ezgh iam scim tokens create <name>Create a SCIM token for your identity provider (Okta, Microsoft Entra ID…). The token is printed once, on stdout, and can’t be shown again; give it to the identity provider with the base URL (ezgh iam scim status). The first token turns SCIM provisioning on: from then on people and groups come from the directory, and hand edits to what it provisioned are refused.
People are only provisioned from domains verified on one of the organization’s SSO providers. Tokens don’t expire: to rotate, create a second, switch the identity provider to it, then delete the first.
Part of ezgh iam scim tokens.
Examples
ezgh iam scim tokens create okta > scim-token.txtFlags
This command also takes the global flags.