Stitchflow
Spacelift logo

Spacelift SCIM guide

Connector Only

How to automate Spacelift user provisioning, and what it actually costs

Native SCIM not available

Summary and recommendation

Spacelift, the infrastructure-as-code management platform, does not support SCIM provisioning on any plan despite user requests for this functionality. While Spacelift offers SAML 2.0 and OIDC SSO integration with identity providers like Okta and Azure AD, SSO is only available on Enterprise plans and requires custom pricing. More critically, SSO only handles authentication - IT teams must still manually create, update, and deactivate user accounts within Spacelift. IdP group memberships can be referenced in login policies, but users aren't automatically provisioned based on those groups.

This creates a significant operational burden for IT teams managing infrastructure access. Unlike typical SaaS applications, Spacelift controls access to critical infrastructure resources and deployment pipelines. Manual user management means delayed onboarding for new developers, potential security gaps when team members change roles, and compliance risks when departing employees aren't promptly deprovisioned from infrastructure management tools. The lack of automated group-based provisioning is particularly problematic given Spacelift's role-based access model for different infrastructure environments and deployment workflows.

The strategic alternative

Spacelift has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaNo Okta OIN app. Supports SSO via SAML 2.0 or OIDC with Okta. SSO is Enterprise plan only.
Microsoft Entra IDSupports Azure AD via SAML or OIDC for SSO. No SCIM provisioning available.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Spacelift accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Spacelift pricing problem

Spacelift gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Pro$399/mo (up to 10 users)
BusinessCustom pricing
EnterpriseCustom pricing

Pricing structure

PlanPriceSSOSCIM
Pro$399/mo (up to 10 users)
BusinessCustom pricing
EnterpriseCustom pricing

What this means in practice

Without SCIM, Spacelift user management creates operational overhead:

Manual provisioning
Each new team member requires manual account creation in Spacelift
Deprovisioning gaps
When employees leave, IT must remember to manually remove Spacelift access
No group sync
IdP group memberships can be referenced in login policies, but users still need manual creation
JIT limitations
SSO JIT only works after manual account setup, defeating the automation purpose

Additional constraints

Enterprise plan requirement
SSO (SAML/OIDC) is only available on custom Enterprise pricing, not the $399/mo Pro plan
No Okta OIN app
Spacelift isn't in the Okta Integration Network, requiring manual SAML/OIDC configuration
Limited Azure AD documentation
No specific Microsoft Entra integration guide available
Compliance risk
Manual processes increase the likelihood of orphaned accounts and access policy violations

Summary of challenges

  • Spacelift does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Spacelift actually offers for identity

SSO (Enterprise plan required)

Spacelift provides federated authentication through standard protocols:

SettingDetails
ProtocolSAML 2.0 or OIDC
Supported IdPsOkta, Entra ID, Google Workspace, any SAML/OIDC provider
Plan requirementEnterprise tier only
User managementManual or JIT provisioning

Critical gap: While SSO handles authentication, there's no automated user lifecycle management. Users must be manually added to Spacelift before they can access resources.

What's missing entirely

Spacelift has no SCIM endpoint or automated provisioning capabilities:

FeatureSupported?
Create users❌ Manual only
Update user attributes❌ Manual only
Deactivate users❌ Manual only
Group synchronization❌ No
Role assignment automation❌ Manual only

Real-world impact: IT teams manage Spacelift access through manual processes. When employees join, change roles, or leave, someone must remember to update Spacelift permissions separately from your IdP.

IdP Integration Status

Neither Okta nor Entra ID offer native Spacelift provisioning apps:

Okta
No Integration Network listing for Spacelift
Entra ID
No enterprise gallery application with provisioning
Google Workspace
No marketplace app with automated provisioning

This leaves teams with SSO for authentication but manual user management for everything else.

What IT admins are saying

Community sentiment on Spacelift's provisioning reveals frustration with manual user management:

  • Users must be manually added to Spacelift workspaces even after SSO is configured
  • No automated deprovisioning when employees leave the organization
  • SSO requires expensive Enterprise plan, blocking automation for smaller teams
  • IdP group memberships can inform login policies but don't trigger user creation

We've been asking for SCIM support for a while now. Having to manually manage users in Spacelift when we have everything automated through Okta is a pain point.

IT Admin, Reddit

SSO works great but you still have to go into Spacelift and manually add each user to the right spaces. Defeats the purpose of having centralized identity management.

Infrastructure Engineer, GitHub Issues

The recurring theme

Spacelift forces IT teams to maintain a separate user management process outside their identity provider, creating operational overhead and security gaps when user access isn't automatically revoked.

The decision

Your SituationRecommendation
Small infrastructure team (<10 users)Manual management acceptable for now
Growing DevOps team (10-50 users)Use Stitchflow: automation prevents bottlenecks
Enterprise with compliance requirementsUse Stitchflow: automated provisioning essential for audit trails
Multi-team infrastructure accessUse Stitchflow: centralized user management critical
High developer turnover environmentUse Stitchflow: instant deprovisioning reduces security risk

The bottom line

Spacelift excels at infrastructure automation but completely lacks user provisioning capabilities—no SCIM support despite user demand, and even SSO requires their Enterprise plan. For teams managing infrastructure access at scale, Stitchflow delivers the automated user lifecycle management that Spacelift should have built natively.

Make Spacelift workflows AI-native

Spacelift has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No SCIM support - feature requested by users but not implementedUsers must be manually added/removed or rely on SSO JITSSO (SAML/OIDC) requires Enterprise planIdP group memberships can be used in login policies but not auto-provisioned

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No SCIM support - feature requested by users but not implemented
  • Users must be manually added/removed or rely on SSO JIT
  • SSO (SAML/OIDC) requires Enterprise plan
  • IdP group memberships can be used in login policies but not auto-provisioned

Documentation not available.

Unlock SCIM for
Spacelift

Spacelift has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
Spacelift logo
Spacelift
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide