Summary and recommendation
Whimsical supports SCIM 2.0 provisioning, but only on Organization/Enterprise plans ($18-20/editor/month or $150/editor/year). The implementation has several operational limitations: SCIM requires SAML SSO to be configured first and disabling SAML breaks SCIM entirely. Role management must happen exclusively from your IdP, removing local admin control. Provisioned users won't appear in your Whimsical workspace until they actually log in via SAML, creating visibility gaps for IT teams tracking account status.
For teams currently on Pro ($10/user/month), enabling SCIM means upgrading to Organization—an 80-100% price increase. For a 50-person team, that's $6,000-7,500/year in additional licensing costs just to unlock automated provisioning for a visual collaboration tool that may only be used by specific departments or project teams.
The strategic alternative
Whimsical gates SCIM behind Organization. Skip the Organization plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.
Quick SCIM facts
| SCIM available? | Yes |
| SCIM tier required | Enterprise |
| SSO required first? | Yes |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Official docs |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | ✓ | ✓ | OIN app with full provisioning |
| Microsoft Entra ID | ✓ | ✓ | Gallery app with SCIM |
| Google Workspace | ✓ | JIT only | SAML SSO with just-in-time provisioning |
| OneLogin | ✓ | ✓ | Supported |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages Whimsical accounts manually. Here's what that costs:
The Whimsical pricing problem
Whimsical gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Plan Structure (Billed Annually)
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Pro | $10/user/month | ||
| Organization | $150/editor/year (~$12.50/month) | ||
| Enterprise | $18-20/editor/month |
Note: Organization pricing shown reflects annual billing discount. Monthly Organization pricing aligns closer to $18/editor/month.
What this means in practice
Using current list prices (Pro → Organization for SCIM access):
| Team Size | Annual Upgrade Cost | Monthly Upgrade Cost |
|---|---|---|
| 25 editors | +$750/year | +$62.50/month |
| 50 editors | +$1,500/year | +$125/month |
| 100 editors | +$3,000/year | +$250/month |
Calculation: ($150 - $120) × editors for annual; higher monthly differential
Additional constraints
Summary of challenges
- Whimsical supports SCIM but only at Enterprise tier ($18-20/editor/month or $150/editor/year (Organization/Enterprise))
- Google Workspace users get JIT provisioning only, not full SCIM
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What the upgrade actually includes
Whimsical doesn't sell SCIM à la carte. It's bundled with Organization tier features at $18-20/editor/month:
The SCIM implementation is straightforward but has notable constraints: it requires SAML SSO to be configured first, roles must be managed entirely from your IdP (not within Whimsical), and provisioned users won't appear in your workspace until they complete their first SAML login.
Stitchflow Insight
If you need enterprise security controls anyway, the Organization upgrade delivers solid value. If you just want automated user provisioning for your visual collaboration tool, you're paying $18-20/editor/month for workspace features that most IT teams won't use. We estimate ~60% of Organization features are irrelevant for teams that only need SCIM provisioning.
What IT admins are saying
Community sentiment on Whimsical's SCIM implementation reveals frustration with configuration complexity and SSO dependencies. Common complaints:
- SCIM completely breaks if you disable SAML SSO, even temporarily
- Users must log in via SAML before appearing in the workspace
- Role management is forced through IdP groups, removing Whimsical admin control
- Email address case sensitivity issues causing sync failures with Okta
Had to troubleshoot for hours why users weren't showing up - turns out they needed to actually log in via SSO first before SCIM would recognize them in the workspace.
The fact that disabling SAML breaks SCIM provisioning is a nightmare for testing and troubleshooting. You can't separate the two systems.
The recurring theme
Whimsical's SCIM feels like an afterthought with too many dependencies and gotchas that create operational headaches for IT teams.
The decision
| Your Situation | Recommendation |
|---|---|
| On Pro ($10/user/month), need SCIM | Use Stitchflow: avoid the 80-100% price increase to Organization |
| On Organization, small team (under 50 users) | Use native SCIM: you're already paying for the tier |
| On Organization, large team (50+ users) | Consider Stitchflow: flat $5K pricing beats per-user costs |
| Need Google Workspace or OneLogin support | Use Stitchflow: native SCIM only supports Okta and Entra ID |
| Small creative team, infrequent user changes | Manual may work: but watch for collaboration gaps across departments |
The bottom line
Whimsical gates SCIM behind Organization. Stitchflow automates complete workflows without that SCIM Tax upgrade.
Make Whimsical workflows AI-native
Whimsical gates SCIM behind Organization. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.
Technical specifications
SCIM Version
2.0
Supported Operations
Create, Update, Deactivate, Groups
Supported Attributes
Not specifiedPlan requirement
Enterprise
Prerequisites
SSO must be configured first
Key limitations
- Requires SAML SSO to be configured first
- Disabling SAML also disables SCIM
- Roles must be managed from IdP, not Whimsical
- Email addresses must be lowercase (Okta)
- Provisioned users must log in via SAML to appear in workspace
Configuration for Okta
Integration type
Okta Integration Network (OIN) app with SCIM provisioning
Prerequisite
SSO must be configured before enabling SCIM.
Where to enable
Required credentials
SCIM endpoint URL and bearer token (generated in app admin console).
Configuration steps
Enable Create Users, Update User Attributes, and Deactivate Users.
Provisioning trigger
Okta provisions based on app assignments (users or groups).
Enterprise required for SCIM
Whimsical gates SCIM behind Organization. Stitchflow automates complete workflows without that SCIM Tax upgrade.
Configuration for Entra ID
Integration type
Microsoft Entra Gallery app with SCIM provisioning
Prerequisite
SSO must be configured before enabling SCIM.
Where to enable
Required credentials
Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).
Configuration steps
Set Provisioning Mode = Automatic, configure SCIM connection.
Provisioning trigger
Entra provisions based on user/group assignments to the enterprise app.
Sync behavior
Entra provisioning runs on a scheduled cycle (typically every 40 minutes).
Enterprise required for SCIM
Whimsical gates SCIM behind Organization. Stitchflow automates complete workflows without that SCIM Tax upgrade.
Unlock SCIM for
Whimsical
Whimsical gates SCIM behind Organization plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade, avoiding a 100% markup.
See how it works


