Both are managed from Security → Users Sync.
The Security area is available to users with the IT Admin role. Admins can open Users Sync and copy the SCIM details, but only IT Admins can edit the SCIM fields mapping.
HR directory sync
Juno connects directly to your HR system’s API, reads your people data, and creates, updates, or deactivates Juno accounts to match.Supported HR systems
For HiBob, BambooHR, Google Workspace, Oracle HCM, and custom connectors, Juno Support can also read extra fields beyond the defaults.
How it’s set up
HR directory sync is configured by Juno Support — there’s no self-serve setup screen. To get started, contact your Juno account team. You’ll typically be asked for:- API credentials for your HR system (for example, an API token or OAuth client), or SFTP connection details and the file path
- Which HR fields should map to which Juno fields — such as email, name, department, job title, manager, and hire date
What to expect
- Daily sync. Juno reads your HR system once a day, early morning UTC, and then applies the changes to Juno accounts.
- Matching. Juno matches people to existing accounts by email by default. People with no email aren’t synced.
- New hires get a new Juno account automatically.
- Changes to names, departments, job titles, managers, and other mapped fields update the existing account.
- Leavers are deactivated, not deleted. People who are marked inactive in your HR system, or who no longer appear in it, are deactivated in Juno.
- Safety check. If more than 20% of your synced people would drop out of the HR data at once, Juno skips that deactivation run so a broken HR export can’t lock everyone out.
SCIM 2.0 provisioning
With SCIM, your identity provider creates, updates, and deactivates Juno users as soon as you make the change there. Juno works as a standard SCIM 2.0 service provider using bearer-token authentication.Set up SCIM
1
Copy your SCIM details from Juno
Go to Security → Users Sync. Under SCIM Provisioning Parameters:, copy the SCIM URL and the SCIM Token. The URL is unique to your organization and looks like
https://scim.the-juno.com/api/v1/scim/v2/<your-organization-id>.2
Add a SCIM provisioning app in your identity provider
In Okta, Microsoft Entra ID, or another SCIM 2.0 identity provider, create or open the app you use for Juno and turn on SCIM provisioning.
3
Paste the URL and token
Paste the SCIM URL as the SCIM base URL and the SCIM Token as the bearer token (API token). Test the connection from your identity provider.
4
Assign users and push
Assign the people who should have Juno accounts to the app, then start provisioning. They appear in Juno as the identity provider sends them.
5
Check and adjust the fields mapping
Back in Users Sync, review SCIM Fields Mapping: and select Edit to change how SCIM attributes map to Juno fields. See Map SCIM attributes.
What SCIM supports
Juno supports the SCIM
/Users resource (create, read, update with PUT or PATCH, and delete) and simple filters (eq, combined with and). Group provisioning and bulk operations aren’t supported — Groups requests return an empty list.
Map SCIM attributes
Selecting Edit opens a four-step wizard:- Review recent data. See the raw data of the 100 most recently updated SCIM users, so you know which attributes your identity provider actually sends.
- Map your data to Juno’s fields. Pick a Juno field for each SCIM attribute — for example First Name, Last Name, Full Name, Email, Employee ID, Department, Job Title, Location, Employee Type, or Hire/Start Date. Your organization’s custom attributes are listed too. The username and email attributes can’t be changed.
- Confirm. Review the differences between the current and new mapping.
- Apply. Select Apply new Fields Mapping. Juno saves the mapping, re-applies it to all existing SCIM users, and updates managers and the organization chart when manager fields changed.

