Before you start
Make sure you have:- SAML SSO enabled for your CodeRabbit Enterprise workspace
- An identity provider app for CodeRabbit, such as Okta or Microsoft Entra ID
- A CodeRabbit workspace admin role
- Admin access to your identity provider’s SCIM or directory sync settings
How SCIM affects access and licenses
SCIM controls workspace directory membership. Seat assignment is managed separately in Workspace Team Management according to the workspace’s seat assignment mode. Deprovisioning removes the member’s active workspace membership. Review seat assignment separately in Workspace Team Management when access changes.Setup flow
1
Open SCIM Settings
In CodeRabbit, open Workspace Settings > SCIM Settings. The page lists the Enterprise SSO connections for the selected workspace.
2
Activate SCIM
Find the SSO connection you want to synchronize and select Activate SCIM.
3
Copy the endpoint and token
Copy the SCIM endpoint URL and SCIM bearer token into your identity provider’s provisioning settings. The token is shown only once. If you close it before saving it, select Regenerate token to create a replacement.
4
Enable provisioning in your identity provider
Enable SCIM provisioning for the CodeRabbit application, then assign the users and groups that should become members of the CodeRabbit workspace.
5
Validate provisioning
Confirm that assigned users appear in Workspace Team Management. Update a test user in your identity provider and verify that the change reaches CodeRabbit before rolling out SCIM to the full group.
Map groups to the Admin role
After SCIM is active and your identity provider has pushed its groups, use Group role mapping on the connection card to map a SCIM group to the CodeRabbit Admin role. CodeRabbit currently supports SCIM group mapping for the Admin role only. If you add more than one mapping, their order controls precedence. The topmost matching group wins for members who belong to multiple mapped groups.Manage the connection
- Select Regenerate token when the current token is lost or compromised, then replace the token in your identity provider.
- Select Deactivate to stop provisioning and invalidate the current token. Provisioning remains off until you activate SCIM again.
What’s next
Enterprise SSO overview
Review Enterprise SSO providers, workspace roles, and setup guidance.
Seat assignment
Configure automatic or manual seat assignment for workspace members.
Roles and permissions
Review how workspace roles, organization roles, and custom permissions work with provisioned users.