Protocol surface

Start with SCIM semantics, not deployment trivia.

The public developer surface keeps protocol behavior separate from environment-specific base URLs, credentials, and directory details. Your deployment chooses the base path. The resource contracts stay recognizable.

/ServiceProviderConfig

Discover supported SCIM behavior before assuming filters, patch semantics, bulk behavior, or authentication shape.

/Schemas

Inspect resource schema instead of hard-coding every attribute assumption into a client.

/ResourceTypes

Understand how resources are represented and which schemas apply.

/Users

Create, read, replace, patch, filter, page, and lifecycle-disable identities through the governed user path.

/Groups

Use bounded group behavior where the current capability matrix marks it available; do not infer unsupported mutation breadth.

Example · deployment-neutral lookup
export FREESCIM_BASE="https://your-freescim.example/scim/v2"
export FREESCIM_TOKEN="replace-with-a-deployment-token"

curl -sS \
  -H "Authorization: Bearer $FREESCIM_TOKEN" \
  "$FREESCIM_BASE/Users?filter=userName%20eq%20%22demo.user%22"

The hostname and base path above are intentionally generic. Production routing, secret storage, and trust configuration belong to the deployment, not to public example code.

Application estate

Enterprise infrastructure without demanding to become the whole enterprise.

FreeSCIM is strongest when it behaves like a well-bounded application: it accepts defined inputs, delegates authority to the right systems, persists only what it should, exposes health and evidence, and can sit beside normal business applications rather than replacing them.

Identity providerProfile and lifecycle intent
HTTPS / proxyTLS, routing, policy edge
FreeSCIM runtimeMap, guard, reconcile, prove
PostgreSQLOperational state and evidence
FreeIPALinux directory and access authority
Coexistence

Fits an existing application platform.

Reverse proxying, external identity, a database, directory connectivity, health checks, and logs are conventional enterprise concerns. FreeSCIM does not require every neighboring application to adopt its authority model.

Isolation

Keep credentials and privilege narrow.

SCIM ingress, human SSO, directory mutation, database access, and remote operational paths remain separate trust concerns with separate evidence.

Survivability

Day-two behavior is part of the design.

Readiness, drift, snapshots, structured errors, audit context, and degraded-state labels are treated as runtime product behavior rather than afterthoughts.

Developer contract

Predictability matters more than magic.

Clients and operators should be able to tell what FreeSCIM accepted, what it rejected, which authority made the final decision, and what evidence remains after the transaction.

01 · Validate

Reject malformed or unsafe intent early.

Schema, identifiers, filters, lifecycle transitions, concurrency expectations, and policy gates should fail explicitly instead of degrading into ambiguous partial writes.

02 · Correlate

Carry a transaction through the evidence plane.

Request context, mapping decisions, downstream operations, drift checks, and operator-visible outcomes should be traceable without logging secrets.

03 · Bound

Do not let provisioning become authorization.

Creating or updating an identity does not bypass Kerberos, HBAC, sudo policy, group policy, or the downstream Linux enforcement model.

04 · Compare

Observe disagreement before repairing it.

Snapshots and persistent comparison make source-versus-directory drift visible before remediation is considered.

05 · Explain

Return useful failure information.

Structured status and error behavior should tell a client whether the problem is syntax, policy, authority, readiness, or downstream execution.

06 · Recover

Design the next safe state.

High-risk transitions remain staged until the proof chain includes a credible rollback or recovery path.

Extension framework

Add integrations without erasing the authority map.

The architecture is adapter-oriented, but extension should remain contract-driven. A future provider or destination belongs in FreeSCIM only when its inputs, privileges, mutation semantics, failure modes, and evidence can be described precisely.

Ingress adapters

Receive lifecycle intent.

Normalize protocol and provider-specific identity data into the canonical lifecycle model.

Authority adapters

Apply bounded state.

Translate approved intent into the destination system without pretending the adapter owns authentication or authorization it does not control.

Evidence adapters

Make outcomes observable.

Capture health, drift, audit, correlation, and downstream proof in a way that survives handoff and incident review.

Runtime preview

Use the operator vocabulary before touching a deployment.

This browser-only simulation is derived from the current runtime UI. It uses synthetic public data and does not connect to production systems.

Truth states

Shipping code and production authority are not the same milestone.

FreeSCIM deliberately keeps implementation, governed enablement, and blocked proof states distinct so developers do not have to reverse-engineer confidence from marketing language.

Current

Implemented behavior with direct operating or conformance evidence.

Governed

Implemented path that remains staged, environment-gated, or policy-limited.

Blocked / roadmap

Not yet entitled to a production claim; prerequisites or end-to-end proof are still missing.

Keep going

Move from protocol to runtime truth.

Use the next surface that matches the question you are trying to answer.