Limitation of SCIM in Vendasta
The SCIM implementation in Vendasta has few limitations which align with our business needs. In this article we will discuss these limitations in more detail.
Namespace scoping​
Every SCIM path operates in the namespace in the URL, your partner id. You manage the users you create there and the users you grant access to.
GET,PUT,PATCHandDELETEon any other user return404. A user-search lookup byuserNameorexternalIdreturns an empty list for that user.- A user's
groupslists the roles they hold in your namespace. activereports whether the user is one of yours. It is not a global enabled/disabled flag and cannot be set through SCIM.DELETEtears down the user's roles and the records behind them. It is permanent, not a temporary deactivation, and afterwards every operation on that id returns404.
Users resources​
userName must be an email address. It is the user's email — there is no separate login name. A userName that is not an email address does not produce a specific validation message; the request fails with a generic 400 ("Failed to create user…") that does not name userName as the cause.
The emails array is not used on write. A user has exactly one email address and it is always taken from userName. Anything in emails on a POST or PUT is ignored — including a different address, or one marked "primary": true. Note that the 201 response to a create echoes the emails you sent rather than what was stored, so it can disagree with a subsequent GET; the GET is authoritative.
A user has one address. If several addresses are provided, the last entry with type work is used. If no entry has type work, the first entry in the array is used regardless of its type.
The accepted addresses[].country is ISO 3166-1 alpha-2. Example: CA
The accepted addresses[].region comprises of ISO 3166-1 alpha-2 of both country code and state code. Example: CA-SK
The phoneNumbers[].value should match the region/country given in address. Example: +1-306-555-1234
Replace User (PUT) is a full replace of the profile only: a profile attribute your request omits is cleared. Roles and group membership are preserved, and userName / emails cannot be changed. externalId is also taken from the body alone, so a PUT that omits it clears the stored mapping — always send it.
Here is a list of supported/not-supported operations under Users resources
| Operation | Supported |
|---|---|
| Search Users | Yes |
| Create User | Yes |
| Get User | Yes |
| Replace User | Yes |
| Update User | Yes |
| Delete User | Yes |
Filter for searching users are limited to userName and externalId. However if no filter is specified it will list down all users.
Groups resources​
Groups in Vendasta are predefined according to business needs. Groups can't be created or deleted. Also Groups name can not be updated through SCIM. In terms of Group update members can be added to a Group or deleted from a Group.
We do support id as a unique identifier of a group and displayName for human readable names.
Group reads never include membership: members is not returned by Search Groups or Get Groups. Read a user to see the groups they belong to.
For more information on Groups in Vendasta please see the SCIM Groups and their assignment to users section.
Here is a list of supported/not-supported operations under Groups resources
| Operation | Supported |
|---|---|
| Search Groups | Yes |
| Create Groups | No |
| Get Groups | Yes |
| Replace Groups | No |
| Update Group | Yes |
| Delete Group | No |
Search criteria is limited to displayName eq "..." and type eq "platformFeature".
Update of groups are limited to adding or removing members through patch requests.