The SCIM Endpoint plugin is an API for managing users and the groups in CELUM. The plugin implements version 2.0 of the SCIM protocol.
To be configured in {home}/appserver/conf/
type: String, required: yes, default: -
The license key for the plugin (product: scimEndpoint), provided by brix.
type: bean name, required: yes, default: -
Determines which Authentication method is applied (scimStaticTokenVerifier or scimJsonWebTokenVerifier).
type: String, required: yes (if applied), default: -
Simple static token for scimStaticTokenVerifier.
type: String, required: yes (if applied), default: -
The secret key for scimJsonWebTokenVerifier (at least 256 bits!)
type: boolean, required: no, default: false
Determines whether a user is deleted or deactivated in case of a DELETE request.
type: List of long (comma-separated), required: no, default: -
A list of users who will be excluded from CRUD operations.
type: List of long (comma-separated), required: no, default: -
A list of users who are not deletable.
type: String, required: no, default: readonly
Sets the userKind if no userType is transmitted.
type: List of long (comma-separated), required: no, default: -
A list of groups who will be excluded from CRUD operations.
type: List of long (comma-separated), required: no, default: -
A list of groups who are not deletable.
To access the SCIM API a Bearer Token is required. The API token must be included via an Authentication/Authorization header** with a type of Bearer when calling any of the SCIM methods. Alternatively, a static token can be provided in the token parameter.
The http Content-Type header has to be set to application/scim+json.
The base URL for all calls to the SCIM API is All SCIM methods are branches of this base URL.
The following Endpoints are available:
GET /ServiceProviderConfig
GET /ResourceTypes
GET /Schemas
The following table maps SCIM attributes to CELUM User attributes.
CELUM | SCIM | Remarks |
ID | id | required |
External ID | externalId | |
Username | userName | required |
Password | password | |
Last name | name.familyName | |
First name | name.givenName | |
Middle name | name.middleName | |
Deactivated | active | Default value for POST is active. |
Userkind | userType | Valid values are readonly, editor or readwrite. Defaul value is readonly and can be configured. |
emails[value][primary][type=work] | ||
Phone | phoneNumbers[value][type=work] | type is required |
Mobile | phoneNumbers[value][type=mobile] | type is required |
Fax | phoneNumbers[value][type=fax] | type is required |
Street | addresses[streetAddress][primary][type=work] | |
Zip | addresses[postalCode][primary][type=work] | |
City | addresses[locality][primary][type=work] | |
Country | addresses[country][primary][type=work] | |
User Groups | groups | Group membership changes MUST be applied via the "Group" Resource |
Created | meta.created |
GET /Schemas/urn:ietf:params:scim:schemas:core:2.0:User returns all user attributes and their characteristics that describe their type and handling.
All attributes must be transmitted in a PUT request. Not required attributes that are missing or empty are usually deleted in Celum. Exceptions:
If multiple emails/addresses are transmitted, one must be marked as primary. Otherwise, no one will be stored in Celum in a POST request and no updated is done in a PUT request.
Full User Representation
"id": "170",
"externalId": "externalID",
"userName": "Test_User_1",
"name": {
"familyName": "Mustermann",
"givenName": "Max",
"middleName": "D."
"active": true,
"emails": [
"value": "",
"type": "work"
"phoneNumbers": [
"value": "061 266 66 66",
"type": "work"
"value": "079 266 66 66",
"type": "mobile"
"value": "061 266 66 11",
"type": "fax"
"addresses": [
"streetAddress": "Musterstrasse 1",
"locality": "Binningen",
"postalCode": "4102",
"country": "Schweiz",
"type": "work"
"groups": [
"value": "149",
"$ref": "http://localhost:8881/scim/v2/Groups/149",
"display": "Admin_Group",
"type": "Group"
"value": "7",
"$ref": "http://localhost:8881/scim/v2/Groups/7",
"display": "Marketing",
"type": "Group"
"value": "126",
"$ref": "http://localhost:8881/scim/v2/Groups/126",
"display": "Test_Group_1",
"type": "Group"
"schemas": [
"meta": {
"resourceType": "User",
"created": "2021-04-14T13:45:31.787Z",
"lastModified": "2021-04-14T13:45:31.787Z",
"location": "http://localhost:8881/scim/v2/Users/170"
Full User Representation
"schemas": [
"externalId": "externalID",
"userName": "Test_User_1",
"password": "123456789A!",
"name": {
"familyName": "Mustermann",
"givenName": "Max",
"middleName": "D."
"active": true,
"userType": "editor",
"emails": [
"value": "",
"primary": true
"value": ""
"phoneNumbers": [
"value": "061 266 66 66",
"type": "work"
"value": "061 266 66 11",
"type": "fax"
"value": "079 266 66 66",
"type": "mobile"
"addresses": [
"streetAddress": "Musterstrasse 1",
"locality": "Binningen",
"postalCode": "4102",
"country": "Schweiz",
"primary": true
"streetAddress": "Musterstrasse 2",
"locality": "Binningen",
"postalCode": "4102",
"country": "Schweiz"
Minimal User Representation
"schemas": [
"userName": "Test_User_1",
"name": {
"familyName": "Mustermann"
The following table maps SCIM attributes to CELUM Usergroup attributes.
CELUM | SCIM | Remarks |
ID | id | reqiured |
External ID | externalId | |
Name | displayName | required |
ID | members[value] | |
Username/Name | members[display] | |
Discriminator | members[type] |
GET /Schemas/urn:ietf:params:scim:schemas:core:2.0:Group returns all group attributes and their characteristics that describe their type and handling.
"id": "186",
"externalId": "externalID",
"displayName": "Test_Group_2",
"members": [
"value": "40",
"$ref": "http://localhost:8881/scim/v2/Users/40",
"display": "editor2",
"type": "User"
"value": "43",
"$ref": "http://localhost:8881/scim/v2/Users/43",
"display": "editor3",
"type": "User"
"value": "44",
"$ref": "http://localhost:8881/scim/v2/Users/44",
"display": "readonly3",
"type": "User"
"value": "8",
"$ref": "http://localhost:8881/scim/v2/Groups/8",
"display": "World",
"type": "Group"
"schemas": [
"meta": {
"resourceType": "Group",
"created": "1970-01-01T00:00:00.000Z",
"lastModified": "1970-01-01T00:00:00.000Z",
"location": "http://localhost:8881/scim/v2/Groups/186"
Full Usergroup Representation
"schemas": [
"externalId": "externalID",
"displayName": "Test_Group_2",
"members": [
"value": "40",
"type": "User"
"value": "42",
"type": "User"
"value": "7",
"type": "Group"
Minimal Usergroup Representation
"schemas": [
"displayName": "Test_Group_3"
POST /Bulk
POST [prefix]/.search
The information and implementation details provided here are for guidance only and come without any guarantee. Please note that we do not offer support for Azure.
The mapping must be deleted before you can edit/delete the customappsso attributes.
Azure Active Directory Attribute | customappsso Attribute | Type | Remarks |
- | id | String | primary key, required |
userPrincipalName | userName | String | required |
Switch([IsSoftDeleted], , "False", "True", "True", "False") | active | Boolean | |
emails[type eq "work"].value | String | ||
givenName | name.givenName | String | |
surname | name.familyName | String | |
streetAddress | addresses[type eq "work"].streetAddress | String | |
city | addresses[type eq "work"].locality | String | |
telephoneNumber | phoneNumbers[type eq "work"].value | String | |
mobile | phoneNumbers[type eq "mobile"].value | String | |
facsimileTelephoneNumber | phoneNumbers[type eq "fax"].value | String | |
mailNickname | externalId | String | |
postalCode | addresses[type eq "work"].postalCode | String | |
country | addresses[type eq "work"].country | String |
No changes need to be made to the default mapping for groups.
Azure Active Directory Attribute | customappsso Attribute | Type | Remarks |
- | id | String | primary key, required |
objectId | externalId | String | |
displayName | displayName | String | required |
members | members | Reference | urn:ietf:params:scim:schemas:core:2.0:Group urn:ietf:params:scim:schemas:extension:enterprise:2.0:User |
see Link
Tenant URL
Use the flags below in the tenant URL of your application in order to change the default SCIM client behavior.
Null attribute can't be provisioned
Azure AD currently can't provision null attributes. If an attribute is null on the user object, it will be
skipped (Link).
Remove user from synced group
If a user is no longer in a synced group, Azure will not send a DELETE, but only a PATCH with active = false. Thus, the
user is only deactivated in
Celum (Link)
Delete user
When a user is deleted, Azure apparently only softDelets it first. This leads to a PATCH/PUT with active =
false (Link).
Here you have to delete the user permanently so that Azure sends a DELETE request.
userName softDeletion
Azure prefixes the userName with the ObjectID during softDeletion. This can lead to the userName being too long for
Celum, which is why the user cannot be deactivated.
SCIM Endpoint | CELUM (min. version) |
1.0 - 1.1 | 6.4.0 |
1.2 | 6.4 (tested with 6.11) |
1.3 | 6.20 |
Release: 2021-04-23
Initial Version
Release: 2022-01-28
Release: 2024-03-07
added type 'work' to emails and addresses
Released 2025-02-19
Compatibility with CELUM 6.20
© brix Solutions AG