SCIM with Google Workspace

Why automated SCIM provisioning from Google Workspace to Stallion is not possible, and what to use for membership and offboarding instead.

SCIM with Google Workspace

Google Workspace cannot provision to Stallion over SCIM. This is a limit of Google Workspace, not of Stallion's SCIM endpoint, which is standard SCIM 2.0 with no provider-specific configuration.

Google sign-in is unaffected:

This page is only about provisioning. Signing in to Stallion with Google is fully supported — see Google OIDC.

Why not

Google's automated user provisioning targets pre-integrated catalog apps only — roughly 80 named applications, each with its own configuration page in the Admin console and its endpoint and attribute mapping already built in. There is no screen anywhere in Google Workspace for entering your own SCIM base URL and bearer token.

The path Google offers for an app that is not in its catalog is Set up your own custom SAML app, and that flow is SSO and nothing else: ACS URL, Entity ID, attribute mapping, group mapping into the SAML assertion. No provisioning step exists in it.

So unlike Microsoft Entra — where a non-gallery application exists precisely so an admin can point at an arbitrary SCIM endpoint — there is nowhere to put Stallion's URL, however compliant the endpoint is.

Stallion is not in Google's catalog.

What to use instead

Google sign-in, manual membership

Keep Google OIDC for authentication, so password policy, MFA and session control stay with Google. Manage membership in Members in the Stallion console: invite people, set roles, remove them when they leave.

Offboarding is not automatic:

Suspending someone in Google Workspace stops them signing in, but their Stallion membership and any active session survive until a human removes them in the console. Sessions last 30 days. If automatic offboarding is what you need from SCIM, this option does not give it to you.

A different provider for provisioning

Stallion's SCIM endpoint is generic, so any provider that can push to a custom SCIM URL will work — and it does not have to be the provider you use to sign in. SCIM authenticates on its own bearer token and has no relationship to your OIDC connection.

Plenty of organizations run Google Workspace for mail and calendar while identity lives elsewhere. If that is you:

  • Microsoft Entra ID — documented and tested
  • Okta, JumpCloud, OneLogin, Ping — standard SCIM 2.0 against the same endpoint; not documented here yet, so get in touch and we will walk you through it

If this changes

Getting listed in Google's catalog is an onboarding process with Google, not a change to our code — the endpoint already exists and already speaks the protocol Google's connectors use. If Google Workspace provisioning matters to your rollout, tell us before you commit to a plan; demand is what decides whether we pursue the listing.