---
title: "ezgh iam scim tokens create"
description: "Create a SCIM token for your identity provider; the token is shown once."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ezgh iam scim tokens create

{/* Generated by ezgh-cli's internal/tools/clidocs from the ezgh command tree. Don't edit: change the command's help in ezgh-cli and regenerate. */}

```sh
ezgh iam scim tokens create <name>
```

Create a SCIM token for your identity provider (Okta, Microsoft Entra ID…). The token is printed once, on stdout, and can't be shown again; give it to the identity provider with the base URL (`ezgh iam scim status`). The first token turns SCIM provisioning on: from then on people and groups come from the directory, and hand edits to what it provisioned are refused.

People are only provisioned from domains verified on one of the organization's SSO providers. Tokens don't expire: to rotate, create a second, switch the identity provider to it, then delete the first.

Part of [`ezgh iam scim tokens`](/cli/reference/iam-scim-tokens).

## Examples

```sh
ezgh iam scim tokens create okta > scim-token.txt
```

## Flags

This command also takes the [global flags](/cli/reference#global-flags).

Source: https://docs.ezghcloud.com/cli/reference/iam-scim-tokens-create/index.mdx
