Migrate from a self-hosted SCIM bridge to automated provisioning, hosted by 1Password

Learn how to migrate from a self-hosted SCIM bridge to automated provisioning, hosted by 1Password.

When you provision users with a self-hosted SCIM bridge, it connects your 1Password account to your identity provider so you can create and manage users and groups. You can simplify the connection by migrating to automated provisioning, hosted by 1Password.

Automated provisioning currently supports Entra ID, Google Workspace, JumpCloud, Okta, and OneLogin. To migrate from a self-hosted SCIM bridge, follow the steps below.

Try it yourself

Explore our interactive demo to see how 1Password automated provisioning migration works.

Launch interactive demo

Considerations

When you migrate to automated provisioning, consider the impact it will have on your account:

  • Automated provisioning is hosted by 1Password in the same region as your account. For example, provisioning for an account on 1Password.eu runs in the European Union.
  • You’ll reconnect your identity provider to 1Password with a new SCIM URL and bearer token. If you use Google Workspace, you’ll connect with a Google service account instead.
  • You won’t be able to switch back to a self-hosted SCIM bridge on the account. Automated provisioning is designed differently than a self-hosted SCIM bridge, and your account won’t be compatible with the self-hosted SCIM bridge after you migrate.
  • Automated provisioning won’t manage groups that have the Recover Accounts or Manage All Groups permissions. This is a security feature to prevent provisioning from having account-wide cryptographic access.
  • Users will be confirmed without a delay. With a self-hosted SCIM bridge, there’s a 5-minute delay in user confirmation after they sign up, but with automated provisioning, team members are provisioned immediately after they complete the confirmation flow. Automated provisioning’s immediate confirmations are more secure than a self-hosted SCIM bridge’s automated confirmations because the end-user proves their identity when they accept the invitation.

Limitations

User management with 1Password CLI is only supported in version 2.36.0-beta.02 and later. Learn more about adding and removing team members with the CLI.

Requirements

When you’re ready to migrate to automated provisioning, you’ll need to:

Step 1: Switch to automated provisioning in 1Password

  1. Sign in to your account on 1Password.com.
  2. Select Integrations in the sidebar, then select Automated User Provisioning.

    If you use Google Workspace, continue to the Google Workspace steps below.

  3. Select Switch to hosted provisioning, then select Start setup.
  4. Select Set up hosted provisioning.
  5. Save your credentials in 1Password in case you need them in the future, then select Next.
  6. Leave this page open and continue to step 2.

Step 2: Update the integration in your identity provider

Follow the steps below for your identity provider.

These steps were recorded in March 2026 and may have changed since. Refer to the Microsoft documentation for the most up-to-date steps.

Sign in to your account on the Microsoft Entra admin center and follow these steps:

  1. Select Enterprise applications in the sidebar, then select the 1Password EPM application.
  2. Select Provisioning in the second sidebar.
  3. Open the Admin Credentials section.
  4. Fill out the following fields:
    • Tenant URL: Copy and paste your SCIM URL from the hosted provisioning setup page (not your 1Password account sign-in address). Do not include a trailing slash. For example: https://provisioning.1password.com/scim/v2.
    • Secret token: Copy and paste your bearer token from the hosted provisioning setup page.
  5. Select Test Connection, then select Save.
  6. Go back to the hosted provisioning setup tab in 1Password and select Save credentials in 1Password, then select Done.

These steps were recorded in September 2026 and may have changed since. Refer to Google's documentation to create a project, create a service account, and create a service account key.

Important

Users who aren’t in a selected group will be suspended in 1Password. When you select groups to sync to 1Password, you’ll be asked to review potential suspensions before they happen.

Google Workspace requirements

Google Workspace connects to automated provisioning through a Google service account instead of a SCIM URL and bearer token. Before you begin:

Connect to Google Workspace

Then follow these steps on your Google Workspace integration page in 1Password:

  1. Select Switch to hosted provisioning, enter your account name to confirm, then select Switch to hosted provisioning again.
  2. On the “Upload Google Cloud credentials” page, select the Select a .json Google Workspace account key to upload button, then select your service account key.
  3. In the “Google workspace administrator account (email)” field, enter the email address of a Google Workspace administrator, then select Next.

    Use a Super Administrator or an account with the Users > Read, Groups > Read, and Reports Admin API privileges.

  4. On the “Set up automated sync” page, select Copy to copy the setup script. Learn more about the setup script.
  5. Select Google Cloud Shell and select Authorize if asked.
  6. Paste the script and run it, then go back to 1Password and select Next.

    If the script stops with a billing or Cloud Scheduler error, turn on billing for the project and run the script again.

  7. Select Finish.

These steps were recorded in April 2026 and may have changed since. Refer to the JumpCloud documentation for the most up-to-date steps.

Sign in to your account on the JumpCloud Administrator Portal and follow these steps:

  1. Select SSO Applications in the Access section in the sidebar.
  2. Select the 1Password application.
  3. Select Configuration Settings in the Identity Management section.
  4. Fill out the following fields:
    • Base URL: Copy and paste your SCIM URL from the hosted provisioning setup page (not your 1Password account sign-in address). Do not include a trailing slash. For example: https://provisioning.1password.com/scim/v2.
    • Token key: Copy and paste your bearer token from the hosted provisioning setup page.
  5. Select Update.
  6. Go back to the hosted provisioning setup tab in 1Password and select Save credentials in 1Password, then select Done.

These steps were recorded in March 2026 and may have changed since. Refer to the Okta documentation for the most up-to-date steps.

Sign in to your account on Okta.com, select Admin in the top right, and follow these steps:

  1. Select Applications and Resources > Applications in the sidebar.
  2. Search for the 1Password provisioning application and select it.
  3. Select the Provisioning tab, then select Integration.
  4. Select Edit.
  5. Fill out the following fields:
    • Base URL: Copy and paste your SCIM URL from the hosted provisioning setup page (not your 1Password account sign-in address). Do not include a trailing slash. For example: https://provisioning.1password.com/scim/v2.
    • API Token: Copy and paste your bearer token from the hosted provisioning setup page.
  6. Select Test API Credentials. After it’s complete, select Save.
  7. Go back to the hosted provisioning setup tab in 1Password and select Save credentials in 1Password, then select Done.

2.1: Map the displayName attribute

After you set up the application, you’ll need to add mapping for the displayName attribute in Okta. This will make sure that user display names in 1Password are updated from Okta.

On the Provisioning tab, follow these steps:

  1. Select Go to Profile Editor, then select Add Attribute.
  2. Fill in the following fields:
    • Display name: Enter DisplayName.
    • Variable name: Enter displayName.
    • External namespace: Copy and paste the following: urn:ietf:params:scim:schemas:core:2.0:User
  3. Select Save, then select Mappings.
  4. Select the Okta User to 1Password … tab.
  5. Map the displayName attribute to displayName.
  6. Select Save Mappings > Apply updates.

These steps were recorded in April 2026 and may have changed since. Refer to the OneLogin documentation for the most up-to-date steps.

Sign in to your account on OneLogin.com, select Administration in the top right, and follow these steps:

  1. Select Applications and Resources.
  2. Search for the 1Password application and select it.
  3. Select Configuration, then update the following fields:
    • SCIM Base URL: Copy and paste your SCIM URL from the hosted provisioning setup page (not your 1Password account sign-in address). Do not include a trailing slash. For example: https://provisioning.1password.com/scim/v2.
    • SCIM Bearer Token: Copy and paste your bearer token from the hosted provisioning setup page.
  4. Select Save.
  5. Go back to the hosted provisioning setup tab in 1Password and select Save credentials in 1Password, then select Done.

Step 3: Decommission your SCIM bridge

After you’ve migrated to automated provisioning, you can decommission your SCIM bridge and phase out the infrastructure you deployed it on.

Get help

If you need to manage team members with 1Password CLI, you’ll need to use 1Password CLI version 2.36.0-beta.02 and later. Learn more about adding and removing team members with the CLI.

Learn more



Published: