours spent on manual management/year70 hours
Unused license cost/year$0
IT labor cost/year$4,194
Cost of compliance misses/year$2,341
Total annual financial impact$6,534

The PayPal pricing problem

PayPal gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
StandardTransaction-based (2.59% + $0.49)
Enterprise (Braintree)Custom pricing

Plan Structure

PlanPriceSCIM
StandardTransaction-based (2.59% + $0.49)
Enterprise (Braintree)Custom pricing

Note: SCIM requires Enterprise Braintree accounts with custom negotiated rates. Standard PayPal accounts cannot access SCIM functionality.

What this means in practice

PayPal's SCIM implementation creates a point of no return:

One-way conversion
Once SCIM is enabled, you cannot revert to manual user management
Control panel lockout
After SCIM activation, you lose the ability to edit, create, or delete SSO users through the PayPal interface
Pre-conversion requirements
All non-SSO users must be converted to SSO before SCIM onboarding
Sandbox dependency
Production SCIM requires a working sandbox merchant account first

For payment operations teams, this creates a high-stakes implementation where careful planning is essential—any mistakes in the initial setup become permanent.

Additional constraints

Group management limitations
SCIM can only update existing groups, not create or delete them. Group structure must be established manually first.
Enterprise pricing barrier
Moving to Enterprise Braintree typically requires significant transaction volume commitments and custom rate negotiations.
Testing complexity
The sandbox merchant requirement adds implementation overhead, requiring parallel test environments.
Identity provider specifics
Group sync with Entra requires exact naming conventions with 'BT SANDBOX' or 'BT PRODUCTION' prefixes.

Summary of challenges

  • PayPal supports SCIM but only at Enterprise tier (custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

PayPal doesn't sell SCIM separately—it's only available through Braintree Enterprise accounts and comes bundled with their full payment platform:

SCIM 2.0 automated provisioning (one-way, irreversible)
SAML 2.0 single sign-on
Advanced merchant account controls
Role-based access management
Enhanced security settings
Custom transaction pricing (flat rates, interchange plus)
Dedicated enterprise support

The catch: you're not just paying for identity management—you're buying into Braintree's entire payment processing ecosystem with transaction-based pricing (2.59% + $0.49 per transaction). If you only need SCIM for user management, you're paying processing fees on every transaction to access identity features.

Stitchflow Insight

We estimate ~60% of Braintree Enterprise features are payment processing capabilities that teams seeking basic SCIM automation don't need. The irreversible nature of SCIM onboarding makes this an expensive, high-commitment solution for simple user provisioning.

What IT admins are saying

Community sentiment on PayPal's SCIM implementation centers around its irreversible nature and complex setup requirements. Common complaints:

  • The one-way SCIM onboarding that cannot be reverted once enabled
  • Complex pre-requirements including sandbox setup and SSO conversion
  • Limited group management capabilities (can only update, not create/delete groups)
  • Loss of manual user management capabilities in the control panel after SCIM activation

SCIM onboarding is one-way - cannot revert to non-SCIM once enabled

PayPal Developer Documentation

Cannot edit/create/delete SSO users in control panel after SCIM

Braintree SCIM FAQ

The recurring theme

PayPal's SCIM feels more like a permanent commitment than a flexible automation tool, with significant operational trade-offs that require careful planning before implementation.

The decision

Your SituationRecommendation
Need SCIM but hesitant about one-way commitmentUse Stitchflow: maintain flexibility without irreversible changes
Enterprise Braintree account with SCIM includedUse native SCIM: you're already paying for it
Want group creation/deletion capabilitiesUse Stitchflow: native SCIM can only update existing groups
Complex onboarding requirements concern youUse Stitchflow: skip sandbox setup and SSO user conversion
Small payments team with stable access needsManual may work: but monitor for compliance gaps

The bottom line

PayPal's Braintree SCIM comes with significant limitations—it's irreversible once enabled, requires complex onboarding, and can't create or delete groups. For organizations wanting payment platform automation without the commitment and restrictions, Stitchflow provides full provisioning control at predictable flat-rate pricing.

Make PayPal workflows AI-native

PayPal gates SCIM behind Enterprise (Braintree). We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise (Braintree) upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • SCIM onboarding is one-way - cannot revert
  • Cannot edit/create/delete SSO users in control panel after SCIM
  • Cannot create or delete groups via SCIM - only update
  • Sandbox merchant required before production SCIM
  • Must convert non-SSO users to SSO before SCIM onboarding

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → PayPal → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Braintree SCIM app in Okta OIN. Supports automated user provisioning, de-provisioning, and role/merchant account access management. Email used as unique identifier.

PayPal gates SCIM behind Enterprise (Braintree). Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → PayPal → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Braintree SCIM supports Microsoft Entra. Supports user deletion (unlike Okta). Group sync requires exact name matching with 'BT SANDBOX' or 'BT PRODUCTION' prefixes.

PayPal gates SCIM behind Enterprise (Braintree). Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
PayPal

PayPal gates SCIM behind Enterprise (Braintree) plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
PayPal logo
PayPal
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Adyen logo

Adyen

No SCIM

Payments / Fintech

ProvisioningNot Supported
Manual Cost$11,754/yr

Adyen offers SCIM 2.0 provisioning, but only through Okta's integration—there's no native SCIM endpoint. This creates a significant vendor lock-in scenario where your provisioning capabilities are entirely dependent on using Okta as your identity provider. Teams using Azure Entra, Google Workspace, or OneLogin are left with manual user management despite Adyen supporting SAML SSO with these platforms. The Okta integration itself requires maintaining a company account (not just a merchant account) and keeping at least one non-SSO admin for troubleshooting, adding operational complexity. For payment platforms handling sensitive financial data, this provisioning gap creates serious compliance risks. Your finance team, payment operations staff, and developers need timely access to process transactions and manage risk controls, but without automated provisioning, you're stuck with manual onboarding that can delay critical payment operations. The requirement to maintain non-SSO admin accounts also creates a security backdoor that compliance auditors will flag.

View full guide
Box logo

Box

SCIM Tax
SCIM Tax+200%
Manual Cost$5,892/yr

Box offers automated user provisioning through IdP integrations with Okta and Microsoft Entra ID, but this is not SCIM-compliant provisioning. Instead, Box uses a proprietary API that violates core SCIM standards—the userName attribute isn't required, error codes are non-standard, and attribute mapping is Box-specific. This creates a misleading situation where Box appears to support modern provisioning but actually locks you into IdP-specific integrations. Provisioning requires Business plans ($15/user/month) or higher, and only works with major IdP vendors. This proprietary approach creates significant challenges for IT teams managing multi-vendor environments or planning IdP migrations. Since Box's provisioning relies on custom integrations rather than standardized SCIM, switching identity providers means rebuilding provisioning workflows from scratch. Organizations using less common IdPs, those requiring SCIM compliance for audit purposes, or teams running mixed identity environments are left with manual user management—creating security gaps and administrative overhead that scales poorly as teams grow.

View full guide
Freshdesk logo

Freshdesk

SCIM Tax

Customer Support

SCIM Tax+427%
Manual Cost$7,190/yr

Freshdesk supports SCIM provisioning, but only on the Enterprise plan at $79/agent/month. This creates a significant cost barrier for smaller support teams who need automated provisioning but can't justify nearly $1,000/year per agent just to access SCIM. The provisioning system distinguishes between agents (who handle tickets) and contacts (end users), requiring careful configuration to ensure the right people get the right access levels. Role mapping can also require additional setup work to properly assign support agents to appropriate permission groups. For customer support teams, this pricing gate is particularly problematic because support agents often have high turnover rates and need immediate access to handle incoming tickets. Manual provisioning delays mean either security gaps (shared accounts) or customer service delays (agents waiting for access). The Enterprise plan requirement forces smaller teams to either accept manual processes or overpay for features they may not need.

View full guide