Summary and recommendation
SAP Commerce supports SCIM provisioning, but only through SAP's Cloud Identity Services (IPS) acting as an intermediary proxy. This means you can't provision directly from your IdP to SAP Commerce—instead, your identity provider provisions to SAP IPS, which then provisions to Commerce. This architecture requires Enterprise-level licensing ($150,000-$500,000+/year) and adds complexity with multiple integration points across the SAP ecosystem.
The proxy requirement creates operational overhead and potential failure points. IT teams must manage SAP IPS configurations, troubleshoot multi-hop provisioning flows, and maintain expertise in SAP's identity architecture alongside their primary IdP. When provisioning fails, determining whether the issue is between your IdP and SAP IPS, or between SAP IPS and Commerce, becomes a time-consuming diagnostic exercise.
The strategic alternative
SAP Commerce gates SCIM behind Enterprise. That can unlock provisioning, but it still does not complete the offboarding, access review, or license workflow across the rest of your stack. Stitchflow builds and maintains the IT workflows your team still runs manually, across every app, including the ones without APIs.
Quick SCIM facts
| SCIM available? | Yes |
| SCIM tier required | Enterprise |
| SSO required first? | Yes |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Official docs |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | ✓ | ✓ | OIN app with full provisioning |
| Microsoft Entra ID | ✓ | ✓ | Gallery app with SCIM |
| Google Workspace | ✓ | JIT only | SAML SSO with just-in-time provisioning |
| OneLogin | ✓ | ✓ | Supported |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages SAP Commerce accounts manually. Here's what that costs:
The SAP Commerce pricing problem
SAP Commerce gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Composable | Contact SAP | ||
| Premier | Contact SAP | ||
| Enterprise | $150,000-$500,000+/year |
Plan Structure
| Plan | Price | SCIM |
|---|---|---|
| Composable | Contact SAP | ✓ (via SAP IPS) |
| Premier | Contact SAP | ✓ (via SAP IPS) |
| Enterprise | $150,000-$500,000+/year | ✓ (via SAP IPS) |
All SCIM provisioning requires SAP Cloud Identity Services as a mandatory proxy, regardless of your SAP Commerce pricing tier.
What this means in practice
The SAP IPS requirement creates a multi-hop provisioning chain:
Your IdP → SAP Cloud Identity Services → SAP Commerce
This architecture introduces several operational challenges:
Additional constraints
Summary of challenges
- SAP Commerce supports SCIM but only at Enterprise tier ($150,000-$500,000+/year)
- Google Workspace users get JIT provisioning only, not full SCIM
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What the upgrade actually includes
SAP Commerce doesn't sell SCIM directly. It's bundled with Enterprise licensing and requires SAP Cloud Identity Services as an intermediary:
The real cost isn't just SAP Commerce Enterprise ($150K-$500K+/year) - you also need SAP Cloud Identity Services licensing. SAP deliberately routes all identity management through their central platform, creating vendor lock-in across their entire ecosystem.
Stitchflow Insight
If you just need user provisioning for SAP Commerce, you're paying enterprise platform pricing for what should be basic identity automation. We estimate ~80% of the SAP enterprise bundle is irrelevant for teams that simply want to sync users from their existing IdP.
What IT admins are saying
Community sentiment on SAP Commerce's SCIM implementation reveals frustration with complexity and cost barriers. Common complaints:
- Being locked into the entire SAP ecosystem for identity management
- Requiring SAP Cloud Identity Services as an expensive intermediary layer
- Enterprise-only pricing that starts at $150K+ annually just for basic provisioning
- Complex multi-hop architecture that creates additional failure points
SAP forces you through their Cloud Identity Services for everything. It's like paying a toll booth to get to your own application.
The SAP Commerce licensing is insane. You're looking at $200K minimum just to get user provisioning working, when other platforms include it in their base plans.
The recurring theme
SAP's approach treats SCIM as part of a broader enterprise lock-in strategy, forcing organizations to adopt multiple expensive SAP services just to automate basic user management.
The decision
| Your Situation | Recommendation |
|---|---|
| Need SCIM but not the $150K+ Enterprise tier | Use Stitchflow: get provisioning without the massive platform upgrade |
| Already on Enterprise with SAP IPS | Use native SCIM: you're paying for the full SAP ecosystem |
| Want direct IdP integration (bypass SAP IPS) | Use Stitchflow: avoid the SAP proxy complexity |
| Small e-commerce team, low user turnover | Manual may work: but watch for scaling issues |
| Evaluating SAP Commerce vs alternatives | Factor SCIM costs: Stitchflow works with any e-commerce platform |
The bottom line
SAP Commerce gates SCIM behind Enterprise. The upgrade may unlock provisioning, but the workflow still has to complete across the rest of your stack.
Close the SAP Commerce workflow gap
SAP Commerce gates SCIM behind Enterprise, but the bigger issue is the workflow around it. Stitchflow builds and maintains the offboarding, access review, or license workflow underneath.
Technical specifications
SCIM Version
2.0
Supported Operations
Create, Update, Deactivate, Groups
Supported Attributes
Not specifiedPlan requirement
Enterprise
Prerequisites
SSO must be configured first
Key limitations
- SAP recommends using SAP Cloud Identity Services
- Common SAP SCIM schema across apps
- Multiple SAP integration points
- Complex enterprise licensing
Configuration for Entra ID
Integration type
Microsoft Entra Gallery app with SCIM provisioning
Prerequisite
SSO must be configured before enabling SCIM.
Where to enable
Required credentials
Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).
Configuration steps
Set Provisioning Mode = Automatic, configure SCIM connection.
Provisioning trigger
Entra provisions based on user/group assignments to the enterprise app.
Sync behavior
Entra provisioning runs on a scheduled cycle (typically every 40 minutes).
Microsoft Entra provisions to SAP Cloud Identity Services, which then provisions to SAP Commerce. SCIM 2.0 connector released Sept 2025. Requires SAP IPS as proxy.
SAP Commerce gates SCIM behind Enterprise. The upgrade may unlock provisioning, but the workflow still has to complete across the rest of your stack.
Close the workflow gap in
SAP Commerce
SAP Commerce gates SCIM behind Enterprise plan. That can unlock provisioning, but it still does not complete the offboarding, access review, or license workflow across your stack.
Start with the free gap diagnostic


