Configure SCIM provisioning in HCP Terraform
This topic describes how to enable SCIM provisioning in HCP Terraform and generate the credentials required to connect your identity provider. After completing these steps, configure your identity provider to complete the setup.
Requirements
You must meet the following requirements to enable SCIM.
Account
- Your HCP Terraform organization must be on an Essentials, Standard, or Premium plan.
- You must be a member of the owners team for your HCP Terraform organization.
- Your organization must be in a standalone HCP Terraform account. Organizations in accounts integrated with HCP are not supported.
Identity provider
- You must have already configured SAML SSO for your identity provider in your organization. You cannot use the HashiCorp Cloud Platform (HCP) SSO integration for SCIM.
- You must use either Okta or Microsoft Entra ID as your identity provider. Okta requires a custom application because the Okta integration network gallery application for HCP Terraform is incompatible with SCIM for HCP Terraform.
Recommendations
You should also maintain at least two manually managed accounts in the owners team for emergency access. You cannot manage the owners team with SCIM, and users managed through SCIM cannot serve as emergency break-glass accounts because they lack password authentication.
Review your existing IdP group structure and team memberships before enabling SCIM. When SCIM synchronizes a group that already exists in HCP Terraform, the IdP group takes precedence and replaces existing membership.
Enable SCIM
- Log in to HCP Terraform and navigate to your organization.
- Click Organization settings and then SCIM provisioning.
- Click Enable SCIM.
- Click Generate SCIM token.
- Set an expiration date between 30 days and one year from the creation date. SCIM tokens in HCP Terraform have mandatory expiration dates. Rotate the token before it expires to avoid interruptions to SCIM synchronization.
- Copy and store the token securely before closing the dialog. The token is displayed only once. If you close the the dialog before saving the token, you must generate a new token. You need the token to configure the integration your identity provider.
- Copy and save the URL from the Base URL field. You need the base URL to configure the integration with your identity provider.
Configure your identity provider
Follow the instructions for your IdP:
You must have the following information generated during the Enable SCIM step:
- The SCIM base URL from Organization settings > SCIM provisioning
- The SCIM token generated when you enabled SCIM
You must also create a custom SAML application in your identity provider before configuring SCIM. The existing gallery application for Terraform Cloud does not support SCIM for HCP Terraform. Refer to your identity provider setup guide for instructions.
Next steps
Follow the instructions for your IdP to complete the setup: