Skip to content

API integration

This page contains an overview of the details required to communicate with Digidentity's SCIM API.

Endpoints

Most SCIM applications

Customers using SCIM applications other than Microsoft Entra ID can use the following endpoints:

  • Pre-production: https://gate.digidentity-preproduction.eu/api/v2/scim/
  • Production: https://gate.digidentity.eu/api/v2/scim/

Microsoft Entra ID

Customers making use of MS Entra ID must use the following endpoints instead:

  • Pre-production: https://gate.digidentity-preproduction.eu/api/v2/scim/?aadOptscim062020
  • Production: https://gate.digidentity.eu/api/v2/scim/?aadOptscim062020

Authentication

Most SCIM applications

Where possible, Digidentity advises use of OAuth2 client credentials authentication for SCIM implementations. Credentials for authentication (OAuth2 client ID, secret, and scope) will be provided by Digidentity's Implementation team during onboarding.

Microsoft Entra ID

As MS Entra ID does not support client credentials authentication, customers using this application must connect using bearer token authentication. This requires customers to retrieve an access token from Digidentity's backend (rather than configuring their OAuth2 client ID and secret in the SCIM application directly).

Access tokens can be retrieved programmatically via an HTTP request to Digidentity's backend. For more information, please see our API specification.

Security best practices

Keeping your OAuth client credentials and access tokens secret is vital to the security of your application.

  1. Keep your credentials secure:
    • Do not expose your credentials in URLs, public repositories, or logs.
    • Do not share your credentials via email, screen-share, or any other unsecured method.
    • Store your credentials in a trust store or secure environment variable (where applicable).
  2. Use HTTPS to prevent interception of your credentials.
  3. Report compromised credentials immediately by contacting Digidentity.