Before you begin
Ask your Sela contact for:- Your SCIM Base URL
- Your SCIM Bearer Token
Configure SCIM
1
Add the SCIM application
In Okta Admin:
- Open Applications → Browse App Catalog.
- Search for (OAuth Bearer Token) Governance with SCIM 2.0.
- Select the application and click Add Integration.
- Set Application label to
Sela SCIM. - Enable Do not display application icon to users.
- Disable Browser plugin auto-submit.
- Click Next, then Done.
2
Connect Okta to Sela
Open the new Sela SCIM application, then:
- Open Provisioning → Integration.
- Click Configure API Integration.
- Enable API Integration.
- Enter the SCIM 2.0 Base URL provided by Sela.
- Enter the OAuth Bearer Token provided by Sela.
- Click Test API Credentials.
- After Okta reports a successful connection, click Save.
3
Enable user provisioning
Open Provisioning → To App, click Edit, and configure:
- Create Users: enabled
- Update User Attributes: enabled
- Deactivate Users: enabled
- Sync Password: disabled
- Set password when creating new users: disabled
4
Keep only required mappings
Under Provisioning → To App → Attribute Mappings, keep the mappings that
send these required values:
- User name
- First name
- Last name
- Primary email
- Primary email type
- Primary phone type
- Address type
5
Assign users and groups
Open the Assignments tab and assign the people or groups that Okta should
provision into Sela.Users who need to sign in must also be assigned to the separate Sela SSO
application. Assigning a group to the SCIM application provisions its users,
but does not push the group object itself.
6
Push groups
To provision group objects and memberships:
- Open the Push Groups tab.
- Select Push Groups → Find groups by name.
- Choose the group to send to Sela.
- Confirm the match and click Save.
- Repeat for each group Sela should receive.
Verify the integration
Start with one test user and one test group before assigning production users:- Assign the test user to the Sela SCIM application.
- Confirm the assignment reaches a provisioned state in Okta.
- Ask your Sela contact to confirm that the user and pushed group arrived.
- Update the user’s first or last name and confirm the update is synchronized.
- Unassign the user and confirm that the user is deactivated in Sela.