Automated User Provisioning (SCIM)

This page is not available in the language you requested. You have been redirected to the English version of the page.
Link to this page copied to clipboard
Not for use with personal data

Automated User Provisioning (SCIM)

axe Account supports SCIM 2.0 (System for Cross-domain Identity Management), the industry-standard protocol for automating user provisioning. With SCIM, manage axe access directly from your identity provider — such as Okta, Microsoft Entra ID, or any SCIM 2.0-compliant identity provider — instead of manually in the axe Account Portal. Users are provisioned and deprovisioned automatically based on identity provider group membership.

What SCIM does for your organization

  • Automated provisioning — New users receive an axe account and product access automatically, based on their group membership in your identity provider.
  • Reliable offboarding — When a user is removed from your identity provider, their axe access is revoked immediately, closing security gaps and freeing up seats.
  • Access that stays in sync — Team and product-access changes in your identity provider flow through to axe, keeping entitlements accurate as people and roles change.
  • Centralized governance — Your directory becomes the single source of truth for who has access to which axe products, with a consistent, auditable record.

Supported identity providers

axe implements the SCIM 2.0 standard and works with Okta, Microsoft Entra ID (formerly Azure AD) or any SCIM 2.0-compliant identity provider.

Supported Deque products

SCIM provisioning is supported and tested for the following products:

  • Axe DevTools for Web
  • Axe Monitor
  • Axe Reports
  • Axe Auditor

Your identity provider may also see groups for other subscriptions your enterprise holds, such as Deque University or integration subscriptions. Assigning users to those groups through SCIM is not supported — manage them in the axe Account Portal instead.

Prerequisites at a glance

To use SCIM, your enterprise needs:

  1. A SCIM subscription on your axe Account enterprise.
  2. Single Sign-On (SSO) configured for your organization's email domain.
  3. A SCIM API key, generated in the axe Account Portal.

See Prerequisites & Setup to get started.

In this section