SCIM controls login access for people already on the roster. It does not create or manage the employee roster itself. Add people through People first; SCIM then grants or revokes their ability to sign in.
Enable directory sync
1
Open Directory sync
Go to Settings → Sidekick → Auth and open the directory sync section.
2
Turn it on
Enabling directory sync generates a one-time bearer token and a SCIM base URL.
3
Copy the token and base URL
Copy both immediately. The token is shown once; if you navigate away without copying it, you’ll need to rotate it to see a new one.
4
Configure your identity provider
In your identity provider, add a SCIM connection using the base URL and bearer token from Sidekick.
What SCIM does
Once connected, your identity provider grants and revokes Sidekick login access for people who already exist on the roster. Adding someone to the connected group in your provider grants them access; removing them revokes it.What SCIM does not do
SCIM does not write the employee roster. It doesn’t add new people to Oximy or change their department, title, or other roster details. Managing who exists on the roster still happens through People.Rotate or disable
- Rotate the token if it’s been exposed or you’re rolling it as routine hygiene. Rotating invalidates the old token immediately, so update your identity provider’s configuration with the new one right away.
- Disable directory sync to stop your identity provider from controlling Sidekick access. People keep whatever access they held at the moment sync was disabled, until changed manually.
Where to go next
SSO
Connect Sidekick to your identity provider so people sign in with company credentials.