This article covers what SCIM is, why it’s useful, how to turn it on, and which identity providers work with Sketch.
What is SCIM provisioning?
With SCIM provisioning you can automate user management through your identity provider (IdP). It helps keep your users, permissions, and access in sync with your internal systems — and cuts down the manual work involved. You’ll need to be on an Enterprise or Private Cloud plan.
What is SCIM?
SCIM (System for Cross-domain Identity Management) is an industry standard for automating user provisioning. It lets your identity provider create, update, and deactivate user accounts in external services without any manual work from Workspace admins.
SCIM keeps your Sketch Workspace in sync with your organization’s directory. When someone joins, changes teams, or leaves the company, their Sketch access updates automatically.
Benefits of SCIM
SCIM gives your organization better security, consistency, and makes user management far easier. It is especially helpful for larger teams, distributed organizations, or companies with strict compliance requirements.
- User lifecycle management runs automatically.
- Adding a user in your IdP automatically creates their Sketch account.
- Removing or disabling a user in your IdP immediately revokes their access.
- Admins spend less time managing seats manually: access stays aligned with your internal directory, reducing errors and keeping everything up to date.
- Security and compliance improve by preventing outdated accounts or lingering access after role changes or when someone leaves.
How do I enable SCIM for my organization?
- Head to your Workspace settings, then look for the Single Sign-on tab.
- Copy the
Base URLandSCIM Tokenthat appear. - Paste these values in the Provisioning section of your identity provider.
If you need any help setting things up, get in touch with your Customer Success manager.
Which identity providers do we support?
We currently support SCIM provisioning with:
- Okta
- Google Workspace
- Microsoft Entra ID (formerly Azure Active Directory)
If your organization uses one of these providers, your Customer Success manager will share the configuration details you need, including SCIM endpoint URLs and OAuth tokens, and guide you through the setup.