Skip to main content
Directory sync uses SCIM 2.0 to let your identity provider control who has Sidekick login access, so access follows what you manage in your provider instead of a separate manual step in Sidekick.
SCIM controls login access for people already on the roster. It does not create or manage the employee roster itself. Add people through People first; SCIM then grants or revokes their ability to sign in.

Enable directory sync

1

Open Directory sync

Go to Settings → Sidekick → Auth and open the directory sync section.
2

Turn it on

Enabling directory sync generates a one-time bearer token and a SCIM base URL.
3

Copy the token and base URL

Copy both immediately. The token is shown once; if you navigate away without copying it, you’ll need to rotate it to see a new one.
4

Configure your identity provider

In your identity provider, add a SCIM connection using the base URL and bearer token from Sidekick.

What SCIM does

Once connected, your identity provider grants and revokes Sidekick login access for people who already exist on the roster. Adding someone to the connected group in your provider grants them access; removing them revokes it.

What SCIM does not do

SCIM does not write the employee roster. It doesn’t add new people to Oximy or change their department, title, or other roster details. Managing who exists on the roster still happens through People.

Rotate or disable

  • Rotate the token if it’s been exposed or you’re rolling it as routine hygiene. Rotating invalidates the old token immediately, so update your identity provider’s configuration with the new one right away.
  • Disable directory sync to stop your identity provider from controlling Sidekick access. People keep whatever access they held at the moment sync was disabled, until changed manually.

Where to go next

SSO

Connect Sidekick to your identity provider so people sign in with company credentials.