SCIM contract map

The API supports discovery, users, groups, filters, paging, lifecycle mutations, active-state disable, structured failures, and transaction-scoped password delivery. The control plane then follows the requested state into FreeIPA and Linux evidence.

Primary resources

Password transaction boundary

The API may receive password material only when an authorized identity provider includes it in the current SCIM transaction. FreeSCIM detects it in memory, never persists or logs it, records only presence and outcome flags, and requires policy and downstream proof.

Client expectations