Skip to main content

Configure SCIM provisioning between Okta and Comeen Play

Automatically create, update and deactivate Comeen Play users from Okta with SCIM 2.0.

Objective

This guide explains how to configure SCIM 2.0 user provisioning between Okta and Comeen Play.

This setup allows you to:

  • Create Comeen Play users automatically when they are assigned to the app in Okta

  • Keep user profiles in sync with Okta

  • Deactivate users automatically when they are unassigned or deactivated in Okta

SCIM manages user accounts; sign-in is handled by SSO. We recommend configuring both, see Configure SAML SSO between Okta and Comeen Play.


Prerequisites

Before starting:

  • Admin access to Comeen Play, with access to Settings → SCIM Provisioning

  • Admin access to Okta, with rights to edit app integrations and manage assignments

  • Recommended: a Comeen Play app already configured in Okta for SAML SSO. You can enable provisioning on that same app.


Step 1 - Enable SCIM provisioning in Comeen Play

  1. Log in to your Comeen account and go to Settings

  2. Open the SCIM Provisioning tab

  3. Turn on Enable SCIM provisioning

  4. Copy the SCIM base URL with the copy button. It looks like https://api.new.play.comeen.com/scim/spaces/<your space ID>/v2. You will paste it into Okta in Step 3.

  5. In Authentication method, select Bearer token

  6. In Default role, choose the role assigned to every user created through SCIM. Leave it empty to create users without a role and assign roles manually.

  7. Click Save changes

⚠ The SCIM base URL is specific to your space. If you manage several spaces, repeat this guide for each one with its own URL and token.

OAuth2 (client credentials) is also available for identity providers that support it. For Okta, use Bearer token.

Step 2 - Create a bearer token

  1. In the Bearer tokens section, click + Create token

  2. Enter a name that identifies the integration, for example Okta production

  3. Choose an expiration: 6 months, 1 year (recommended), 2 years, Custom date or No expiry

  4. Click Create token, then copy the token right away

⚠ The token is displayed only once, at creation. If you lose it, create a new token and revoke the old one.

The token then appears in the list with its Name, Expires, Last used and Created dates. Provisioning stops when a token expires, so plan its renewal.

Step 3 - Configure provisioning in Okta

Enable SCIM on the Comeen Play app

  1. In the Okta Admin Console, go to Applications → Applications and open your Comeen Play app

  2. On the General tab, in App Settings, click Edit

  3. Under Provisioning, select SCIM and click Save. A Provisioning tab appears.

No Comeen Play app yet? Create one with Create App Integration → SAML 2.0 following the SSO guide, then come back to this step.

Connect Okta to Comeen Play

  1. Open the Provisioning tab, select Integration and click Edit

  2. Fill in the fields as follows:

Okta field

Value

SCIM version

2.0

SCIM connector base URL

The SCIM base URL copied in Step 1

Unique identifier field for users

email

Supported provisioning actions

Import New Users and Profile Updates, Push New Users, Push Profile Updates, Push Groups, Import Groups

Authentication Mode

HTTP Header

Authorization (Bearer)

The token created in Step 2

Click Test Connector Configuration. Okta should display Connector configured successfully. Close the dialog and click Save.

Choose what Okta sends to Comeen Play

  1. On the Provisioning tab, select To App and click Edit

  2. Enable Create Users, Update User Attributes and Deactivate Users

  3. Click Save

Check attribute mappings

Scroll down to Comeen Play Attribute Mappings and make sure these attributes are mapped. The username comes from the Sign On tab: set Application username format to Email.

Comeen Play (SCIM) attribute

Okta value

Username (userName)

Configured in Sign On settings (Email)

Given name (givenName)

user.firstName

Family name (familyName)

user.lastName

⚠ Use the same email as the SAML NameID so SSO and SCIM resolve to the same Comeen Play account. Avoid changing a user's username in Okta once they are provisioned.

Step 4 - Assign users and push groups

Assign users

  1. Open the Assignments tab of the Comeen Play app

  2. Click Assign, then Assign to People or Assign to Groups

  3. Select the people or groups, then click Save and Go Back and Done

Okta creates each assigned user in Comeen Play within a few minutes, with the default role set in Step 1.

Push groups (optional)

Push groups when you want your Okta groups to exist as user groups in Comeen Play.

  1. Open the Push Groups tab and click Push Groups → Find groups by name

  2. Search for the group, select it and click Save

  3. Wait until the Push Status changes from Pushing to Active

Assigning a group provisions its members as users. Pushing a group also creates the group itself and keeps its membership in sync.

Step 5 - Testing the Configuration

  1. Assign one test user to the app in Okta

  2. In Comeen Play, go to Settings → SCIM Provisioning and scroll to Provisioning activity

  3. Check that a SCIM: created event appears for the test user, under the name of the token used

  4. In Okta, change the user's first or last name. A SCIM: updated event appears with Fields changed: name.

  5. Unassign or deactivate the user in Okta. A SCIM: updated event appears with Fields changed: is_active, and the user shows as (disabled).

  6. In the Bearer tokens list, check that Last used shows a recent date

Use the search bar, Sort by Created at and Filter to find a specific user or event.


Managing tokens

  • Renew before expiry: create a new token, paste it into Okta (Provisioning → Integration → Edit), run Test Connector Configuration, then revoke the old token.

  • Revoke: click Revoke next to a token. Okta can no longer call the SCIM API with it, immediately.

  • One token per integration: give each identity provider or environment its own token, so you can tell their events apart and revoke one without affecting the others.

Troubleshooting

Symptom

What to check

Test Connector Configuration fails

The base URL is copied in full (ending in /v2), Enable SCIM provisioning is on and saved, and the token is pasted without extra spaces.

401 Unauthorized error in Okta

The token has expired or was revoked. Create a new one and update Okta.

Users are not created

The user is assigned to the app in Okta and Create Users is enabled under To App. Check Okta → Reports → System Log for errors.

Users are created without a role

No Default role is set in Comeen Play. Set one, or assign roles manually.

A user has two accounts

The SCIM userName and the SAML NameID use different values. Map both to the user's email.

FAQ

What happens when I unassign a user in Okta?

The user is deactivated in Comeen Play and can no longer sign in. Their account is kept, so it can be reactivated by assigning them again.

Are existing Comeen Play users affected?

Users whose email matches an Okta user are linked to that Okta user and updated from then on. Users not managed by Okta stay unchanged.

Can I still edit provisioned users in Comeen Play?

Yes, but Okta remains the source of truth: any synced attribute is overwritten at the next update from Okta.

Does SCIM replace SSO?

No. SCIM manages accounts; SSO manages sign-in. Configure both for a complete Okta integration.

Did this answer your question?