Definition

SCIM, the System for Cross-domain Identity Management, is an HTTP-based protocol that standardizes how user identities are managed across multiple domains. In HR software, it lets a system of record such as an HRIS create, update, and deactivate user accounts in connected applications automatically.

Also known as: System for Cross-domain Identity Management, SCIM provisioning

How it works

SCIM, defined in IETF RFC 7644, provides a standardized service for managing identities in multi-domain scenarios. It rests on a common schema, defined in RFC 7643, so different systems describe users and groups the same way.

A SCIM client, such as an HRIS, sends HTTP requests to a SCIM endpoint on each connected application. Four functions are supported. Create adds a resource to endpoints such as /Users or /Groups. Read retrieves resources, with filtering, sorting, and pagination. Update works through PUT, which replaces attributes, or PATCH, which applies partial changes. Delete removes a resource.

Payloads use JSON with the media type application/scim+json. For HR teams, this means a hire, role change, or termination recorded once can flow to downstream applications without manual account administration.

Example

When a company marks a new hire as active in its HRIS, a SCIM connection creates the employee's accounts in the collaboration and learning tools. When the employee leaves, a delete or deactivate request removes those accounts.

How it differs from similar terms

SCIM vs Single Sign-On. SCIM manages the lifecycle of user accounts, while single sign-on handles the sign-in event itself. Organizations commonly deploy both together.

Related terms and guides

Full HR glossary

Frequently asked questions

What does SCIM do?

SCIM standardizes identity management across systems using an HTTP-based protocol. A source system can create, read, update, and delete user and group records in other applications, which reduces manual account setup and helps keep access aligned with employment status. It relies on a shared schema so systems describe users consistently.

What format does SCIM use?

SCIM exchanges data as JSON, identified by the media type application/scim+json. Each resource lists the applicable SCIM schema URIs, and attribute definitions follow the core schema in RFC 7643, including characteristics such as mutability and cardinality. Requests are sent over HTTP to endpoints on each connected application.

How is SCIM different from SSO?

SSO authenticates a user at sign-in. SCIM provisions and deprovisions the accounts that user signs in to. SCIM answers whether an account exists and what attributes it holds, while SSO answers whether the person is who they claim to be.