Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. Administration
  3. Guides
  4. SCIM

Pulumi Cloud & SCIM

This Pulumi Cloud feature is available in the Enterprise edition.

    Pulumi Cloud supports System for Cross-domain Identity Management (SCIM) 2.0 integration with different identity providers. SCIM enables you to manage your users and groups centrally in your Identity Provider (IdP) and then synchronize those users and groups to Pulumi Cloud.

    SCIM provisions two things in Pulumi Cloud:

    • Users become members of your Pulumi organization, able to sign in through your identity provider.
    • Groups become teams, and group membership becomes team membership. Grant those teams access to stacks, environments, and other entities with RBAC.

    Pulumi implements a single SCIM 2.0 endpoint. Every identity provider uses the same routes, schemas, and attributes, so only the IdP-side setup differs from one provider to the next. The guides at the end of this page cover popular providers.

    Pulumi supports only one Pulumi Cloud organization per SCIM application. If your team manages multiple Pulumi Cloud organizations, you must configure separate SCIM applications for each Pulumi Cloud organization in your Identity Provider.

    Before you start

    SCIM changes how accounts and teams behave in ways that matter before you connect an identity provider: deprovisioning deactivates users rather than deleting them, deleting a group deletes its team, usernames can’t change after an account is created, and provisioned accounts become organization-managed. Read SCIM provisioning for the capabilities, supported attributes, and behavior to plan for.

    Next steps

    To set up synchronization between Pulumi and your SAML 2.0 identity provider, refer to one of our example guides:

    For the provisioning errors you are most likely to hit and how to resolve them, see Troubleshooting.

      The infrastructure as code platform for any cloud.