SCIM contract map
The API supports discovery, users, groups, filters, paging, lifecycle mutations, active-state disable, structured failures, and transaction-scoped password delivery. The control plane then follows the requested state into FreeIPA and Linux evidence.
Primary resources
Password transaction boundary
The API may receive password material only when an authorized identity provider includes it in the current SCIM transaction. FreeSCIM detects it in memory, never persists or logs it, records only presence and outcome flags, and requires policy and downstream proof.
Client expectations
- Use tokenized authentication and stable client identifiers.
- Honor discovery, implemented filters, paging limits, ETags where required, and structured SCIM errors.
- Capture status plus request/correlation context for replay diagnostics.
- Do not treat an accepted HTTP response as the end of the proof chain.