Summary and recommendation
TriNet, the PEO (Professional Employer Organization) platform, offers SCIM provisioning but with a critical architectural limitation: it's designed as an HR source system that provisions users to other applications, not to be provisioned from your identity provider. While TriNet supports SCIM via OneLogin/Aquera connectors and offers SAML SSO integration, this setup creates an identity management conflict. Your IdP (Okta, Entra ID) expects to be the authoritative source for user identities, but TriNet functions as its own HR system of record.
This architectural mismatch creates operational complexity for IT teams. You're forced to either maintain dual identity sources or implement custom synchronization logic between your IdP and TriNet's HR data. The OneLogin/Aquera connector dependency also limits your IdP flexibility—you can't simply use standard SCIM endpoints with any identity provider. For organizations trying to centralize identity management, TriNet's role as an HR source system rather than a downstream application disrupts clean provisioning workflows.
The strategic alternative
Stitchflow provides SCIM-level provisioning through resilient browser automation for TriNet that resolves these architectural conflicts. We handle the complex synchronization logic between your authoritative IdP and TriNet's HR system, maintaining consistency across both platforms. Works with any IdP (Okta, Entra, Google Workspace, OneLogin) regardless of TriNet's connector limitations. Flat pricing under $5K/year, regardless of employee count.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | Yes |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Official docs |
Supported identity providers
| IdP | SSO | Provisioning | Notes |
|---|---|---|---|
| Okta | ✓ | Via API | Okta OIN integration with provisioning. Group import and schema discovery. Also available: TriNet by Aquera HR-as-a-Master connector. |
| Microsoft Entra ID | ✓ | Via API | TriNet to Entra ID sync available via Aquera connector. Automatic joiner/mover/leaver sync. Third-party solution. |
| Google Workspace | ✓ | ❌ | SSO only, no provisioning |
| OneLogin | ✓ | ❌ | SSO only |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages TriNet accounts manually. Here's what that costs:
The TriNet pricing problem
TriNet gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Standard | From ~$80/employee/mo (PEPM) |
Pricing structure
| Plan | Pricing | SCIM | SSO |
|---|---|---|---|
| Standard | From ~$80/employee/mo (PEPM) | ❌ Via connectors only | ✓ SAML 2.0 |
Market context
What this means in practice
For most organizations using TriNet
If you do need SCIM provisioning into TriNet
Additional constraints
Summary of challenges
- TriNet does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What TriNet actually offers for identity
SAML SSO (Standard Plan)
TriNet supports SAML 2.0 integration with major identity providers:
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Supported IdPs | Okta, OneLogin, custom SAML providers |
| JIT Provisioning | ✓ Yes |
| SP-initiated | ✓ Yes |
| IdP-initiated | ✓ Yes |
SCIM Provisioning (Via Third-Party Connectors)
TriNet doesn't offer native SCIM but supports provisioning through connector platforms:
| Feature | OneLogin Connector | Aquera/Okta Connector |
|---|---|---|
| Create users | ✓ Yes | ✓ Yes |
| Update attributes | ✓ Yes | ✓ Yes |
| Deactivate users | ✓ Yes | ✓ Yes |
| Group sync | ✓ Yes | ✓ Yes |
| Schema discovery | Limited | ✓ Yes |
The real limitation: These connectors only work with specific IdPs. You're locked into OneLogin or using Aquera's platform for Okta/Entra ID integration. No direct SCIM API means no support for Google Workspace, direct Entra ID, or other identity providers.
HR-as-a-Source Workflow
Important context: TriNet is typically the identity source system, not the target. Most organizations use TriNet to provision users into other applications (Slack, Google Workspace, etc.) rather than provisioning users into TriNet itself.
The connector solutions are designed for:
What IT admins are saying
Community sentiment on TriNet's provisioning reveals typical PEO platform challenges:
- SCIM provisioning only works through specific connectors (OneLogin/Aquera), limiting IdP flexibility
- As an HR source system, TriNet often needs to provision other apps rather than being provisioned itself
- High per-employee pricing (~$80/month minimum) makes any additional integration costs feel expensive
- 5-employee minimum creates barriers for smaller organizations
Price is biggest complaint from users
Higher end pricing compared to market
The recurring theme
TriNet functions more as an identity source than a target application, but when you do need inbound provisioning, you're locked into specific connector solutions that may not match your existing IdP setup.
The decision
| Your Situation | Recommendation |
|---|---|
| Using OneLogin as your IdP | Native connector may work for basic provisioning |
| Using Okta, Entra, or Google Workspace | Use Stitchflow: native options are limited or complex |
| TriNet as HR source system provisioning other apps | Use Stitchflow: streamline outbound provisioning workflows |
| Enterprise with 100+ employees on TriNet | Use Stitchflow: automation essential at scale |
| Compliance-heavy industry requiring audit trails | Use Stitchflow: comprehensive logging and SOC 2 compliance |
The bottom line
TriNet offers SCIM provisioning primarily through OneLogin/Aquera connectors, leaving other IdP users with limited automation options. As an HR platform that often serves as the identity source for other applications, TriNet customers need robust provisioning capabilities. Stitchflow provides universal IdP support and managed automation for under $5K/year—essential for organizations relying on TriNet as their HR foundation.
Automate TriNet without third-party complexity
Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for TriNet at <$5K/year, flat, regardless of team size.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Not specifiedPlan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- SCIM via OneLogin/Aquera connectors (not all IdPs)
- HR source system - typically provisions other apps
- 5 employee minimum
- Not available for hazardous industries
Configuration for Okta
Integration type
Okta Integration Network (OIN) app
Prerequisite
SSO must be configured before enabling SCIM.
Where to enable
Okta OIN integration with provisioning. Group import and schema discovery. Also available: TriNet by Aquera HR-as-a-Master connector.
Use Stitchflow for automated provisioning.
Unlock SCIM for
TriNet
TriNet doesn't offer SCIM. Get an enterprise-grade SCIM endpoint in your IdP, even without native support.
See how it works


