SCIM webhooks vs. the new SET-based events model
Blog post from WorkOS
RFC 9967, published in May 2026, defines a standards-track SCIM profile for Security Event Tokens (SETs) to make provisioning events more consistent across identity providers. It addresses common shortcomings of ad hoc webhooks, including incompatible payload formats, inconsistent retry behavior, uncertain ordering and duplicate handling, and provider-specific or absent integrity protections, by using signed JWT-based events with standard claims and registered event URIs. The RFC also extends SCIM ServiceProviderConfig so providers can advertise event support and introduces an optional asynchronous request mode that separates request acknowledgment from completion notifications. However, it does not prescribe an event transport, guarantee delivery, or require existing vendors to adopt the profile, meaning organizations must still handle event receipt and outages while supporting a mixed environment of SET-based events and legacy webhooks. Adoption is most useful when a provider already supports the standard or when a SCIM service provider wants to improve interoperability, while reliable existing webhook integrations need not be migrated immediately; the source also presents WorkOS Directory Sync as a service intended to absorb evolving provisioning-integration requirements.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Platform Engineering | 3 | 358 | 65 | 25 | -70% |
| Real-time | 1 | 649 | 155 | 80 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.