Skip to main content

Limitation of SCIM in Vendasta

The SCIM implementation in Vendasta has few limitations which align with our business needs. In this article we will discuss these limitations in more detail.

Namespace scoping​

Every SCIM path operates in the namespace in the URL, your partner id. You manage the users you create there and the users you grant access to.

  • GET, PUT, PATCH and DELETE on any other user return 404. A user-search lookup by userName or externalId returns an empty list for that user.
  • A user's groups lists the roles they hold in your namespace.
  • active reports whether the user is one of yours. It is not a global enabled/disabled flag and cannot be set through SCIM.
  • DELETE tears down the user's roles and the records behind them. It is permanent, not a temporary deactivation, and afterwards every operation on that id returns 404.

Users resources​

userName must be an email address. It is the user's email — there is no separate login name. A userName that is not an email address does not produce a specific validation message; the request fails with a generic 400 ("Failed to create user…") that does not name userName as the cause.

The emails array is not used on write. A user has exactly one email address and it is always taken from userName. Anything in emails on a POST or PUT is ignored — including a different address, or one marked "primary": true. Note that the 201 response to a create echoes the emails you sent rather than what was stored, so it can disagree with a subsequent GET; the GET is authoritative.

A user has one address. If several addresses are provided, the last entry with type work is used. If no entry has type work, the first entry in the array is used regardless of its type.

The accepted addresses[].country is ISO 3166-1 alpha-2. Example: CA

The accepted addresses[].region comprises of ISO 3166-1 alpha-2 of both country code and state code. Example: CA-SK

The phoneNumbers[].value should match the region/country given in address. Example: +1-306-555-1234

Replace User (PUT) is a full replace of the profile only: a profile attribute your request omits is cleared. Roles and group membership are preserved, and userName / emails cannot be changed. externalId is also taken from the body alone, so a PUT that omits it clears the stored mapping — always send it.

Here is a list of supported/not-supported operations under Users resources

OperationSupported
Search UsersYes
Create UserYes
Get UserYes
Replace UserYes
Update UserYes
Delete UserYes
info

Filter for searching users are limited to userName and externalId. However if no filter is specified it will list down all users.

Groups resources​

Groups in Vendasta are predefined according to business needs. Groups can't be created or deleted. Also Groups name can not be updated through SCIM. In terms of Group update members can be added to a Group or deleted from a Group.

We do support id as a unique identifier of a group and displayName for human readable names.

Group reads never include membership: members is not returned by Search Groups or Get Groups. Read a user to see the groups they belong to.

For more information on Groups in Vendasta please see the SCIM Groups and their assignment to users section.

Here is a list of supported/not-supported operations under Groups resources

OperationSupported
Search GroupsYes
Create GroupsNo
Get GroupsYes
Replace GroupsNo
Update GroupYes
Delete GroupNo
info

Search criteria is limited to displayName eq "..." and type eq "platformFeature".

info

Update of groups are limited to adding or removing members through patch requests.