Stitchflow
Shopify logo

Shopify SCIM guide

Native SCIM

How to automate Shopify user provisioning, and what it actually costs

Native SCIM requires Plus plan

Summary and recommendation

Shopify supports native SCIM 2.0 provisioning, but only on Shopify Plus—their enterprise tier that starts at $2,300/month (minimum $27,600/year). For merchants on Standard, Shopify, or Advanced plans ($29-$299/month), there's no automated provisioning whatsoever. This creates a massive pricing gap: you either pay $299/month with manual user management, or jump to $2,300/month for automation—an 8x increase that puts SCIM out of reach for most merchants.

For e-commerce businesses, especially during peak seasons, this limitation creates real operational pain. Retailers need to rapidly onboard seasonal staff, manage multi-location access, and ensure former employees immediately lose access to customer data and payment systems. Without SCIM, IT teams manually provision every holiday temp worker and customer service rep—a process that's both time-intensive and creates compliance risks in an industry handling sensitive payment data.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation for Shopify without requiring the Plus upgrade. Works with any Shopify plan and any identity provider. Flat pricing under $5K/year, regardless of team size—a fraction of the Plus licensing premium.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Shopify accounts manually. Here's what that costs:

Source: Stitchflow customers using Shopify, normalized to 500 employees:
Orphaned accounts (ex-employees with access)2
Unused licenses2
IT hours spent on manual management/year101 hours
Unused license cost/year$8,656
IT labor cost/year$6,043
Cost of compliance misses/year$558
Total annual financial impact$15,257

The Shopify pricing problem

Shopify gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
Basic$29/mo
Shopify$79/mo
Advanced$299/mo
Plus$2,300-$2,500/mo

Note: Plus pricing is actually variable based on revenue (0.3-0.4% of monthly sales) with a minimum of $2,300/mo and cap at $40,000/mo. The tier shown reflects the minimum commitment.

What this means in practice

For merchants requiring SCIM access, the upgrade costs are substantial:

Current PlanAnnual Upgrade to PlusCost Increase
Basic ($29/mo)+$27,252/year970% increase
Shopify ($79/mo)+$26,772/year860% increase
Advanced ($299/mo)+$24,012/year670% increase

This represents one of the steepest SCIM upgrade penalties in enterprise software.

Additional constraints

SAML prerequisite
Domain verification and SAML SSO must be configured before SCIM token generation, adding setup complexity.
Domain restriction
SCIM only manages users associated with your verified domain, limiting flexibility for contractors or partners.
Feature bundling
Plus includes features many merchants don't need (10 expansion stores, unlimited staff) but pay for anyway.
Revenue-based pricing
High-volume merchants face even steeper costs as Plus fees scale with sales volume.

Summary of challenges

  • Shopify supports SCIM but only at Enterprise tier ($2,300-$2,500/mo (Plus - 3-year vs 1-year term))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Shopify doesn't sell SCIM à la carte. It's bundled with Shopify Plus features:

SCIM automated provisioning
SAML single sign-on (SSO)
10 expansion stores included
Unlimited staff accounts
Advanced checkout customization
Script Editor for custom functionality
Flow automation builder
Enhanced APIs and webhooks
Dedicated merchant success manager
Priority support

The real issue: you're paying $27,600+ annually for features like checkout customization and script editing when you just want automated user provisioning. Plus requires domain verification and SAML setup before SCIM works—a multi-step process that smaller merchants find unnecessarily complex.

Stitchflow Insight

The Plus upgrade delivers powerful e-commerce features, but most are irrelevant if you just need identity management. We estimate ~80% of Plus features focus on advanced storefront customization, multi-store management, and enterprise sales tools that typical IT teams never touch.

What IT admins are saying

Community sentiment on Shopify's SCIM implementation centers on pricing barriers and complexity. Common complaints:

  • Plus pricing ($2,300-$2,500/mo) puts SCIM completely out of reach for smaller merchants
  • Multi-step setup requiring domain verification and SAML configuration before SCIM
  • Complete lack of SSO/SCIM on standard Shopify plans despite managing sensitive customer data
  • Revenue-based pricing model that penalizes successful businesses with higher identity costs

Plus pricing puts SCIM out of reach for smaller merchants who still need to manage seasonal staff and protect customer data.

Reddit r/shopify

You have to verify your domain AND set up SAML before you can even generate a SCIM token - it's unnecessarily complex for what should be basic identity management.

Shopify Community Forums

The recurring theme

Shopify treats identity management as a luxury enterprise feature rather than a security fundamental, forcing smaller e-commerce businesses to manage user access manually despite handling sensitive payment and customer data.

The decision

Your SituationRecommendation
On Basic/Shopify/Advanced, need SCIMUse Stitchflow: avoid the $2,300+/month Plus upgrade
On Plus but struggling with SAML prerequisite complexityUse Stitchflow: bypass the multi-step domain verification dance
Already on Plus with SAML configuredUse native SCIM: you're paying $27K+/year for it
Need Plus features for multi-store managementEvaluate Plus: SCIM comes bundled with expansion stores
Small shop with low seasonal staff turnoverManual may work: but monitor for holiday hiring gaps

The bottom line

Shopify's SCIM barrier is brutal—a $2,300+/month tier jump that puts provisioning automation out of reach for most merchants. For e-commerce teams that need rapid seasonal onboarding without the Plus premium, Stitchflow delivers enterprise-grade provisioning at under $5K/year.

Automate Shopify without the tier upgrade

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for Shopify at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • SCIM only on Shopify Plus (enterprise tier)
  • Domain must be verified before SCIM setup
  • SAML must be configured before SCIM token generation
  • Only manages users associated with verified domain
  • Okta Group Push not supported

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Shopify → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Full SCIM provisioning with user lifecycle management. Supports Group Linking, Schema Discovery, Attribute Writeback. Role provisioning available.

Native SCIM is available on Enterprise. Use Stitchflow if you need provisioning without the tier upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Shopify → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Microsoft Entra provisioning service supports automatic user/group provisioning. Base URL: https://shopifyscim.com/scim/v2/

Native SCIM is available on Enterprise. Use Stitchflow if you need provisioning without the tier upgrade.

Unlock SCIM for
Shopify

Shopify gates automation behind Plus plan. Stitchflow delivers the same SCIM outcomes for a flat fee.

See how it works
Admin Console
Directory
Applications
Shopify logo
Shopify
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Zendesk logo

Zendesk

SCIM Tax

Customer Support

SCIM StatusIncluded
Manual Cost$15,353/yr

Zendesk does not offer native SCIM provisioning on any plan, despite being a major enterprise customer support platform. While Professional ($115/agent/month) and Enterprise ($169/agent/month) plans support automated provisioning through Okta and Azure AD via API connectors, this creates vendor lock-in and leaves organizations using Google Workspace or OneLogin with no automated provisioning options. For support teams that experience high turnover and need rapid scaling during peak seasons, this forces IT into manual account management that creates onboarding delays and offboarding security gaps. The lack of universal SCIM support becomes particularly problematic during critical periods when customer service quality depends on rapid agent onboarding. Without standardized provisioning, IT teams can't implement consistent user lifecycle management across all applications, creating compliance risks and operational bottlenecks. When support agents leave or need role changes, the manual process increases the window of inappropriate access—a security concern for platforms handling customer data.

View full guide
Gong logo

Gong

SCIM Tax

Revenue Intelligence / Sales

SCIM StatusIncluded
Manual Cost$13,829/yr

Gong supports SCIM (the protocol that lets your identity provider automatically create, update, and remove user accounts), but only on Enterprise plans with custom pricing starting around $1,500/user/year. The pricing structure is particularly complex: annual platform fees ($5K-$50K), per-user licenses ($120-250/month), plus mandatory implementation costs ($15K-$65K). For a 200-user deployment, you're looking at $247K+ annually after typical discounts. Even with SCIM enabled, Gong's default provisioning creates "ghost users" with no seats or capabilities. IT admins must manually configure team assignments and permissions for each provisioned user to actually access Gong's features. This defeats the automation purpose and creates a security gap where users appear provisioned but can't perform their sales functions. For revenue teams handling sensitive customer call data, this provisioning gap is particularly problematic. Sales reps need immediate access to recorded conversations and insights, but Gong's SCIM limitations mean manual intervention for every new hire or role change.

View full guide
Monday.com logo

Monday.com

SCIM Tax
SCIM StatusIncluded
Manual Cost$13,597/yr

Monday.com supports SCIM 2.0 provisioning, but only on Enterprise plans—which cost approximately $480 per user annually. For a 100-person team, that's $48,000/year just for the base licensing, before factoring in the premium features you may not need. The pricing jump from Pro (suitable for up to 40 users) to Enterprise represents a significant cost barrier for mid-sized teams that simply want automated user provisioning. This creates a substantial gap for growing organizations. While monday.com offers JIT (just-in-time) provisioning through SAML SSO, this only creates accounts when users first log in—it doesn't handle automated deprovisioning when employees leave or role changes that require access adjustments. For compliance-conscious IT teams, manual user management at scale becomes both a security risk and an operational burden.

View full guide