Web app Free to use

Flexi-SCIM

A flexible SCIM server for testing identity provisioning

Flexi-SCIM gives you real SCIM 2.0 endpoints to test against. Spin up isolated instances with a path and a token, provision Users and Groups the way your identity provider does, inspect every request it receives, and diff two instances side by side. No identity provider required.

SCIM 2.0 · RFC 7643 · RFC 7644 · Bearer tokens

Flexi-SCIM instance dashboard listing provisioned Users with statuses and Groups

An isolated endpoint in seconds.

Pick a path and a token and you have a working SCIM endpoint at /scim/your-path. Each instance keeps its own Users, Groups, and request log, so parallel tests never see each other's data. Reset an instance to a clean slate any time.

Instances are addressed by the endpoint URL and bearer token you choose, which keeps them drop-in compatible with any SCIM client: point it at the URL, hand it the token, done.

Flexi-SCIM setup form for creating a SCIM instance with endpoint path and token
Path, token, instance: a fresh SCIM endpoint at /scim/your-path

Provision users the way your IdP does.

Create Users with core and enterprise attributes, look them up by filter, move people between roles with PATCH, and group them with membership-aware Groups. The full joiner-mover-leaver cycle works over plain SCIM 2.0, so the same calls your identity provider makes are the calls you test with.

joiner, mover, leaver over SCIM 2.0
$ curl -X POST https://flexi-scim.etelej.com/scim/demo/Users \
    -H "Authorization: Bearer $TOKEN" -d '{...}'
201 {"id":"1206687434","userName":"[email protected]","active":true}
$ curl ".../Users?filter=userName eq \"[email protected]\"" \
    -H "Authorization: Bearer $TOKEN"
200 {"totalResults":1,"resources":[{"id":"1206687434",...}]}
$ curl -X PATCH .../Users/1206687434 -H "Authorization: Bearer $TOKEN" \
    -d '{"Operations":[{"op":"replace","path":"active","value":false}]}'
200 {"active":false}
Create, filter, PATCH: the same operations your identity provider sends

See exactly what your client sent.

Each instance keeps a log of the requests it receives: method, path, and full request body, newest first. When provisioning misbehaves, the log shows whether the request ever arrived, what it actually contained, and what the server did with it.

Instance details stay read-only with the token masked, and a reset button clears the contents when you want a clean run.

Flexi-SCIM request log listing POST and PATCH provisioning requests with methods, paths, and bodies
Method, path, and body for every request the instance received

Prove two runs did the same thing.

Run the same provisioning flow against two instances, then diff them. Flexi-SCIM compares the requests each instance received and reports a match, or lists exactly which operations one side is missing. Hand the report to whoever owns the misbehaving client.

It is the fastest way to answer why provisioning worked in staging but not in production: replay both, compare, and read the missing operations.

Flexi-SCIM instance details showing the endpoint URL, masked token, and reset controls
Instance details: endpoint, masked token, and reset controls

Stop testing SCIM on production.

Free to use, no sign-up. Create an instance, point your SCIM client at it, and watch the requests land.