MemorySync
Enterprise / Directory sync

SCIM Provisioning

Create, update, and deactivate MemorySync accounts automatically from your directory using the SCIM 2.0 protocol.

Lifecycle

What each directory change does

A MemorySync account is created with your default role, so the person can sign in without anyone filing a ticket.

Compatibility

Supported providers

These are the provisioning options available in Settings → SCIM. Each one is configured with a dedicated provisioning token and the SCIM base URL shown during setup.

OktaAzure ADOneLogin
Operations

Keeping provisioning healthy

Use a dedicated token
Provisioning authenticates with its own bearer token, separate from your API keys, so it can be rotated independently.
Watch sync health
The dashboard reports recent provisioning runs and failures. A failing sync usually means a revoked token or a changed directory permission.
Deactivation over deletion
Directory removal deactivates the account rather than erasing history, which is what auditors expect.
Combine with SSO
SCIM manages who has an account; SSO manages how they authenticate. Most organizations enable both.
Was this page helpful?