SCIM provisioning with Okta
Automatically provision members and roles from Okta to Pinecone over SCIM.
Instead of managing members and roles manually in Pinecone, you can have your identity provider (IdP) provision them automatically over SCIM. This page continues Configure SSO with Okta and shows how to set up SCIM provisioning with Okta. These instructions can be adapted for any provider with SCIM 2.0 support.
How it works
Section titled “How it works”When SCIM provisioning is enabled, your IdP manages organization membership and roles in Pinecone in near real time:
- As members are added, updated, or removed in Okta, those changes sync to Pinecone over SCIM in near real time, not just at login.
- Okta connects to a SCIM endpoint that Pinecone provides, authenticating with a bearer token you generate in the Pinecone console.
- Pinecone reads each member's roles from the SCIM
rolesattribute and sets their organization and project roles to exactly those values. Values that don't match a known role are ignored. For the other attributes Pinecone reads, see Supported attributes. - While SCIM is enabled, SCIM is the source of truth for roles: Pinecone no longer applies the roles in a member's SAML login assertion, even though members still sign in through SAML SSO.
- Deactivating or removing a member in Okta removes them from the organization, and clearing a member's roles revokes their access.
- Because membership and roles come entirely from your IdP, while SCIM is enabled you can no longer invite members or edit roles in the Pinecone console or through the Admin API.
Supported attributes
Section titled “Supported attributes”Pinecone reads the following SCIM user attributes and ignores all others, including emails, phoneNumbers, addresses, photos, title, and enterprise extension attributes such as department and manager.
A member needs both required attributes to get access. Okta can't provision a member without userName, and a member whose roles has no organization role has no access to the organization.
| SCIM attribute | Required | How Pinecone uses it |
|---|---|---|
userName |
Yes | The member's email address, which must match the one they use to sign in through SAML SSO. See Step 3. |
roles |
Yes | The member's organization and project roles. See Role attribute values. |
active |
No | Whether the member is active. Setting it to false removes the member from the organization. If Okta doesn't send it, Pinecone treats the member as active. |
displayName |
No | The member's name, shown in the Pinecone console. |
name.givenName |
No | The member's first name. Stored on the member's profile, but not shown in the console. |
name.familyName |
No | The member's last name. Stored on the member's profile, but not shown in the console. |
The console shows a member's displayName, or their email address if Okta doesn't send one. To show members' names in the console, keep the displayName mapping.
Role attribute values
Section titled “Role attribute values”Pinecone reads roles from the roles attribute. Each value uses one of the following formats:
- Organization role:
pinecone:<OrgRole> - Project role:
pinecone:project:<projectID>:<ProjectRole>
<projectID> is the project's unique ID. To find it, go to the project list in the Pinecone console. For more information, see Project IDs.
A user can hold multiple roles by sending multiple values in the roles attribute.
Organization roles
Section titled “Organization roles”For details on what each organization role grants, see Understanding organizations.
| Organization role | Attribute value |
|---|---|
| Organization owner | pinecone:OrgOwner |
| Organization manager | pinecone:OrgManager |
| Organization member | pinecone:OrgMember |
| Billing admin | pinecone:OrgBillingAdmin |
Project roles
Section titled “Project roles”For details on what each project role grants, see Understanding projects.
| Project role | Attribute value |
|---|---|
| Project owner | pinecone:project:<projectID>:ProjectOwner |
| Project manager | pinecone:project:<projectID>:ProjectManager |
| Project member | pinecone:project:<projectID>:ProjectMember |
| Control plane editor | pinecone:project:<projectID>:ControlPlaneEditor |
| Control plane viewer | pinecone:project:<projectID>:ControlPlaneViewer |
| Data plane editor | pinecone:project:<projectID>:DataPlaneEditor |
| Data plane viewer | pinecone:project:<projectID>:DataPlaneViewer |
For example, to make a user an organization manager who is also a project owner on one project, send these two values in the roles attribute:
pinecone:OrgManager
pinecone:project:a2f7dddb-1597-4eff-9f71-535fde243f58:ProjectOwner1. Start SCIM setup in Pinecone
Section titled “1. Start SCIM setup in Pinecone”- In the Pinecone console, go to Settings > Access > Identity provider.
- Confirm that single sign-on shows the Enforced status. If it doesn't, edit your SSO configuration to enforce SSO before continuing.
- In the User management section, select Manage roles with SCIM provisioning.
- In the Set up SCIM provisioning dialog, review the instructions and click Get started.
2. Generate a SCIM token
Section titled “2. Generate a SCIM token”- Choose the token's permissions and expiry. By default the token grants all user permissions and expires in 90 days; you can also choose Token never expires.
- Click Generate token.
- Copy the bearer token. The SCIM endpoint is shown on the next screen of the dialog. You'll add both to Okta in Step 3.
3. Connect Okta to the SCIM endpoint
Section titled “3. Connect Okta to the SCIM endpoint”-
In Okta, navigate to Applications > Pinecone > General.
-
In the App Settings section, click Edit, set Provisioning to SCIM, and click Save.
-
Open the Provisioning tab and click Configure API Integration.
-
Select Enable API Integration and enter the following:
-
Click Test API Credentials to verify the connection, then click Save.
-
Under Provisioning > To App, click Edit and enable Create Users, Update User Attributes, and Deactivate Users.
-
Still under Provisioning > To App, scroll to Pinecone Attribute Mappings and check the source for
userName. If it's set touser.loginor an Active Directory attribute, change it touser.emailand click Save.
4. Send role values to Pinecone
Section titled “4. Send role values to Pinecone”Okta doesn't send a member's Pinecone roles by default. You define one app attribute per role you want to assign, then map a value to it for the right members. Pinecone reads only each value, so the same approach scales to as many roles as you need.
-
In Okta, go to Directory > Profile Editor and open the Pinecone app profile.
-
For each role you want to assign, click Add Attribute and configure:
- Data type:
string - External name:
roles.^[type=='<label>'].value, where<label>is any unique label for the role (for example,orgOwnerorprojManager). Pinecone reads only the value, so the label is only used to keep attributes distinct in Okta. - External namespace:
urn:ietf:params:scim:schemas:core:2.0:User
- Data type:
-
Go to Provisioning > To App > Pinecone Attribute Mappings (or Mappings in the Profile Editor) and map each attribute to the role value for the members who should hold it. Set the mapping to apply on create and update. Source the value however you manage users, for example:
- From a custom user profile attribute that holds the
pinecone:*value. - From group membership with an expression such as
isMemberOfGroupName('Pinecone Owners') ? 'pinecone:OrgOwner' : ''.
- From a custom user profile attribute that holds the
-
Click Preview for a representative user and confirm the
rolesattribute resolves to the expectedpinecone:*values (includingpinecone:OrgOwnerfor a current owner).
For example, an organization manager who is also a project owner on one project needs two attributes: one mapped to pinecone:OrgManager and one mapped to pinecone:project:<projectID>:ProjectOwner. Project values include the project's unique ID, not its name.
5. Provision members and verify
Section titled “5. Provision members and verify”- Assign your members to the Pinecone app in Okta so it pushes them over SCIM. For members who were already assigned, use Provisioning > To App > Force Sync or Apply updates now so their attributes resync.
- Confirm the members and roles arrived. In Okta, check Reports > System Log (or the app's provisioning activity) for SCIM errors if members don't appear.
- Verify that at least one current Pinecone organization owner was provisioned with
pinecone:OrgOwner.
6. Enable SCIM in Pinecone
Section titled “6. Enable SCIM in Pinecone”- Back in the Pinecone Set up SCIM provisioning dialog, click Enable SCIM. Pinecone verifies that an organization owner has been provisioned with
pinecone:OrgOwnerbefore activating. - If Pinecone blocks activation because no owner is provisioned, return to Okta, assign
pinecone:OrgOwnerto a current owner (see Step 4), let it sync, and click Enable SCIM again.
Once enabled, your IdP is the source of truth for membership and roles. Members and their roles sync automatically as you provision them in Okta.
To rotate or revoke tokens or view the SCIM endpoint, select Manage next to the SCIM option. To stop provisioning, select Manage roles in Pinecone (or Disable SCIM from the Manage dialog), which revokes all SCIM tokens and reverts to manual role management. Existing role assignments are preserved until you change them.