Stitchflow
RudderStack logo

RudderStack SCIM guide

Native SCIM

How to automate RudderStack user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

RudderStack supports SCIM 2.0 for automated user provisioning, but only on Enterprise plans with custom pricing (starting well above their $750/month Starter tier). While the SCIM implementation covers core functionality—creating users, updating attributes, and deactivating accounts—it requires contacting their team to enable and has notable restrictions: users can only be deactivated (not deleted), email addresses can't be updated via SCIM, and SSO is limited to SP-initiated flows only.

For customer data platform teams on Starter or Growth plans, this creates a significant provisioning gap. Manual user management becomes unwieldy as data engineering and marketing teams scale, especially when onboarding contractors or managing cross-functional access to sensitive customer data pipelines. SSO with JIT provisioning helps with authentication, but leaves IT teams manually managing user lifecycle events—a compliance risk when handling customer PII across data warehouse connections.

The strategic alternative

RudderStack gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages RudderStack accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The RudderStack pricing problem

RudderStack gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
StarterFrom $750/month
GrowthCustom pricing
EnterpriseCustom pricing

Note: SCIM includes user creation, attribute updates, and deactivation (deletion not supported). Email addresses cannot be updated via SCIM after initial provisioning.

What this means in practice

RudderStack's custom pricing model makes it difficult to calculate exact upgrade costs, but the jump from Starter ($750/month minimum) to Enterprise represents a significant increase. Based on typical customer data platform pricing:

Small teams (10-20 users)
Enterprise pricing often starts at $2,000-3,000/month, representing a 3-4x increase from Starter
Mid-size teams (50+ users)
Enterprise can reach $5,000-10,000/month depending on data volume and feature requirements
Large teams (100+ users)
Pricing scales with both user count and data processing volume

The lack of transparent pricing means teams must engage in lengthy sales processes just to understand SCIM costs.

Additional constraints

Manual enablement required
SCIM must be enabled by RudderStack's team - it's not self-service even on Enterprise plans.
SP-initiated SSO only
No support for IdP-initiated authentication, limiting user experience flexibility.
Limited user management
Cannot delete users (only deactivate) and cannot update email addresses post-creation.
Sales-gated access
Custom pricing requires enterprise sales engagement, adding weeks to implementation timelines.

Summary of challenges

  • RudderStack supports SCIM but only at Enterprise tier (Custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

RudderStack doesn't sell SCIM à la carte. It's bundled with Enterprise-tier features:

SCIM automated provisioning (requires team enablement)
SAML single sign-on (SSO)
Advanced security controls
Premium customer support
Enhanced data governance features
Custom data retention policies
Advanced workspace management
Dedicated customer success manager

The bigger issue: RudderStack requires manual intervention from their team to enable SCIM, even after you upgrade. This creates deployment friction and ongoing dependency on their support process.

Stitchflow Insight

If you need enterprise-grade data infrastructure controls anyway, the upgrade may make sense. If you just want automated user provisioning for your customer data platform, you're paying for a comprehensive enterprise bundle you won't fully use. We estimate ~80% of Enterprise features are irrelevant for teams that only need SCIM.

What IT admins are saying

Community sentiment on RudderStack's SCIM implementation is mixed, with frustration centered on the manual enablement process and Enterprise tier requirements. Common complaints:

  • Having to contact the RudderStack team to enable SCIM after purchasing Enterprise
  • Cannot update user email addresses through SCIM provisioning
  • SP-initiated SSO only - no IdP-initiated login support
  • SCIM deactivates users but cannot delete them entirely

Why do we have to contact support to enable a feature we're already paying for? Just give us a toggle in the admin panel.

Reddit r/dataengineering

The email update limitation is annoying when people change names or departments. We have to manually update those in RudderStack.

Customer Data Platform Slack community

The recurring theme

RudderStack has solid SCIM functionality but creates unnecessary friction with manual enablement requirements and missing standard features like email updates.

The decision

Your SituationRecommendation
On Starter plan, need SCIMUse Stitchflow: avoid the Enterprise upgrade and custom pricing
Already on Enterprise tierUse native SCIM: you're paying for it and it's fully featured
Need Enterprise features beyond SCIMEvaluate Enterprise upgrade: SCIM comes bundled
Small team, willing to contact support for setupNative SCIM may work: if you can handle the manual enablement process
Want immediate deployment without vendor coordinationUse Stitchflow: no need to contact RudderStack's team for enablement

The bottom line

RudderStack's SCIM is locked behind Enterprise pricing and requires contacting their team for enablement, creating barriers for teams on lower tiers. For organizations that need automated provisioning without the Enterprise commitment or support dependency, Stitchflow delivers immediate deployment at predictable pricing.

Make RudderStack workflows AI-native

RudderStack gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • Contact team to enable SCIM
  • Cannot update email via SCIM
  • SP-initiated SSO only
  • Does not support user deletion (deactivates only)
  • Does not support IdP-initiated authentication

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → RudderStack → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Full SCIM provisioning via OIN app. Push users, update attributes, deactivate/reactivate users. Cannot update email via SCIM. Contact team to enable SCIM. SP-initiated SSO only.

RudderStack gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → RudderStack → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Microsoft Azure Entra ID SSO and SCIM documented. Contact team to enable SCIM. Does not support IdP-initiated authentication. Does not support removing users (deactivates only).

RudderStack gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
RudderStack

RudderStack gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
RudderStack logo
RudderStack
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Absorb LMS logo

Absorb LMS

SCIM Tax

Learning Management System (LMS)

SCIM StatusIncluded
Manual Cost$11,754/yr

Absorb LMS supports native SCIM provisioning, but only on Enterprise plans with SSO as a required paid add-on. Even with SCIM enabled, the implementation has critical limitations: SAML provisioning only creates accounts on first login and never updates existing users, and full user provisioning requires the specific "Absorb 5 - New Learner Experience" version. For organizations managing compliance training across hundreds or thousands of learners, these gaps create ongoing manual work. The SSO-as-add-on model means you're paying extra fees on top of already custom Enterprise pricing ($6-12/user/month base, but varies significantly). For learning management systems handling external partners, contractors, and employees across different access levels, the inability to update existing user attributes through SAML provisioning forces IT teams into manual account management—exactly what automated provisioning should eliminate.

View full guide
Airbase logo

Airbase

SCIM Tax

Spend Management / Corporate Cards

SCIM StatusIncluded
Manual Cost$11,754/yr

Airbase supports SCIM provisioning, but only on Enterprise plans starting around $8,500/year. While SCIM works with all major identity providers (Okta, Entra ID, Google Workspace), the Enterprise requirement creates a significant barrier for smaller finance teams who need automated provisioning for spend management but can't justify enterprise-level spend management software costs. This creates a particular challenge in finance applications where rapid provisioning and deprovisioning is critical for corporate card access and financial controls. Manual user management means delayed access for new employees needing corporate cards, and more critically, potential security gaps when departing employees retain access to spend management systems. For finance teams handling sensitive financial data and corporate spending, these delays and oversights create both operational friction and compliance risks.

View full guide