Stitchflow
Windsurf logo

Windsurf SCIM guide

Native SCIM

How to automate Windsurf user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

Windsurf supports native SCIM provisioning through their standard SCIM 2.0 implementation. However, SCIM access is locked behind the Enterprise tier at $60/user/month—double the cost of their Teams plan ($30/user/month) that includes SSO. For a 50-developer team, upgrading from Teams to Enterprise solely for SCIM costs an additional $18,000/year. The implementation also requires SCIM to be the single source of truth—mixing manual user management with SCIM creates account drift issues.

This pricing gap creates a real problem for growing engineering teams. Developers need immediate access to AI coding tools when they join, but manually provisioning accounts in a sensitive IP environment introduces security risks and delays onboarding. SSO alone doesn't solve this—you still need someone manually creating accounts, assigning proper model access controls, and cleaning up when developers leave.

The strategic alternative

Stitchflow provides managed SCIM automation for Windsurf without requiring the Enterprise tier upgrade. Works with any plan, any IdP. Flat pricing under $5K/year regardless of team size.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Windsurf accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Windsurf pricing problem

Windsurf gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure (Billed Monthly)

PlanPriceSSOSCIM
Teams$30/user/mo
Enterprise$60/user/mo

Note: Teams tier includes SSO but no SCIM. Enterprise is required for full SCIM provisioning with group push and role-based model access controls.

What this means in practice

Using current list prices (Teams → Enterprise for SCIM):

Team SizeAnnual Upgrade Cost
25 developers+$9,000/year
50 developers+$18,000/year
100 developers+$36,000/year

Calculation: $30/user/month × users × 12 months for the tier upgrade

Additional constraints

No volume discounts until 200+ users
Smaller engineering teams pay full list price for the Enterprise upgrade.
Credit costs stack on top
Enterprise pricing doesn't include unlimited AI usage - teams still pay $40/1000 pooled credits for heavy model usage.
SP-initiated SSO only
IDP-initiated SSO is not supported, limiting some identity workflow configurations.
Manual provisioning drift risk
Windsurf warns that mixing SCIM with manual or API provisioning creates user state conflicts - Enterprise SCIM must be the single source of truth.

Summary of challenges

  • Windsurf supports SCIM but only at Enterprise tier ($60/user/month (Enterprise with ZDR))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Windsurf doesn't sell SCIM à la carte. It's bundled with Enterprise features at $60/user/month:

SCIM 2.0 automated provisioning (create, update, deactivate users and groups)
SAML single sign-on with RBAC controls
Zero Data Retention (ZDR) for code privacy
Model access controls by team/role
Advanced security settings and audit logs
SOC 2 Type II compliance
Enterprise support and SLA

Stitchflow Insight

Teams upgrading from the $30/month Teams plan (which includes SSO) pay double their current rate primarily for SCIM and ZDR. If you need enterprise-grade code security anyway, the upgrade makes sense. If you just want automated user provisioning, you're paying for a premium bundle. We estimate ~60% of Enterprise features are irrelevant for teams that only need basic SCIM functionality.

What IT admins are saying

Community sentiment on Windsurf's SCIM requirements centers around the steep Enterprise pricing barrier. Common complaints:

  • Enterprise tier required for SCIM doubles the cost from Teams ($30 to $60/user/month)
  • No middle-ground option between Teams SSO and full Enterprise features
  • Mixing SCIM with manual provisioning creates user drift issues
  • SP-initiated SSO only - no IdP-initiated support for streamlined workflows

Enterprise required for SSO/SCIM - that's a big jump from the Teams plan just for identity features.

Enterprise IT Forum

The documentation warns about drift if you mix SCIM with manual user management, but then why charge so much for the automation?

Reddit IT Discussion

The recurring theme

Windsurf forces a 100% price increase just to get automated provisioning, pushing teams toward error-prone manual user management or expensive Enterprise upgrades.

The decision

Your SituationRecommendation
On Teams ($30/user), need SCIMUse Stitchflow: avoid the $30/user/month Enterprise upgrade
On Pro ($15/month), need team provisioningUse Stitchflow: skip both Teams and Enterprise tiers
Already on Enterprise with SCIMUse native SCIM: you're paying $60/user/month for it
Large engineering team (200+ users) with volume discountsEvaluate Enterprise: SCIM comes bundled with volume pricing
Small dev team, infrequent changesManual may work: but consider security implications for code access

The bottom line

Windsurf's Enterprise tier requirement means SCIM costs $30-45/user/month more than your current plan. For development teams that need automated provisioning without Enterprise features, Stitchflow delivers SCIM automation at under $5K/year total.

Automate Windsurf without the tier upgrade

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for Windsurf at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

None

Key limitations

  • SSO recommended but not required for SCIM
  • SCIM should be source of truth - mixing with manual/API creates drift
  • Enterprise tier required for SCIM
  • SP-initiated SSO only - IDP-initiated NOT supported

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Where to enable

Entra admin center → Enterprise applications → Windsurf → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Enterprise required for SCIM

Native SCIM is available on Enterprise. Use Stitchflow if you need provisioning without the tier upgrade.

Unlock SCIM for
Windsurf

Windsurf gates automation behind Enterprise plan. Stitchflow delivers the same SCIM outcomes for a flat fee, saving you 100%.

See how it works
Admin Console
Directory
Applications
Windsurf logo
Windsurf
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Airbase logo

Airbase

SCIM Tax

Spend Management / Corporate Cards

SCIM StatusIncluded
Manual Cost$11,754/yr

Airbase supports SCIM provisioning, but only on Enterprise plans starting around $8,500/year. While SCIM works with all major identity providers (Okta, Entra ID, Google Workspace), the Enterprise requirement creates a significant barrier for smaller finance teams who need automated provisioning for spend management but can't justify enterprise-level spend management software costs. This creates a particular challenge in finance applications where rapid provisioning and deprovisioning is critical for corporate card access and financial controls. Manual user management means delayed access for new employees needing corporate cards, and more critically, potential security gaps when departing employees retain access to spend management systems. For finance teams handling sensitive financial data and corporate spending, these delays and oversights create both operational friction and compliance risks.

View full guide
Airfocus logo

Airfocus

SCIM Tax

Product Management / Roadmapping

SCIM StatusIncluded
Manual Cost$11,754/yr

Airfocus supports SCIM provisioning, but only on Enterprise plans with custom pricing. While it handles basic user lifecycle management (create, update, deactivate), it lacks group provisioning entirely—meaning team assignments and workspace access must be managed manually. The Azure Entra integration also suffers from significant delays (~40 minutes for provisioning), creating gaps where users can't access product roadmaps they need immediately. For product management teams, this creates operational friction. Product managers, executives, and engineering leads need timely access to strategic roadmaps, but manual group assignments slow onboarding and complicate offboarding. Without automated group provisioning, IT teams must coordinate with product leads to ensure the right stakeholders have appropriate workspace access—exactly the kind of manual work SCIM should eliminate.

View full guide