A Python library that serves the SCIM protocol over any storage, built upon scim2-models, following the RFC7643 and RFC7644 specifications. It validates the requests, applies them to the resources and builds the responses. The application only reads and writes the resources.
It comes with an in-memory storage, WSGI and ASGI applications with no dependency, and a
scim2-server command that serves a test server.
scim2-server is for projects that need to:
- serve a standalone SCIM server;
- add SCIM to an existing application, with SCIM models that describe its data;
- test a SCIM client against a working server, from the
scim2-servercommand, a container, or the pytest-scim2-server fixture.
SCIM stands for System for Cross-domain Identity Management, and it is a provisioning protocol. Provisioning is the action of managing a set of resources across different services, usually users and groups. SCIM is often used between Identity Providers and applications in completion of standards like OAuth2 and OpenID Connect. It allows users and groups creations, modifications and deletions to be synchronized between applications.
- Resources: creation, read, replacement, PATCH and deletion
- Search: filters, sorting, paging and attribute selection, on a resource type or at the root
- Bulk requests: with
bulkIdreferences andfailOnErrors - ETags: conditional requests and protection against concurrent writes
- Discovery:
ServiceProviderConfig,ResourceTypesandSchemas - Storages: an interface to implement, an in-memory storage, and a test suite that checks a storage
- Sync & Async: a synchronous and an asynchronous handler, over the same rules
- Multi-tenancy: one set of resources per URL prefix
pip install scim2-serverServe a test server from the command line:
scim2-server --port 8080Or build the WSGI application in Python:
from scim2_server.applications.wsgi import WSGIApplication
from scim2_server.memory import InMemoryStorage
from scim2_server.utils import load_default_provider
app = WSGIApplication(InMemoryStorage(), load_default_provider())A container image is published on the GitHub container registry for each release:
docker run --publish 8080:8080 ghcr.io/python-scim/scim2-server --bearer-token secretThe server has been tested against a live Microsoft Entra system and a live Okta system.
- Overview introduces the parts of a SCIM server, from the description of the service to the test server.
- How-to guides cover focused tasks, such as writing a storage or integrating a web framework.
- Explanation covers the layers of the server, the writes of resources and the bulk requests.
- Reference lists the public API
and the options of the
scim2-servercommand.
The contribution page describes how to run the tests, the style checks and the documentation build.
scim2-server belongs in a collection of SCIM tools developed by Yaal Coop, with scim2-models, scim2-client, scim2-tester and scim2-cli.
Parts of this software were initially developed at CONTACT Software (GitHub) and subsequently made available under the Apache License Version 2.0.