> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Update organization SCIM settings

> Controls whether provisioned SCIM Groups remain metadata or create and manage organization teams.



## OpenAPI

````yaml /openapi.json patch /v1/scim
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for API-key-authenticated routes that
    accept organization API keys.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: dev
servers: []
security: []
tags:
  - name: System
    description: Service health and operational routes.
  - name: Organizations
    description: Top-level organization creation and context routes.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: SCIM
    description: Organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: Templates
    description: Organization shared template routes.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Admin
    description: Administrative reporting routes.
  - name: Users
    description: Current user and membership routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
paths:
  /v1/scim:
    patch:
      tags:
        - SCIM
      summary: Update organization SCIM settings
      description: >-
        Controls whether provisioned SCIM Groups remain metadata or create and
        manage organization teams.
      operationId: patchV1Scim
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                groupMappingMode:
                  type: string
                  enum:
                    - metadata_only
                    - create_teams
              required:
                - groupMappingMode
      responses:
        '200':
          description: Organization SCIM settings updated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OrganizationScimConnectionResponse'
        '401':
          description: Unauthorized
        '403':
          description: Only workspace owners and super-admins can manage SCIM.
        '404':
          description: SCIM connection not found
      security:
        - bearerAuth: []
components:
  schemas:
    OrganizationScimConnectionResponse:
      type: object
      properties:
        baseUrl:
          type: string
          format: uri
        ssoReady:
          type: boolean
        connection:
          anyOf:
            - $ref: '#/components/schemas/OrganizationScimConnection'
            - type: 'null'
        health:
          $ref: '#/components/schemas/OrganizationScimHealth'
      required:
        - baseUrl
        - ssoReady
        - connection
        - health
    OrganizationScimConnection:
      type: object
      properties:
        id:
          type: string
        providerId:
          type: string
        organizationId:
          type: string
        groupMappingMode:
          type: string
          enum:
            - metadata_only
            - create_teams
        createdAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
        updatedAt:
          type: string
          format: date-time
          pattern: >-
            ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
      required:
        - id
        - providerId
        - organizationId
        - groupMappingMode
        - createdAt
        - updatedAt
    OrganizationScimHealth:
      type: object
      properties:
        unresolvedFailureCount:
          type: integer
          minimum: 0
          maximum: 9007199254740991
        lastFailureAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        lastFailureAction:
          anyOf:
            - type: string
            - type: 'null'
        lastFailureMessage:
          anyOf:
            - type: string
            - type: 'null'
        nextRetryAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
        lastSuccessfulSyncAt:
          anyOf:
            - type: string
              format: date-time
              pattern: >-
                ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
            - type: 'null'
      required:
        - unresolvedFailureCount
        - lastFailureAt
        - lastFailureAction
        - lastFailureMessage
        - nextRetryAt
        - lastSuccessfulSyncAt
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: session-token
      description: >-
        Session token passed as `Authorization: Bearer <session-token>` for
        user-authenticated Den routes.

````