Teams and Businesses

Deploy the 1Password SCIM bridge on DigitalOcean

Learn how to deploy the 1Password SCIM bridge on DigitalOcean, so you can integrate with your identity provider.

Tip

If you don’t use DigitalOcean, you can still automate provisioning in another deployment environment.

With 1Password Business, you can automate many common administrative tasks using the 1Password SCIM bridge. It uses the System for Cross-domain Identity Management (SCIM) protocol to connect 1Password with your existing identity provider, like Azure Active Directory or Okta.

Step 1: Deploy the SCIM bridge on DigitalOcean

If you don’t already have a DigitalOcean account, create one. Then follow these steps.

1.1: Create a cluster

The SCIM bridge must be deployed within a cluster. To create a cluster:

  1. Visit 1Password SCIM bridge on DigitalOcean Marketplace and click “Create 1Password SCIM bridge”.
  2. Configure your cluster using the provided defaults or choose your preferred options.
  3. Scroll to the bottom and click Create Cluster.

Your cluster is now provisioning. After a few minutes, you’ll receive an email from DigitalOcean confirming that your load balancer is ready.

1.2: Set up the SCIM bridge

After your load balancer is ready:

  1. Click Networking in the sidebar and choose Load Balancers. You’ll see the IP address for your load balancer.

  2. Click the IP address to copy it.

  3. Paste the IP address in your web browser’s address bar and press Return.

You’ll see the 1Password SCIM Bridge Setup page.

DigitalOcean load balancer configuration screen showing the IP address to copy

the load balancer IP address in a web browser's adderss bar

Step 2: Connect the SCIM bridge to your 1Password account

Before you can connect the SCIM bridge to your 1Password account, you’ll need to configure a DNS record to point your domain to the IP address of your load balancer. For example: https://scim.example.com. Then follow these steps.

2.1: Sign in to your 1Password account

On the 1Password SCIM Bridge Setup page:

  1. Enter the domain name you configured for your load balancer to verify it.
  2. Click Sign In and follow the onscreen instructions.

If you see "Generate New Credentials", the setup process has already been completed. If you've lost your bearer token or session file or changed the sign-in details for the account shown, click Generate New Credentials.

1Password SCIM Bridge Status

2.2: Authenticate with the SCIM bridge

After you complete the setup process, you’ll see:

  • Your scimsession file. It contains the credentials for your new Provision Manager account.
  • Your bearer token. It’s the key to decrypt your scimsession file.
  1. Save them both in 1Password. You’ll need your bearer token to connect your identity provider to the SCIM bridge. Your scimsession file will be installed automatically, but it’s a good idea to have a backup. Learn how to save important files in 1Password.
  2. Click “Install on <yourdomain>”. You’ll see the 1Password SCIM Bridge Status page.
  3. Enter your OAuth bearer token and click Verify.

Important

The bearer token and scimsession file combined can be used to sign in to your Provision Manager account. You’ll need to share the bearer token with your identity provider, but it’s important to never share it with anyone else. And never share your scimsession file with anyone at all.

Step 3: Connect your identity provider to the SCIM bridge

Because the 1Password SCIM bridge provides a SCIM 2.0-compatible web service that accepts OAuth bearer tokens for authorization, you can use it with a variety of identity providers.

Connect to the load balancer where you’ve configured the SCIM bridge (for example: https://scim.example.com) and authenticate using your OAuth bearer token.

Learn how to connect your identity provider:

Azure Active Directory

Okta

Get help

The 1Password SCIM bridge requires 1Password Business and a supported SCIM 2.0-compatible identity provider: Azure Active Directory or Okta.

If you lose your bearer token or session file

Your OAuth bearer token and scimsession file are cryptographically linked. If you lose either one, you’ll need to generate a new bearer token and session file. Then deploy the SCIM bridge again.

If you change the account details for your Provision Manager account

If you change the Master Password, Secret Key, or email address for the account you created for provision management, you’ll need to generate a new bearer token and session file. Then deploy the SCIM bridge again.

If you still need help

For more information about the SCIM bridge, contact your 1Password Business representative. To get help and share feedback, join the discussion in the 1Password Support forum.

Published: