sondahub / SCIM 2.0 test server
SCIM 2.0 test server
A whole company to provision against: 300 people in 40 groups, served over SCIM 2.0 with the full filter language, PATCH as Okta and Entra send it, Bulk with references, ETags and discovery — and errors in SCIM's own shape. Free, public token.
Connect
- Base URL
- https://api.sondahub.com/scim/v2
- Auth
- Authorization: Bearer sonda-scim-token
- Or
- an access token from the OAuth server
- Users
- 300, userName is the login (clara.brown)
- Groups
- 40: departments, teams, roles, offices
curl https://api.sondahub.com/scim/v2/ServiceProviderConfig
Endpoints
uniqueness for a userName that is taken.If-Match is honoured: a stale ETag answers 412.active: false.bulkId references between them and failOnErrors./Schemas: discovery, open to everyone.Try it
curl -H "Authorization: Bearer sonda-scim-token" \ "https://api.sondahub.com/scim/v2/Users?filter=title%20co%20%22Engineer%22%20and%20name.givenName%20sw%20%22A%22&attributes=userName,title"
curl -X POST https://api.sondahub.com/scim/v2/Users \
-H "Authorization: Bearer sonda-scim-token" \
-H "Content-Type: application/scim+json" \
-d '{"schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],"userName":"ada.lovelace","name":{"givenName":"Ada","familyName":"Lovelace"},"emails":[{"value":"[email protected]","type":"work","primary":true}],"active":true}'
curl -H "Authorization: Bearer sonda-scim-token" -H "X-Sondahub-Session: $TOKEN" \ "https://api.sondahub.com/scim/v2/Users?filter=userName%20eq%20%22ada.lovelace%22"
curl -X PATCH https://api.sondahub.com/scim/v2/Users/2 \
-H "Authorization: Bearer sonda-scim-token" \
-H "Content-Type: application/scim+json" \
-d '{"schemas":["urn:ietf:params:scim:api:messages:2.0:PatchOp"],"Operations":[{"op":"replace","path":"active","value":false}]}'
curl -X PATCH https://api.sondahub.com/scim/v2/Groups/12 \
-H "Authorization: Bearer sonda-scim-token" \
-H "Content-Type: application/scim+json" \
-d '{"schemas":["urn:ietf:params:scim:api:messages:2.0:PatchOp"],"Operations":[{"op":"add","path":"members","value":[{"value":"2"}]}]}'
Writes keep to the session like everywhere else, with the directory's rules: a userName exists once, a person is in a group once. The same people are on the Identity REST API, and they sign in over SAML and OIDC.
Questions
Can I connect Okta or Microsoft Entra ID to it?
Yes, as a SCIM 2.0 app with the base URL above and the bearer token — Okta's “SCIM connector base URL” and Entra's “Tenant URL” and “Secret Token”. Connection tests, user lookups and imports are answered from the directory. One thing to know: an IdP's provisioning engine will not carry a session token, so each of its calls sees the seed directory — a user it creates is answered right but not there on its next call. Drive SCIM from your own tests, carrying the token, for a stateful run.
Which filters work?
The whole RFC 7644 filter language: eq ne co sw ew gt ge lt le pr, and, or, not, parentheses, and value paths like emails[type eq "work" and value co "@orbit"] — on any attribute, with sortBy, sortOrder, startIndex, count (up to 200), attributes and excludedAttributes.
Does PATCH accept what Okta and Entra send?
Yes: add, replace and remove with or without a path, value paths, members[value eq "…"] removals, Entra's capitalised ops and string booleans, and Okta's whole-object replaces. Each PATCH answers the resource as it now is.
How do I get /Me?
With an access token for a person instead of the SCIM token: the password grant on the OAuth server as clara.brown / probe, say. /Me then answers that user.