> ## Documentation Index
> Fetch the complete documentation index at: https://docs.junojourney.com/llms.txt
> Use this file to discover all available pages before exploring further.

# User sync and SCIM

> Keep Juno user accounts in sync with your HR system or identity provider — daily HRIS directory sync or real-time SCIM 2.0 provisioning.

export const RelatedPages = ({pages = []}) => {
  if (pages.length === 0) return null;
  return <>
      <br />
      <strong>Related articles</strong>
      <CardGroup cols={2}>
        {pages.map(page => <Card title={page.title} href={page.href} key={page.href} />)}
      </CardGroup>
    </>;
};

export const RoleBadge = ({roles = []}) => {
  const colorMap = {
    Admin: "yellow",
    Manager: "blue",
    Learner: "green",
    "Co-editor": "purple"
  };
  return <>
      {roles.map(role => <span key={role}><Badge color={colorMap[role] || "gray"} size="sm" shape="pill">{role}</Badge>{" "}</span>)}
    </>;
};

export const Prerequisites = ({items = []}) => {
  return <Note title="Before you start">
      {items.length > 0 && <ul>
          {items.map((item, index) => <li key={index}>{item}</li>)}
        </ul>}
    </Note>;
};

export const InternalNote = ({children}) => {
  const [isInternal, setIsInternal] = useState(false);
  useEffect(() => {
    const user = window.__mintlify_user__;
    if (user?.groups?.includes("internal")) setIsInternal(true);
  }, []);
  if (!isInternal) return null;
  return <div className="internal-note">
      <strong className="internal-note-title">🔒 Internal Note</strong>
      <div>{children}</div>
    </div>;
};

<RoleBadge roles={["Admin"]} />

Juno can keep your organization's user list up to date automatically, so you don't have to add, update, or deactivate accounts by hand. There are two ways to do it:

| Method                    | How it works                                                  | Best for                                                                                     |
| ------------------------- | ------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
| **HR directory sync**     | Juno pulls your people data from your HR system once a day.   | Organizations whose source of truth is an HR system (HRIS).                                  |
| **SCIM 2.0 provisioning** | Your identity provider pushes changes to Juno as they happen. | Organizations that manage access in an identity provider such as Okta or Microsoft Entra ID. |

Both are managed from **Security → Users Sync**.

<Note>
  The **Security** area is available to users with the **IT Admin** role. Admins can open **Users Sync** and copy the SCIM details, but only IT Admins can edit the SCIM fields mapping.
</Note>

***

## HR directory sync

Juno connects directly to your HR system's API, reads your people data, and creates, updates, or deactivates Juno accounts to match.

### Supported HR systems

| HR system                      | What Juno reads by default                                                                                                            |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------- |
| **HiBob**                      | Name, email, job title, department, manager, site, start date                                                                         |
| **BambooHR**                   | Work email, employee number, name, job title, department, location, supervisor, photo, hire date, employment status                   |
| **SAP SuccessFactors**         | Users from the SuccessFactors OData API                                                                                               |
| **Oracle HCM Cloud**           | Name, work email, job title, department, location, manager, start date, hire date, employee number                                    |
| **Google Workspace Directory** | Email, name, job title, department, manager, suspended status                                                                         |
| **Custom connector**           | Any HR or directory system with a JSON REST API (token, custom header, or OAuth 2.0 authentication; paged or unpaged results)         |
| **SFTP file**                  | A CSV or Excel file (`.csv`, `.xlsx`, `.xls`) on your SFTP server. Juno reads the first sheet and uses the first row as column names. |

For HiBob, BambooHR, Google Workspace, Oracle HCM, and custom connectors, Juno Support can also read extra fields beyond the defaults.&#x20;

### How it's set up

HR directory sync is configured by **Juno Support** — there's no self-serve setup screen. To get started, contact your Juno account team. You'll typically be asked for:

* API credentials for your HR system (for example, an API token or OAuth client), or SFTP connection details and the file path
* Which HR fields should map to which Juno fields — such as email, name, department, job title, manager, and hire date

### What to expect

* **Daily sync.** Juno reads your HR system once a day, early morning UTC, and then applies the changes to Juno accounts.
* **Matching.** Juno matches people to existing accounts by email by default. People with no email aren't synced.&#x20;
* **New hires** get a new Juno account automatically.
* **Changes** to names, departments, job titles, managers, and other mapped fields update the existing account.
* **Leavers are deactivated, not deleted.** People who are marked inactive in your HR system, or who no longer appear in it, are deactivated in Juno.&#x20;
* **Safety check.** If more than 20% of your synced people would drop out of the HR data at once, Juno skips that deactivation run so a broken HR export can't lock everyone out.

<Tip>
  Need to keep a specific person out of the sync — for example, an Admin who isn't in the HR system yet? Ask Juno Support to exclude that account from sync.
</Tip>

***

## SCIM 2.0 provisioning

With SCIM, your identity provider creates, updates, and deactivates Juno users as soon as you make the change there. Juno works as a standard SCIM 2.0 service provider using bearer-token authentication.

<Prerequisites
  items={[
"Admin access to your identity provider",
"Access to Security → Users Sync in Juno",
]}
/>

### Set up SCIM

<Steps>
  <Step title="Copy your SCIM details from Juno">
    Go to **Security → Users Sync**. Under **SCIM Provisioning Parameters:**, copy the **SCIM URL** and the **SCIM Token**. The URL is unique to your organization and looks like `https://scim.the-juno.com/api/v1/scim/v2/<your-organization-id>`.
  </Step>

  <Step title="Add a SCIM provisioning app in your identity provider">
    In Okta, Microsoft Entra ID, or another SCIM 2.0 identity provider, create or open the app you use for Juno and turn on SCIM provisioning.
  </Step>

  <Step title="Paste the URL and token">
    Paste the **SCIM URL** as the SCIM base URL and the **SCIM Token** as the bearer token (API token). Test the connection from your identity provider.
  </Step>

  <Step title="Assign users and push">
    Assign the people who should have Juno accounts to the app, then start provisioning. They appear in Juno as the identity provider sends them.
  </Step>

  <Step title="Check and adjust the fields mapping">
    Back in **Users Sync**, review **SCIM Fields Mapping:** and select **Edit** to change how SCIM attributes map to Juno fields. See [Map SCIM attributes](#map-scim-attributes).
  </Step>
</Steps>

<Warning>
  Treat the SCIM token like a password. Anyone with it can create and deactivate users in your organization. If it's exposed, contact Juno Support to revoke existing tokens.
</Warning>

### What SCIM supports

| Action in your identity provider | What happens in Juno                                                                                                                       |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| Assign a user                    | A Juno account is created. If an account with the same username or email already exists, Juno links to it instead of creating a duplicate. |
| Update a user's attributes       | The Juno account is updated using your fields mapping.                                                                                     |
| Set a user to inactive           | The Juno account is deactivated. Setting them active again reactivates it.                                                                 |
| Delete a user                    | The Juno account is deactivated and marked as deleted.                                                                                     |

Juno supports the SCIM `/Users` resource (create, read, update with PUT or PATCH, and delete) and simple filters (`eq`, combined with `and`). Group provisioning and bulk operations aren't supported — Groups requests return an empty list.

### Map SCIM attributes

Selecting **Edit** opens a four-step wizard:

1. **Review recent data.** See the raw data of the 100 most recently updated SCIM users, so you know which attributes your identity provider actually sends.
2. **Map your data to Juno's fields.** Pick a Juno field for each SCIM attribute — for example **First Name**, **Last Name**, **Full Name**, **Email**, **Employee ID**, **Department**, **Job Title**, **Location**, **Employee Type**, or **Hire/Start Date**. Your organization's custom attributes are listed too. The username and email attributes can't be changed.
3. **Confirm.** Review the differences between the current and new mapping.
4. **Apply.** Select **Apply new Fields Mapping**. Juno saves the mapping, re-applies it to all existing SCIM users, and updates managers and the organization chart when manager fields changed.

To connect people to their managers, map your manager attribute to one of the manager options: **Manager Employee ID**, **Manager UserName**, **Manager Email**, **Manager Full Name**, **Manager (Other)**, or **Manager Juno ID (Entra ID)**.

<InternalNote>
  Support users also see **Force SCIM Mapping**, **Force Directory Sync**, **Force Directory Mapping**, and **Show Directory Sync Raw Data** (dry run) on Users Sync. HRIS connectors, SCIM token revocation, and per-user sync exclusion are configured by Support.
</InternalNote>

<RelatedPages
  pages={[
{ href: "/integrations/sso-and-saml", title: "SSO & SAML" },
{ href: "/admin/managing-users", title: "Managing Users" },
{ href: "/integrations/salesforce-provisioning", title: "Provision customers from Salesforce" },
]}
/>
