Objective
This guide explains how to configure SCIM 2.0 user provisioning between Okta and Comeen Play.
This setup allows you to:
Create Comeen Play users automatically when they are assigned to the app in Okta
Keep user profiles in sync with Okta
Deactivate users automatically when they are unassigned or deactivated in Okta
SCIM manages user accounts; sign-in is handled by SSO. We recommend configuring both, see Configure SAML SSO between Okta and Comeen Play.
Prerequisites
Before starting:
Admin access to Comeen Play, with access to Settings → SCIM Provisioning
Admin access to Okta, with rights to edit app integrations and manage assignments
Recommended: a Comeen Play app already configured in Okta for SAML SSO. You can enable provisioning on that same app.
Step 1 - Enable SCIM provisioning in Comeen Play
Log in to your Comeen account and go to Settings
Open the SCIM Provisioning tab
Turn on Enable SCIM provisioning
Copy the SCIM base URL with the copy button. It looks like
https://api.new.play.comeen.com/scim/spaces/<your space ID>/v2. You will paste it into Okta in Step 3.In Authentication method, select Bearer token
In Default role, choose the role assigned to every user created through SCIM. Leave it empty to create users without a role and assign roles manually.
Click Save changes
⚠ The SCIM base URL is specific to your space. If you manage several spaces, repeat this guide for each one with its own URL and token.
OAuth2 (client credentials) is also available for identity providers that support it. For Okta, use Bearer token.
Step 2 - Create a bearer token
In the Bearer tokens section, click + Create token
Enter a name that identifies the integration, for example Okta production
Choose an expiration: 6 months, 1 year (recommended), 2 years, Custom date or No expiry
Click Create token, then copy the token right away
⚠ The token is displayed only once, at creation. If you lose it, create a new token and revoke the old one.
The token then appears in the list with its Name, Expires, Last used and Created dates. Provisioning stops when a token expires, so plan its renewal.
Step 3 - Configure provisioning in Okta
Enable SCIM on the Comeen Play app
In the Okta Admin Console, go to Applications → Applications and open your Comeen Play app
On the General tab, in App Settings, click Edit
Under Provisioning, select SCIM and click Save. A Provisioning tab appears.
No Comeen Play app yet? Create one with Create App Integration → SAML 2.0 following the SSO guide, then come back to this step.
Connect Okta to Comeen Play
Open the Provisioning tab, select Integration and click Edit
Fill in the fields as follows:
Okta field | Value |
SCIM version | 2.0 |
SCIM connector base URL | The SCIM base URL copied in Step 1 |
Unique identifier field for users |
|
Supported provisioning actions | Import New Users and Profile Updates, Push New Users, Push Profile Updates, Push Groups, Import Groups |
Authentication Mode | HTTP Header |
Authorization (Bearer) | The token created in Step 2 |
Click Test Connector Configuration. Okta should display Connector configured successfully. Close the dialog and click Save.
Choose what Okta sends to Comeen Play
On the Provisioning tab, select To App and click Edit
Enable Create Users, Update User Attributes and Deactivate Users
Click Save
Check attribute mappings
Scroll down to Comeen Play Attribute Mappings and make sure these attributes are mapped. The username comes from the Sign On tab: set Application username format to Email.
Comeen Play (SCIM) attribute | Okta value |
Username ( | Configured in Sign On settings (Email) |
Given name ( |
|
Family name ( |
|
⚠ Use the same email as the SAML NameID so SSO and SCIM resolve to the same Comeen Play account. Avoid changing a user's username in Okta once they are provisioned.
Step 4 - Assign users and push groups
Assign users
Open the Assignments tab of the Comeen Play app
Click Assign, then Assign to People or Assign to Groups
Select the people or groups, then click Save and Go Back and Done
Okta creates each assigned user in Comeen Play within a few minutes, with the default role set in Step 1.
Push groups (optional)
Push groups when you want your Okta groups to exist as user groups in Comeen Play.
Open the Push Groups tab and click Push Groups → Find groups by name
Search for the group, select it and click Save
Wait until the Push Status changes from Pushing to Active
Assigning a group provisions its members as users. Pushing a group also creates the group itself and keeps its membership in sync.
Step 5 - Testing the Configuration
Assign one test user to the app in Okta
In Comeen Play, go to Settings → SCIM Provisioning and scroll to Provisioning activity
Check that a SCIM: created event appears for the test user, under the name of the token used
In Okta, change the user's first or last name. A SCIM: updated event appears with Fields changed: name.
Unassign or deactivate the user in Okta. A SCIM: updated event appears with Fields changed: is_active, and the user shows as (disabled).
In the Bearer tokens list, check that Last used shows a recent date
Use the search bar, Sort by Created at and Filter to find a specific user or event.
Managing tokens
Renew before expiry: create a new token, paste it into Okta (Provisioning → Integration → Edit), run Test Connector Configuration, then revoke the old token.
Revoke: click Revoke next to a token. Okta can no longer call the SCIM API with it, immediately.
One token per integration: give each identity provider or environment its own token, so you can tell their events apart and revoke one without affecting the others.
Troubleshooting
Symptom | What to check |
Test Connector Configuration fails | The base URL is copied in full (ending in |
401 Unauthorized error in Okta | The token has expired or was revoked. Create a new one and update Okta. |
Users are not created | The user is assigned to the app in Okta and Create Users is enabled under To App. Check Okta → Reports → System Log for errors. |
Users are created without a role | No Default role is set in Comeen Play. Set one, or assign roles manually. |
A user has two accounts | The SCIM |
FAQ
What happens when I unassign a user in Okta?
The user is deactivated in Comeen Play and can no longer sign in. Their account is kept, so it can be reactivated by assigning them again.
Are existing Comeen Play users affected?
Users whose email matches an Okta user are linked to that Okta user and updated from then on. Users not managed by Okta stay unchanged.
Can I still edit provisioned users in Comeen Play?
Yes, but Okta remains the source of truth: any synced attribute is overwritten at the next update from Okta.
Does SCIM replace SSO?
No. SCIM manages accounts; SSO manages sign-in. Configure both for a complete Okta integration.










