scim2-server
This is an example WSGI-SCIM server using scim2-models. It utilizes werkzeug and scim2-filter-parser and keeps all resources in-memory, they are lost once the process exits.
Features
- Discovery endpoints (
/v2/ServiceProviderConfig,/v2/ResourceTypes,/v2/Schemas) - Create/Read/Update/Delete resources (
POST,GET,PUT,DELETE) - Searching & Filtering
- Support for ETags
- Unique Constraints
- HTTP PATCH (Add/Remove/Replace)
- Sorting
The only optional feature currently missing is support for Bulk operations (RFC 7644, Section 3.7).
Usage
$ scim2-server [-h] [--schema SCHEMA] [--resource-type RESOURCE_TYPE] [--bearer-token BEARER_TOKEN] [--hostname HOSTNAME] [--port PORT] [--reverse-proxy] [--dump-resources DUMP_RESOURCES]
-h/--help: Show help message--reverse-proxy: Allow using the provider behind a Reverse Proxy (required for URL rewriting).--schema: Register schemas from specified JSON file. If not provided, loads the default schemas from RFC 7643.--resource-type: Register resource types from specified JSON file. If not provided, loads the default resource types from RFC 7643.--bearer-token: Registers a bearer token that can be used for accessing the service. If no tokens are provided, anonymous access without authentication is allowed.--hostname: The hostname to listen on. Defaults to127.0.0.1.--port: The port to listen on. Defaults to8080.--dump-resources: Dump a JSON document containing all resources when the provider exits normally.
Notes
This provider can be used as a starting point if you want to implement a SCIM provider. You should probably change the following things, if you want to use it in production:
- Use a proper production WSGI server instead of the one provided by Werkzeug
- Implement your own Backend as a subclass of
scim2_server.backend.Backend - Implement proper authorization with OAuth instead of public access or static bearer tokens
- Support the
/Meendpoint, if it applies in your use case - Add support for using either a static URL prefix or improve the support for usage behind a reverse proxy
The provider in its current state has been tested successfully against a live Microsoft Entra system as well as a live Okta system.
Origins
Parts of this software were initially developed at CONTACT Software (GitHub) and subsequently made available under the Apache License Version 2.0.
Release files for scim2-server 0.1.9
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| scim2_server-0.1.9.tar.gz | 27.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| scim2_server-0.1.9-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 55.9 kB
Release files / scim2_server-0.1.9.tar.gz
| Download URL | scim2_server-0.1.9.tar.gz |
|---|---|
| Size | 27.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
46719347a5e23c3676c8fec458f494bc24792a1c4cc21d2806d7591f92a4f505
|
|
BLAKE2b-256 checksum How to use checksums |
c30d6dc0d89a988c79690adf4b44f86fcc5ebe209a1db9008ceec100cc3a1dd8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 27, 2026.
Transparency logRelease files / scim2_server-0.1.9-py3-none-any.whl
| Download URL | scim2_server-0.1.9-py3-none-any.whl |
|---|---|
| Size | 29.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e0cc2258176dfae8dca823da9451bcff88d3c357a270a03f52878405c26345e2
|
|
BLAKE2b-256 checksum How to use checksums |
fd9b0ad5c752bc42258bddee6dc738e04b53875d2fcf868afecbdf7093cb52d2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 27, 2026.
Transparency log