Agent skill

Implementing Scim Provisioning With Okta

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implement automated user lifecycle provisioning and deprovisioning using the SCIM 2.0 protocol with Okta as the identity provider.

Apache-2.0Auto-check passedBackend & APIs

Install Implementing Scim Provisioning With Okta

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-scim-provisioning-with-okta -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-scim-provisioning-with-okta --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-scim-provisioning-with-okta .claude/skills/implementing-scim-provisioning-with-okta && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-scim-provisioning-with-okta
GitHub stars
34k
Token cost
~2.3k tokens
SKILL.md length
632 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement automated user lifecycle provisioning and deprovisioning using the SCIM 2.0 protocol with Okta as the identity provider.

  • Works in 5 steps: Build SCIM 2.0 API Server → Configure Okta Application → Map Attributes → …
  • Automating account creation
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 3 more sections
  • Runs Python scripts from its folder; needs SCIM_BEARER_TOKEN

What it does

Implementing Scim Provisioning With Okta is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implement automated user lifecycle provisioning and deprovisioning using the SCIM 2.0 protocol with Okta as the identity provider. Use when automating account creation, attribute sync, or deactivation across downstream applications through Okta SCIM integration, or when troubleshooting SCIM provisioning failures.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Okta. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Automating account creation
  • Deactivation across downstream applications through Okta SCIM integration
  • Troubleshooting SCIM provisioning failures

Example prompts

  • “/implementing-scim-provisioning-with-okta”

Requirements

  • Python 3
  • A credential in SCIM_BEARER_TOKEN

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Build SCIM 2.0 API Server
  2. Configure Okta Application
  3. Map Attributes
  4. Implement Error Handling
  5. Test with Runscope/Okta SCIM Validator

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • tools.ietf.org
    • developer.okta.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SCIM_BEARER_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Scim Provisioning With Okta loads about 2.3k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 632 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 632 words, ~2,290 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-scim-provisioning-with-okta/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-scim-provisioning-with-okta
description
Implement automated user lifecycle provisioning and deprovisioning using the SCIM 2.0 protocol with Okta as the identity provider. Use when automating account creation, attribute sync, or deactivation across downstream applications through Okta SCIM integration, or when troubleshooting SCIM provisioning failures.
domain
cybersecurity
subdomain
identity-access-management
tags
scim, okta, provisioning, identity-management, automation, sso, lifecycle-management
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-01, PR.AA-02, PR.AA-05, PR.AA-06
mitre_attack
T1078, T1110, T1556, T1098
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, positioning, resource-development

Implementing SCIM Provisioning with Okta

Overview

SCIM (System for Cross-domain Identity Management) is an open standard protocol (RFC 7644) that automates the exchange of user identity information between identity providers like Okta and service providers. This skill covers building a SCIM 2.0-compliant API endpoint and integrating it with Okta for automated user lifecycle management including provisioning, deprovisioning, profile updates, and group management.

When to Use

  • When deploying or configuring implementing scim provisioning with okta capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Okta tenant with admin access (Developer or Production)
  • Application with REST API capable of user management
  • TLS-secured endpoint (HTTPS required)
  • Okta API token or OAuth 2.0 client credentials
  • Python 3.9+ with Flask or FastAPI

Core Concepts

SCIM 2.0 Protocol

SCIM defines a standard schema for representing users and groups via JSON, with a RESTful API for CRUD operations:

OperationHTTP MethodEndpointDescription
Create UserPOST/scim/v2/UsersProvisions a new user account
Read UserGET/scim/v2/Users/{id}Retrieves user details
Update UserPUT/PATCH/scim/v2/Users/{id}Modifies user attributes
Delete UserDELETE/scim/v2/Users/{id}Removes user account
List UsersGET/scim/v2/UsersLists users with filtering
Create GroupPOST/scim/v2/GroupsCreates a group
Manage GroupPATCH/scim/v2/Groups/{id}Add/remove group members
Okta SCIM Integration Architecture
Okta (IdP) ──SCIM 2.0 over HTTPS──> SCIM Server ──> Application Database
     │                                     │
     ├── User Assignment                   ├── Create/Update User
     ├── User Unassignment                 ├── Deactivate User
     ├── Profile Push                      ├── Sync Attributes
     └── Group Push                        └── Manage Groups
Required SCIM Endpoints
  1. ServiceProviderConfig (/scim/v2/ServiceProviderConfig): Advertises SCIM capabilities
  2. ResourceTypes (/scim/v2/ResourceTypes): Describes supported resource types
  3. Schemas (/scim/v2/Schemas): Publishes the SCIM schema definitions
  4. Users (/scim/v2/Users): User lifecycle operations
  5. Groups (/scim/v2/Groups): Group management operations

Workflow

Step 1: Build SCIM 2.0 API Server

Create a Flask-based SCIM server that implements the core endpoints. The server must handle:

  • User CRUD: Create, read, update, delete, and list users
  • Filtering: Support eq filter on userName (required by Okta)
  • Pagination: Return startIndex, itemsPerPage, and totalResults
  • Authentication: Bearer token validation on all endpoints
python
from flask import Flask, request, jsonify
import uuid
from datetime import datetime

app = Flask(__name__)

# Bearer token for Okta authentication
SCIM_BEARER_TOKEN = "your-secure-token-here"

def require_auth(f):
    def wrapper(*args, **kwargs):
        auth = request.headers.get("Authorization", "")
        if not auth.startswith("Bearer ") or auth[7:] != SCIM_BEARER_TOKEN:
            return jsonify({"detail": "Unauthorized"}), 401
        return f(*args, **kwargs)
    wrapper.__name__ = f.__name__
    return wrapper

@app.route("/scim/v2/Users", methods=["POST"])
@require_auth
def create_user():
    data = request.json
    user_id = str(uuid.uuid4())
    user = {
        "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
        "id": user_id,
        "userName": data.get("userName"),
        "name": data.get("name", {}),
        "emails": data.get("emails", []),
        "active": True,
        "meta": {
            "resourceType": "User",
            "created": datetime.utcnow().isoformat() + "Z",
            "lastModified": datetime.utcnow().isoformat() + "Z",
            "location": f"/scim/v2/Users/{user_id}"
        }
    }
    # Persist user to database
    return jsonify(user), 201

@app.route("/scim/v2/Users", methods=["GET"])
@require_auth
def list_users():
    filter_param = request.args.get("filter", "")
    start_index = int(request.args.get("startIndex", 1))
    count = int(request.args.get("count", 100))
    # Parse filter: userName eq "john@example.com"
    # Query database with filter
    return jsonify({
        "schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
        "totalResults": 0,
        "startIndex": start_index,
        "itemsPerPage": count,
        "Resources": []
    })
Step 2: Configure Okta Application
  1. Create SCIM App Integration:

    • Navigate to Okta Admin Console > Applications > Create App Integration
    • Select SWA or SAML 2.0 as sign-on method
    • In the General tab, select SCIM for Provisioning
  2. Configure SCIM Connection:

    • SCIM connector base URL: https://your-app.com/scim/v2
    • Unique identifier field: userName
    • Supported provisioning actions: Push New Users, Push Profile Updates, Push Groups
    • Authentication Mode: HTTP Header (Bearer Token)
  3. Enable Provisioning Features:

    • To App: Create Users, Update User Attributes, Deactivate Users
    • Configure attribute mappings between Okta profile and SCIM schema
Show full SKILL.md (233 more words)Show less
Step 3: Map Attributes

Map Okta user profile attributes to your SCIM schema:

Okta AttributeSCIM AttributeDirection
loginuserNameOkta -> App
firstNamename.givenNameOkta -> App
lastNamename.familyNameOkta -> App
emailemails[type eq "work"].valueOkta -> App
departmenturn:ietf:params:scim:schemas:extension:enterprise:2.0:User:departmentOkta -> App
Step 4: Implement Error Handling

SCIM specifies standard error response format:

json
{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"],
  "detail": "User already exists",
  "status": "409",
  "scimType": "uniqueness"
}

Common error codes: 400 (Bad Request), 401 (Unauthorized), 404 (Not Found), 409 (Conflict), 500 (Internal Server Error).

Step 5: Test with Runscope/Okta SCIM Validator

Okta provides an automated SCIM test suite (via Runscope/BlazeMeter) that validates your SCIM implementation against all required operations:

  1. Import the Okta SCIM 2.0 test suite from the OIN submission portal
  2. Configure the base URL and authentication token
  3. Run the full test suite covering user CRUD, filtering, and pagination
  4. Fix any failing tests before submitting to OIN

Validation Checklist

  • SCIM server accessible over HTTPS with valid TLS certificate
  • Bearer token authentication enforced on all endpoints
  • User creation returns 201 with full user representation
  • User search by userName eq "..." filter works correctly
  • Pagination parameters (startIndex, count) handled properly
  • User deactivation sets active: false (not hard delete)
  • PATCH operations support add, replace, remove ops
  • Group push creates and manages group memberships
  • Okta SCIM validator test suite passes all tests
  • Error responses conform to SCIM error schema

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-scim-provisioning-with-okta of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Scim Provisioning With Okta next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Scim Provisioning With Okta compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Scim Provisioning With Okta this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Oauth2 Resource Serverrrezartprebreza/spring-boot-skills301—~1.2kAutomated safety check: PassMIT
Emulate Seedyonatangross/orchestkit292—~4.5kAutomated safety check: PassMIT
Cursor Sso Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Cometchat Securitycometchat/cometchat-skills132—~1.9kAutomated safety check: PassMIT

Similar skills

  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Oauth2 Resource Server

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing…

    301 GitHub stars~1.2k tokensUpdated 19 days ago
    Backend & APIsAuto-check passed
  • Emulate Seed

    yonatangross/orchestkit

    Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.

    292 GitHub stars~4.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cursor Sso Integration

    jeremylongshore/tons-of-skills-marketplace

    Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace.

    2.8k GitHub stars~2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cometchat Security

    cometchat/cometchat-skills

    Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…

    132 GitHub stars~1.9k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Implementing Scim Provisioning With Okta

What does Implementing Scim Provisioning With Okta do?

Implement automated user lifecycle provisioning and deprovisioning using the SCIM 2.0 protocol with Okta as the identity provider. Implementing Scim Provisioning With Okta is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.0 protocol with Okta as the identity provider.

When should I use Implementing Scim Provisioning With Okta?

Implementing Scim Provisioning With Okta fits situations like: automating account creation; deactivation across downstream applications through Okta SCIM integration; troubleshooting SCIM provisioning failures.

How do I install Implementing Scim Provisioning With Okta in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-scim-provisioning-with-okta -a claude-code`. Or copy the skill folder (skills/implementing-scim-provisioning-with-okta in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-scim-provisioning-with-okta in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Scim Provisioning With Okta in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-scim-provisioning-with-okta -a codex`. Or copy the skill folder (skills/implementing-scim-provisioning-with-okta in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-scim-provisioning-with-okta in your project. Codex loads it when a task matches its description.

Can I use Implementing Scim Provisioning With Okta in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-scim-provisioning-with-okta -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-scim-provisioning-with-okta, .gemini/skills/implementing-scim-provisioning-with-okta, .github/skills/implementing-scim-provisioning-with-okta and .opencode/skills/implementing-scim-provisioning-with-okta in your project.

What does Implementing Scim Provisioning With Okta need to run?

Going by SKILL.md and its folder, Implementing Scim Provisioning With Okta needs Python for the scripts in its folder and credentials named SCIM_BEARER_TOKEN. Our summary lists: Python 3; A credential in SCIM_BEARER_TOKEN.

Does Implementing Scim Provisioning With Okta access the network?

SKILL.md names 2 domains. As links in the text: tools.ietf.org and developer.okta.com. This is read from the text; nothing was executed.

Is Implementing Scim Provisioning With Okta safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Scim Provisioning With Okta use?

Implementing Scim Provisioning With Okta is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Scim Provisioning With Okta use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Scim Provisioning With Okta?

Skills that share tags, products or a category with Implementing Scim Provisioning With Okta: Iam Audit (briiirussell/cybersecurity-skills, 413 stars), Oauth2 Resource Server (rrezartprebreza/spring-boot-skills, 301 stars), Emulate Seed (yonatangross/orchestkit, 292 stars) and Cursor Sso Integration (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Scim Provisioning With Okta?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.