Build against the contract. Operate against the evidence.
FreeSCIM exposes standards-shaped lifecycle behavior while keeping Linux authority, mutation safety, reconciliation, and proof visible. The goal is not a clever API. It is a predictable identity control plane that can live beside the rest of an enterprise application estate.
The public developer surface keeps protocol behavior separate from environment-specific base URLs, credentials, and directory details. Your deployment chooses the base path. The resource contracts stay recognizable.
/ServiceProviderConfig
Discover supported SCIM behavior before assuming filters, patch semantics, bulk behavior, or authentication shape.
/Schemas
Inspect resource schema instead of hard-coding every attribute assumption into a client.
/ResourceTypes
Understand how resources are represented and which schemas apply.
/Users
Create, read, replace, patch, filter, page, and lifecycle-disable identities through the governed user path.
/Groups
Use bounded group behavior where the current capability matrix marks it available; do not infer unsupported mutation breadth.
The hostname and base path above are intentionally generic. Production routing, secret storage, and trust configuration belong to the deployment, not to public example code.
Application estate
Enterprise infrastructure without demanding to become the whole enterprise.
FreeSCIM is strongest when it behaves like a well-bounded application: it accepts defined inputs, delegates authority to the right systems, persists only what it should, exposes health and evidence, and can sit beside normal business applications rather than replacing them.
Identity providerProfile and lifecycle intent
HTTPS / proxyTLS, routing, policy edge
FreeSCIM runtimeMap, guard, reconcile, prove
PostgreSQLOperational state and evidence
FreeIPALinux directory and access authority
Coexistence
Fits an existing application platform.
Reverse proxying, external identity, a database, directory connectivity, health checks, and logs are conventional enterprise concerns. FreeSCIM does not require every neighboring application to adopt its authority model.
Isolation
Keep credentials and privilege narrow.
SCIM ingress, human SSO, directory mutation, database access, and remote operational paths remain separate trust concerns with separate evidence.
Survivability
Day-two behavior is part of the design.
Readiness, drift, snapshots, structured errors, audit context, and degraded-state labels are treated as runtime product behavior rather than afterthoughts.
Developer contract
Predictability matters more than magic.
Clients and operators should be able to tell what FreeSCIM accepted, what it rejected, which authority made the final decision, and what evidence remains after the transaction.
01 · Validate
Reject malformed or unsafe intent early.
Schema, identifiers, filters, lifecycle transitions, concurrency expectations, and policy gates should fail explicitly instead of degrading into ambiguous partial writes.
02 · Correlate
Carry a transaction through the evidence plane.
Request context, mapping decisions, downstream operations, drift checks, and operator-visible outcomes should be traceable without logging secrets.
03 · Bound
Do not let provisioning become authorization.
Creating or updating an identity does not bypass Kerberos, HBAC, sudo policy, group policy, or the downstream Linux enforcement model.
04 · Compare
Observe disagreement before repairing it.
Snapshots and persistent comparison make source-versus-directory drift visible before remediation is considered.
05 · Explain
Return useful failure information.
Structured status and error behavior should tell a client whether the problem is syntax, policy, authority, readiness, or downstream execution.
06 · Recover
Design the next safe state.
High-risk transitions remain staged until the proof chain includes a credible rollback or recovery path.
Extension framework
Add integrations without erasing the authority map.
The architecture is adapter-oriented, but extension should remain contract-driven. A future provider or destination belongs in FreeSCIM only when its inputs, privileges, mutation semantics, failure modes, and evidence can be described precisely.
Ingress adapters
Receive lifecycle intent.
Normalize protocol and provider-specific identity data into the canonical lifecycle model.
Authority adapters
Apply bounded state.
Translate approved intent into the destination system without pretending the adapter owns authentication or authorization it does not control.
Evidence adapters
Make outcomes observable.
Capture health, drift, audit, correlation, and downstream proof in a way that survives handoff and incident review.
Runtime preview
Use the operator vocabulary before touching a deployment.
This browser-only simulation is derived from the current runtime UI. It uses synthetic public data and does not connect to production systems.
Truth states
Shipping code and production authority are not the same milestone.
FreeSCIM deliberately keeps implementation, governed enablement, and blocked proof states distinct so developers do not have to reverse-engineer confidence from marketing language.
Current
Implemented behavior with direct operating or conformance evidence.
Governed
Implemented path that remains staged, environment-gated, or policy-limited.
Blocked / roadmap
Not yet entitled to a production claim; prerequisites or end-to-end proof are still missing.
Keep going
Move from protocol to runtime truth.
Use the next surface that matches the question you are trying to answer.