SCIM lets your identity provider tell Vallkey who’s in your organization and in which groups, so nobody keeps two lists. It’s part of Business.
Connect your provider
- In the console, open Members, Identity provider, and choose Make a token.
- The console shows a SCIM address and a token. The token is shown once.
- Give both to your provider, with the user name mapped to each person’s email address: the address their Vallkey account has.
Make a new token replaces the old one. Disconnect stops your provider’s calls, and leaves your organization as it is.
What happens
| At your provider | In Vallkey |
|---|---|
| Someone is assigned | An admin’s device looks them up, checks their key, and invites them. They join by accepting |
| A group is made, renamed, or its members change | The organization’s group follows |
| A group is deleted | It’s taken out, with what it was granted |
| Someone is deactivated or deleted | They stop receiving the organization’s vaults at once. Each vault they had then gets a new key |
What to know
- Adding waits for an admin’s device. Our server can’t add anyone to your organization, by design. With an admin’s device in use, it takes seconds; otherwise, until one is next used.
- People without a Vallkey account wait. They aren’t emailed yet: ask them to sign up with that address. The console lists who’s waiting.
- It never makes an admin, and never takes an owner away. A mistake at your provider can’t lock you out.
- People and groups you made by hand stay.
- We learn the group names your provider sends. A group made by hand in the console has a name only your admins can read.
- Deactivating isn’t deleting. The person keeps their Vallkey account and their own vaults.
- SCIM adds and removes; single sign-on signs people in. Set up both, and deactivating someone takes their vaults at once and keeps them from signing in again.
After someone is taken away, see when someone leaves.
Last updated October 4, 2026