### Steps to set up SCIM with Okta

1. Set up the password policy (password should contain at least one number and one symbol), if using the **Classic Engine on Okta** follow the below steps **,** or if using the **OIE engine,** follow the steps as mentioned in this **[Okta guide](https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-password.htm)**.
   - Navigate to Security -> Authentication on your Okta Administrator Dashboard.
   - Click Edit and update the password policy by enabling Number and Symbol, then click on Update Policy.

2. Navigate to the Applications view within your Okta Administrator Dashboard.

3. Click on **Browse App Catalog.**

4. Search for **Wundergraph Cosmo.**

5. Click on **Add Integration.**

6. Now give the app a name and then click on **Next.**

7. Select **Administrator sets username, user sets password** and for **Application username format** under **Credentials Details** select **Email** and then click **Done.**

8. Navigate to the settings page on WunderGraph Cosmo and enable **SCIM.**

9. Once SCIM is enabled, you will be provided with a **SCIM Server URL,** copy it **.**

10. Navigate to the API Keys page on WunderGraph Cosmo and click on New API Key.

11. Provide the key with a name, select **Never** for **Expires,** then select **SCIM** under **Permissions,** then click on **Generate API key.**

12. Copy the API key provided.

13. Navigate to the provisioning tab of the app created on okta, then click on **Configure API Integration.**

14. Check the **Enable API Integration** and then populate the **API token** with the **API key** copied in the previous steps.

15. Click on **Test API Credentials** and once it’s verified successfully, click on **Save**

16. Navigate to the “ **to App” ** tab **, and** click on **Edit.**

17. Enable **Create Users, Update User Attributes, Deactivate Users** and **Sync Password.**

18. Under **Sync Password** for **Password type**, select **Sync Okta Password.**

19. Click **save.**

20. Now you can navigate the Assignments tab and assign users/groups who should have access to WunderGraph Cosmo.

If you are using both **SSO with OIDC** and **SCIM**, please make sure that the users assigned in both apps are the same.
