This guide walks workspace administrators through configuring SCIM provisioning between Okta and Fellow, enabling automated user lifecycle management across your organization.
Supported Features
Feature | Description |
Create Users | New users added to Okta are automatically provisioned in Fellow. |
Update User Attributes | Profile changes in Okta are synced to Fellow for all users assigned to the application. |
Deactivate Users | Deactivating a user in Okta prevents them from signing in to Fellow and marks their account as Disabled. |
Reactivate Users | Reactivating a user in Okta restores their access to Fellow and marks their account as Enabled. |
Group Push | Okta groups can be pushed to Fellow as Teams. |
Requirements
A Fellow account on an Enterprise plan with SCIM enabled
A Fellow workspace administrator account
An Okta administrator account (or coordination with your IT team)
Part 1: Enable SCIM in Fellow
Sign in to Fellow using a workspace administrator account.
Navigate to Workspace Settings β Account Integrations and select the SCIM2 card.
Click the Connect button in the top-right corner of the page.
On the configuration form that appears, click Regenerate SCIM Token and confirm the action when prompted.
Copy the generated SCIM token and store it securely β you will need it in the next section.
Part 2: Configure SCIM in Okta
2.1 Access or Add the Fellow Application
Sign in to your Okta account and navigate to Applications at:
https://<your_workspace>.okta.com/admin/apps/activeIf you have already configured OIDC for Fellow: locate the existing Fellow application and proceed directly to the Provisioning tab.
If you have not yet added Fellow: click Browse App Catalog, search for
Fellow.app, and click Add. When prompted, enter your Fellow subdomain and complete the initial setup form.
2.2 Enable API Integration
Navigate to the Provisioning tab of the Fellow application.
Check the Enable API Integration checkbox.
Paste the SCIM token copied from Fellow into the API Key field.
Click Test API Credentials to verify the connection. Once the test passes, click Save.
2.3 Configure Provisioning Actions
On the Provisioning tab, select To App and click Edit.
Enable the following checkboxes:
Create Users
Update User Attributes
Deactivate Users
Click Save.
2.4 Configure Sign-On Settings
Navigate to the Sign On tab of the Fellow application and click Edit.
Set the Application Username Format field to Email.
Click Save.
SCIM provisioning is now active. Users assigned to the Fellow application in Okta will be automatically synced to Fellow.
Troubleshooting & Tips
Username and email updates are not supported. If your organization needs to change user email domains, merge user accounts, or migrate users between domains, contact the Fellow support team before making any changes in Okta to avoid provisioning errors.
For assistance, reach out to the Fellow support team via:
Email: [email protected]
In-app chat: via Intercom within the Fellow application
