SCIM provisioning uses a connector URL and token generated in Insomnia. The token authorizes your identity provider to provision users and teams.
Administrators can view the current SCIM token status in Insomnia:
- From the Insomnia Enterprise control dashboard sidebar, click SCIM.
- Review the SCIM configuration page to see:
- If SCIM is enabled.
- If the token is valid, expiring soon, or expired.
When a token is close to expiration and cannot be refreshed automatically, Insomnia displays a warning message on the SCIM page and sends email notifications starting 20 days before the token expires.
Insomnia automatically attempts to refresh the SCIM connector token every 90 days, before it expires. This helps prevent provisioning interruptions that are caused by routine token expiration and reduces the need for manual maintenance. If the automatic refresh succeeds, SCIM provisioning continues without interruption.
Warning: If the automatic refresh fails, SCIM effectively breaks. Account owners must manually refresh the token to continue SCIM provisioning. Insomnia will warn the account owner and co-owners that the refresh failed.
If the token isn’t refreshed after it expires, then the following happen:
- New users aren’t provisioned from the identity provider.
- Users deactivated in the identity provider aren’t removed from Insomnia.
If the token refresh fails, you must manually refresh the token from the SCIM settings:
- In the Insomnia web app, navigate to Enterprise Controls > SCIM.
- Select Refresh Token.
- Enter your passphrase to generate a new token.
- In your identity provider, update the token.