doc: added tip for SCIM

This commit is contained in:
Sheen Capadngan
2024-11-23 03:11:06 +08:00
parent 7c62a776fb
commit 63fac39fff
+16 -7
View File
@@ -3,11 +3,15 @@ title: "SCIM Overview"
description: "Learn how to provision users for Infisical via SCIM."
---
<Note>
SCIM provisioning can only be enabled when either SAML or OIDC is setup for
the organization.
</Note>
<Info>
SCIM provisioning is a paid feature.
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical,
then you should contact [email protected] to purchase an enterprise license to use it.
SCIM provisioning is a paid feature. If you're using Infisical Cloud, then it
is available under the **Enterprise Tier**. If you're self-hosting Infisical,
then you should contact [email protected] to purchase an enterprise license
to use it.
</Info>
You can configure your organization in Infisical to have users and user groups be provisioned/deprovisioned using [SCIM](https://scim.cloud/#Implementations2) via providers like Okta, Azure, JumpCloud, etc.
@@ -25,8 +29,13 @@ SCIM providers:
<AccordionGroup>
<Accordion title="Why do SCIM-provisioned users have to finish setting up their account?">
Infisical's SCIM implementation accounts for retaining the end-to-end encrypted architecture of Infisical because we decouple the **authentication** and **decryption** steps in the platform.
For this reason, SCIM-provisioned users are initialized but must finish setting up their account when logging in the first time by creating a master encryption/decryption key. With this implementation, IdPs and SCIM providers cannot and will not have access to the decryption key needed to decrypt your secrets.
Infisical's SCIM implementation accounts for retaining the end-to-end
encrypted architecture of Infisical because we decouple the
**authentication** and **decryption** steps in the platform. For this
reason, SCIM-provisioned users are initialized but must finish setting up
their account when logging in the first time by creating a master
encryption/decryption key. With this implementation, IdPs and SCIM providers
cannot and will not have access to the decryption key needed to decrypt your
secrets.
</Accordion>
</AccordionGroup>