Skip to main content

Okta Integration Guide (SCIM)

How to configure Fellow Okta integration for users provisioning using SCIM protocol

Written by Dev Team
Updated over a month ago

This guide walks workspace administrators through configuring SCIM provisioning between Okta and Fellow, enabling automated user lifecycle management across your organization.

Supported Features

Feature

Description

Create Users

New users added to Okta are automatically provisioned in Fellow.

Update User Attributes

Profile changes in Okta are synced to Fellow for all users assigned to the application.

Deactivate Users

Deactivating a user in Okta prevents them from signing in to Fellow and marks their account as Disabled.

Reactivate Users

Reactivating a user in Okta restores their access to Fellow and marks their account as Enabled.

Group Push

Okta groups can be pushed to Fellow as Teams.

Requirements

  • A Fellow account on an Enterprise plan with SCIM enabled

  • A Fellow workspace administrator account

  • An Okta administrator account (or coordination with your IT team)

Part 1: Enable SCIM in Fellow

  1. Sign in to Fellow using a workspace administrator account.

  2. Navigate to Workspace Settings β†’ Account Integrations and select the SCIM2 card.

  3. Click the Connect button in the top-right corner of the page.

  4. On the configuration form that appears, click Regenerate SCIM Token and confirm the action when prompted.

  5. Copy the generated SCIM token and store it securely β€” you will need it in the next section.

Part 2: Configure SCIM in Okta

2.1 Access or Add the Fellow Application

  1. Sign in to your Okta account and navigate to Applications at: https://<your_workspace>.okta.com/admin/apps/active

  2. If you have already configured OIDC for Fellow: locate the existing Fellow application and proceed directly to the Provisioning tab.

  3. If you have not yet added Fellow: click Browse App Catalog, search for Fellow.app, and click Add. When prompted, enter your Fellow subdomain and complete the initial setup form.

2.2 Enable API Integration

  1. Navigate to the Provisioning tab of the Fellow application.

  2. Check the Enable API Integration checkbox.

  3. Paste the SCIM token copied from Fellow into the API Key field.

  4. Click Test API Credentials to verify the connection. Once the test passes, click Save.

2.3 Configure Provisioning Actions

  1. On the Provisioning tab, select To App and click Edit.

  2. Enable the following checkboxes:

    1. Create Users

    2. Update User Attributes

    3. Deactivate Users

  3. Click Save.

2.4 Configure Sign-On Settings

  1. Navigate to the Sign On tab of the Fellow application and click Edit.

  2. Set the Application Username Format field to Email.

  3. Click Save.

SCIM provisioning is now active. Users assigned to the Fellow application in Okta will be automatically synced to Fellow.

Troubleshooting & Tips

Username and email updates are not supported. If your organization needs to change user email domains, merge user accounts, or migrate users between domains, contact the Fellow support team before making any changes in Okta to avoid provisioning errors.

For assistance, reach out to the Fellow support team via:

Did this answer your question?