Configure Okta SAML first so provisioned users can sign in. SCIM manages workspace membership; SAML handles authentication.
Prerequisites
- Okta admin access
- Antsfield workspace owner role
- Enterprise plan with SCIM enabled
- SAML SSO configured (recommended)
Set up Okta SCIM
1
Open Antsfield SCIM settings
In Antsfield, go to Settings → Security and open SCIM configuration. Generate or copy your:
- SCIM endpoint URL
- Bearer token (shown once — store in a secrets manager)
2
Enable provisioning in Okta
In the Okta Admin Console, open your Antsfield SAML application.Go to the Provisioning tab and click Configure API Integration. Enable provisioning and enter the Antsfield SCIM base URL and bearer token.
3
Configure provisioning settings
Under Provisioning → To App, enable:
- Create Users
- Update User Attributes
- Deactivate Users
4
Assign users or groups
Assign the Antsfield app to Okta users or groups. Okta pushes create, update, and deactivate events to Antsfield via SCIM.
5
Verify provisioning
- Assign a test user in Okta.
- Confirm they appear under Settings → Members in Antsfield.
- Deactivate the test user in Okta and confirm they lose workspace access.

