Set up SCIM user provisioning
SCIM automatically manages who can access your Lovable workspace and what they can do, directly from your company's identity system. This keeps your user list and roles in Lovable always up-to-date without manual effort.
Anyone managing user access for a company's Lovable workspace needs this to automate user setup and roles.
Do this, in order
- 1
Go to your Lovable Workspace settings, then Access, then Identity, and click 'Enable' for SCIM provisioning.
This starts the setup wizard in Lovable to connect with your company's identity system.
- 2
In the wizard, enter the exact names of your company's user groups for 'Admin', 'Editor', and 'Viewer' roles, and decide if Lovable should send welcome emails.
This tells Lovable which company groups correspond to which access levels, ensuring users get the right permissions automatically.
- 3
Copy the 'Base SCIM URL' and 'SCIM API key' that Lovable provides.
These are the secret codes your company's identity system needs to talk to Lovable securely.
- 4
Go to your company's identity system (like Okta or Microsoft Entra ID) and find the Lovable application's provisioning settings.
You need to tell your identity system how to connect to Lovable using the codes you just copied.
- 5
Enter the 'Base SCIM URL' and 'SCIM API key' into your identity system's provisioning settings, and enable actions like 'Create Users', 'Update User Attributes', and 'Deactivate Users'.
This completes the connection, allowing your identity system to automatically manage users in Lovable.
- 6
Assign users or groups to the Lovable application in your company's identity system, and push the groups you mapped in Lovable.
This tells your identity system which specific users and groups should be managed in Lovable, activating the automatic provisioning.
Paste this into your project
Hey Lovable, I need to set up SCIM user provisioning. I've got my SSO ready and domains verified. Can you guide me through enabling SCIM, setting up group mappings for Admin, Editor, and Viewer roles, and then give me the Base SCIM URL and API key to configure in my Identity Provider? I want to make sure I copy the API key correctly.
Words decoded
- SCIM
- A standard way for different computer systems to talk to each other about user information, like creating accounts or changing roles.
- Identity Provider (IdP)
- A system that stores and manages user identities, like Okta or Microsoft Entra ID, which your company uses to log into various services.
- Provisioning
- The automatic process of creating, updating, and removing user accounts and their access rights across different software systems.
- SSO (Single Sign-On)
- A way for users to log in once to one system and then access multiple other systems without needing to log in again for each one.
- Bearer Token
- A type of security key, like a digital ticket, that grants access to a system when presented.
- OIDC (OpenID Connect)
- A modern standard for verifying a user's identity, often used with SSO.
- SAML (Security Assertion Markup Language)
- An older but still common standard for exchanging authentication and authorization data, often used with SSO.
Where people get stuck
- Forgetting to copy the API key immediately after it's generated, as it's only shown once.
- Not having an active Single Sign-On (SSO) provider set up before trying to enable SCIM.
- Not having admin access to your company's Identity Provider (IdP) or the correct role in Lovable (Workspace owner or admin).
- Not verifying your email domain in Lovable, as SCIM only provisions users from verified domains.
- Entering group names incorrectly (e.g., wrong capitalization or punctuation) in Lovable, as matching is case-sensitive.
- Not updating your Identity Provider with a new API key immediately after rotating it in Lovable, which will break provisioning.
- Mapping a group to the 'Owner' role without understanding that all members of that group will become owners, and the current owner's role might change.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.