Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

Retiring home-grown SCIM without anyone noticing

Blog post from WorkOS

Post Details
Company
Date Published
Author
Jônatas Santos
Word Count
2,329
Company Posts That Month
46
Language
English
Hacker News Points
-
Post removed?
No
Summary

SCIM Bridge is presented as a self-hosted, reversible proxy for migrating existing enterprise SCIM provisioning integrations to WorkOS Directory Sync without interrupting offboarding, user updates, or group changes and without requiring customers to replace their IdP credentials. Positioned between customer IdPs and an application’s existing SCIM endpoint, it initially passes requests through unchanged, then dual-writes changes to both the native endpoint and WorkOS, backfills existing directory data, and progresses directories through staged modes before a final cutover to WorkOS event-driven synchronization. Its core migrated-id contract allows WorkOS to adopt the application’s preexisting SCIM resource IDs, preserving the identifiers IdPs use for later updates and enabling rollback before the final workos-only transition. The process supports bulk provisioning and configuration, per-directory controls, a single gated Directory Sync listener, activity logs, reconciliation tools, and divergence monitoring, while emphasizing persistent ID mappings, a single bridge writer, ordered event polling, and explicit handling of failed dual writes. Organizations are advised to pilot one directory, move others in waves, compare active rather than total user counts after cutover, and use the included demo mode to test the workflow before production deployment.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.