SCIM Provisioning for GraphQL | Automated User Lifecycle | Cosmo by WunderGraph - WunderGraph

User access follows your identity provider automatically

SCIM provisioning connects your identity provider to Cosmo. New users get invited automatically. Departing users are deactivated immediately. No manual steps in between.

No manual onboarding. No delayed offboarding.

The problem

Manual provisioning creates security gaps

User access that depends on manual steps depends on someone remembering to do them. Onboarding is delayed. Offboarding is incomplete. Audit trails don't add up.

New hires wait days for tool access

Manual invitations require an administrator to notice a new hire, find the right access level, and send the invitation. Access is delayed when the process depends on humans remembering.

Departing employees retain access

Offboarding requires visiting every tool individually. One step missed means a former employee retains access. The risk window grows with every tool added to the stack.

User data drifts between systems

When attributes change in the identity provider — name, team, role — those changes don't automatically reach Cosmo. Two systems, two sources of truth, neither fully correct.

Our solution

Automated user lifecycle via SCIM

Cosmo implements the SCIM standard. Your identity provider pushes user lifecycle events — create, update, deactivate — directly to Cosmo. The integration uses a dedicated API key for authentication and requires no ongoing maintenance.

How to set up SCIM

  1. Generate an API key with SCIM permission enabled in Cosmo Studio.
  2. Configure your identity provider's SCIM application using the Cosmo SCIM endpoint and the API key as the authorization header.
  3. When a user is added to the SCIM application in your IdP, Cosmo sends them an invitation email automatically.
  4. When a user's attributes change in the IdP, Cosmo synchronizes the change automatically.
  5. When a user is removed from the SCIM application, Cosmo immediately deactivates their account.
  6. Pair with SSO for complete identity management: SSO handles authentication, SCIM handles provisioning.

Configure once. User lifecycle runs automatically from there.

SCIM Provisioning

Before & After

Before Cosmo With Cosmo
Manual invitation for every new hire Automatic invitation when added to IdP SCIM app
Delayed or forgotten offboarding Immediate deactivation on IdP removal
Attribute drift between IdP and Cosmo Automatic synchronization of user attributes
Orphaned accounts from former employees Clean user lifecycle, no manual cleanup required

Three operations

Full lifecycle support

How Cosmo SCIM works

Create

Adding a user to your IdP's SCIM application triggers an invitation email to the user. They accept the invitation and join your Cosmo organization.

Update

Attribute changes in the identity provider — name, email, or other profile data — are synchronized to Cosmo automatically via the SCIM protocol.

Deactivate

Removing a user from the SCIM application immediately deactivates their Cosmo account. No lag, no manual step, no orphaned access.

Authenticate

SCIM uses an API key with SCIM permission as its authorization header. Create a dedicated key for the SCIM integration and store it securely in your IdP configuration.

What's included

Automated identity lifecycle, standards-based

Automate user provisioning for your organization

SCIM provisioning is available on the Enterprise plan.