Loading

How to Integrate SCIM with Quip for Automated User Provisioning

Julkaisupäivä: Aug 18, 2026
Kuvaus

SCIM (System for Cross-domain Identity Management) is an open standard that allows your identity provider (IdP) — such as Okta, Azure Active Directory, or OneLogin — to automatically create, update, and deactivate Quip user accounts based on changes in your directory. This eliminates the need to manually manage Quip users when employees join or leave the organization. This article covers SCIM configuration requirements, setup steps, and common questions.

Ratkaisu

Requirements

  • A Quip site with a Quip Plus or Quip Advanced subscription
  • Site Admin access to the Quip Admin Console
  • An identity provider that supports SCIM 2.0 (Okta, Azure AD, OneLogin, and others)
  • A Quip Admin API key with write permissions (see Create an API Key for Quip)

Example: A company using Okta for identity management wants to ensure that when a new employee is added to the "Quip Users" group in Okta, their Quip account is created automatically with the correct email and name — and when they leave, their Quip account is deactivated the same day their Okta account is disabled, without requiring manual intervention from the Quip administrator.

Quip SCIM Endpoint

The Quip SCIM 2.0 base URL is: https://[yoursite].quip.com/scim/v2

Use this endpoint when configuring the SCIM application in your identity provider. Authentication uses your Quip Admin API key as a bearer token.

Configuration Steps

  1. In the Quip Admin Console, generate an Admin API key with write access (see Create an API Key for Quip).
  2. In your identity provider, create a new SCIM application for Quip and configure the following:
    • SCIM base URL: https://[yoursite].quip.com/scim/v2
    • Authentication method: Bearer token
    • Bearer token value: Your Quip Admin API key
  3. Map your IdP's user attributes to Quip's SCIM attributes. At minimum, map email, first name, and last name.
  4. Assign the Quip SCIM application to the groups or users you want to provision.
  5. Trigger a test provisioning sync and verify in the Quip Admin Console that the expected users have been created.

What SCIM Can and Cannot Do in Quip

SCIM supports the following actions in Quip:

  • Create users: New users are provisioned as Quip site members
  • Update user attributes: Changes to name or email in the IdP are reflected in Quip
  • Deactivate users: Users removed from the SCIM app in the IdP are deactivated in Quip

SCIM does not handle:

  • Assigning Admin roles (must be done manually in the Admin Console)
  • Managing document or folder membership (that is handled separately through Quip's sharing model)

Troubleshooting SCIM Provisioning

If users are not being provisioned as expected, check the following:

  • Confirm the API key has write scope enabled
  • Verify the SCIM base URL does not have a trailing slash
  • Check the provisioning logs in your IdP for error codes returned by Quip's SCIM endpoint
  • Confirm the user's email domain is in the Quip trusted domains list
Knowledge-artikkelin numero

000392638

 
Ladataan
Salesforce Help | Article