Configure Okta SAML first so provisioned users can sign in. SCIM manages workspace membership; SAML handles authentication.
Prerequisites
- Okta admin access
- Retrac workspace owner role
- Enterprise plan with SCIM enabled
- SAML SSO configured (recommended)
Set up Okta SCIM
Open Retrac SCIM settings
In Retrac, go to Settings → Security and open SCIM configuration. Generate or copy your:
- SCIM endpoint URL
- Bearer token (shown once — store in a secrets manager)
Enable provisioning in Okta
In the Okta Admin Console, open your Retrac SAML application.Go to the Provisioning tab and click Configure API Integration. Enable provisioning and enter the Retrac SCIM base URL and bearer token.
Configure provisioning settings
Under Provisioning → To App, enable:
- Create Users
- Update User Attributes
- Deactivate Users
| Okta attribute | SCIM field |
|---|---|
user.email | userName / emails |
user.firstName | name.givenName |
user.lastName | name.familyName |
Assign users or groups
Assign the Retrac app to Okta users or groups. Okta pushes create, update, and deactivate events to Retrac via SCIM.