End-to-end proof chain

SCIM requestPayload guardMappingFreeIPA writeLinux validationEvidence export

Password convergence

When an identity provider includes a password in an authorized SCIM transaction, FreeSCIM handles it only in memory, checks the eligible-user and execution gates, sends it through the bounded FreeIPA password route, and records the non-secret outcome. A successful directory write is followed by a current Linux login proof before the capability is marked working.

Lifecycle coverage

Users

Create, read, replace, patch, disable, filter, page, retry, and reconcile.

Groups

Visibility, creation, filtering, snapshots, membership evidence, and authority boundaries.

Mappings

Canonical identity, usernames, email, manager, active state, and directory-safe transformations.

Drift

Okta and FreeIPA snapshots, compare-first workflows, execution previews, and bounded repair.

Success means usable identity

FreeSCIM does not stop at an HTTP success response. The proof chain continues until the target directory and Linux login behavior agree with the requested lifecycle outcome.