sondahub

sondahub / SCIM 2.0 test server

SCIM 2.0 test server

A whole company to provision against: 300 people in 40 groups, served over SCIM 2.0 with the full filter language, PATCH as Okta and Entra send it, Bulk with references, ETags and discovery — and errors in SCIM's own shape. Free, public token.

Connect

Base URL
https://api.sondahub.com/scim/v2
Auth
Authorization: Bearer sonda-scim-token
Or
an access token from the OAuth server
Users
300, userName is the login (clara.brown)
Groups
40: departments, teams, roles, offices
What the server supports (no auth needed)
curl https://api.sondahub.com/scim/v2/ServiceProviderConfig

Endpoints

GET/scim/v2/UsersA page of users: filter, sortBy, sortOrder, startIndex, count, attributes, excludedAttributes.
POST/scim/v2/UsersCreate a user: 201 with Location and ETag; 409 uniqueness for a userName that is taken.
GET/scim/v2/Users/{id}One user, enterprise extension included (department, employeeNumber, manager).
PUT/scim/v2/Users/{id}Replace. If-Match is honoured: a stale ETag answers 412.
PATCH/scim/v2/Users/{id}PatchOp: add, replace, remove — deactivate with active: false.
DELETE/scim/v2/Users/{id}204.
GET/scim/v2/GroupsGroups with their members; the same verbs as Users. PATCH members to add and remove people.
POST/scim/v2/Users/.searchA SearchRequest in the body instead of the query (also /Groups/.search and /.search).
POST/scim/v2/BulkUp to 100 operations, with bulkId references between them and failOnErrors.
GET/scim/v2/MeThe person an OAuth access token belongs to.
GET/scim/v2/ResourceTypesAnd /Schemas: discovery, open to everyone.

Try it

The examples on this page share one session: run them in order and each sees what the one before it wrote.
Engineers whose name starts with “a”
curl -H "Authorization: Bearer sonda-scim-token" \
  "https://api.sondahub.com/scim/v2/Users?filter=title%20co%20%22Engineer%22%20and%20name.givenName%20sw%20%22A%22&attributes=userName,title"
Provision a user
curl -X POST https://api.sondahub.com/scim/v2/Users \
  -H "Authorization: Bearer sonda-scim-token" \
  -H "Content-Type: application/scim+json" \
  -d '{"schemas":["urn:ietf:params:scim:schemas:core:2.0:User"],"userName":"ada.lovelace","name":{"givenName":"Ada","familyName":"Lovelace"},"emails":[{"value":"[email protected]","type":"work","primary":true}],"active":true}'
Find them again
curl -H "Authorization: Bearer sonda-scim-token" -H "X-Sondahub-Session: $TOKEN" \
  "https://api.sondahub.com/scim/v2/Users?filter=userName%20eq%20%22ada.lovelace%22"
Deactivate user 2
curl -X PATCH https://api.sondahub.com/scim/v2/Users/2 \
  -H "Authorization: Bearer sonda-scim-token" \
  -H "Content-Type: application/scim+json" \
  -d '{"schemas":["urn:ietf:params:scim:api:messages:2.0:PatchOp"],"Operations":[{"op":"replace","path":"active","value":false}]}'
Add user 2 to the Platform Team (group 12)
curl -X PATCH https://api.sondahub.com/scim/v2/Groups/12 \
  -H "Authorization: Bearer sonda-scim-token" \
  -H "Content-Type: application/scim+json" \
  -d '{"schemas":["urn:ietf:params:scim:api:messages:2.0:PatchOp"],"Operations":[{"op":"add","path":"members","value":[{"value":"2"}]}]}'

Writes keep to the session like everywhere else, with the directory's rules: a userName exists once, a person is in a group once. The same people are on the Identity REST API, and they sign in over SAML and OIDC.

Questions

Can I connect Okta or Microsoft Entra ID to it?

Yes, as a SCIM 2.0 app with the base URL above and the bearer token — Okta's “SCIM connector base URL” and Entra's “Tenant URL” and “Secret Token”. Connection tests, user lookups and imports are answered from the directory. One thing to know: an IdP's provisioning engine will not carry a session token, so each of its calls sees the seed directory — a user it creates is answered right but not there on its next call. Drive SCIM from your own tests, carrying the token, for a stateful run.

Which filters work?

The whole RFC 7644 filter language: eq ne co sw ew gt ge lt le pr, and, or, not, parentheses, and value paths like emails[type eq "work" and value co "@orbit"] — on any attribute, with sortBy, sortOrder, startIndex, count (up to 200), attributes and excludedAttributes.

Does PATCH accept what Okta and Entra send?

Yes: add, replace and remove with or without a path, value paths, members[value eq "…"] removals, Entra's capitalised ops and string booleans, and Okta's whole-object replaces. Each PATCH answers the resource as it now is.

How do I get /Me?

With an access token for a person instead of the SCIM token: the password grant on the OAuth server as clara.brown / probe, say. /Me then answers that user.