Buckets:

hf-doc-build/doc-dev / hub /pr_2521 /en /enterprise-scim.html
HuggingFaceDocBuilder's picture
download
raw
30.1 kB
<meta charset="utf-8" /><meta name="hf:doc:metadata" content="{&quot;title&quot;:&quot;User Provisioning (SCIM)&quot;,&quot;local&quot;:&quot;user-provisioning-scim&quot;,&quot;sections&quot;:[{&quot;title&quot;:&quot;Basic SSO: invitation-based provisioning&quot;,&quot;local&quot;:&quot;basic-sso-invitation-based-provisioning&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Managed SSO: full lifecycle provisioning&quot;,&quot;local&quot;:&quot;managed-sso-full-lifecycle-provisioning&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;How to enable SCIM&quot;,&quot;local&quot;:&quot;how-to-enable-scim&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Group provisioning&quot;,&quot;local&quot;:&quot;group-provisioning&quot;,&quot;sections&quot;:[{&quot;title&quot;:&quot;Linking a SCIM group to a Resource Group&quot;,&quot;local&quot;:&quot;linking-a-scim-group-to-a-resource-group&quot;,&quot;sections&quot;:[],&quot;depth&quot;:3},{&quot;title&quot;:&quot;What happens after linking&quot;,&quot;local&quot;:&quot;what-happens-after-linking&quot;,&quot;sections&quot;:[],&quot;depth&quot;:3},{&quot;title&quot;:&quot;SCIM-managed Resource Groups&quot;,&quot;local&quot;:&quot;scim-managed-resource-groups&quot;,&quot;sections&quot;:[],&quot;depth&quot;:3}],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Supported user attributes&quot;,&quot;local&quot;:&quot;supported-user-attributes&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Deprovisioning&quot;,&quot;local&quot;:&quot;deprovisioning&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Supported Identity Providers&quot;,&quot;local&quot;:&quot;supported-identity-providers&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2}],&quot;depth&quot;:1}">
<link href="/docs/hub/pr_2521/en/_app/immutable/assets/0.e3b0c442.css" rel="modulepreload">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/entry/start.d19e5ca7.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/scheduler.409792a1.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/singletons.1ece723a.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/index.0f0d9f26.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/paths.a67d9216.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/entry/app.98ab229a.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/preload-helper.78e52d9f.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/index.92d389ff.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/nodes/0.7799902b.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/each.e59479a4.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/nodes/81.4d872d5a.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/CopyLLMTxtMenu.dcf7fb47.js">
<link rel="modulepreload" href="/docs/hub/pr_2521/en/_app/immutable/chunks/MermaidChart.svelte_svelte_type_style_lang.0c189c7e.js"><!-- HEAD_svelte-u9bgzb_START --><meta name="hf:doc:metadata" content="{&quot;title&quot;:&quot;User Provisioning (SCIM)&quot;,&quot;local&quot;:&quot;user-provisioning-scim&quot;,&quot;sections&quot;:[{&quot;title&quot;:&quot;Basic SSO: invitation-based provisioning&quot;,&quot;local&quot;:&quot;basic-sso-invitation-based-provisioning&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Managed SSO: full lifecycle provisioning&quot;,&quot;local&quot;:&quot;managed-sso-full-lifecycle-provisioning&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;How to enable SCIM&quot;,&quot;local&quot;:&quot;how-to-enable-scim&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Group provisioning&quot;,&quot;local&quot;:&quot;group-provisioning&quot;,&quot;sections&quot;:[{&quot;title&quot;:&quot;Linking a SCIM group to a Resource Group&quot;,&quot;local&quot;:&quot;linking-a-scim-group-to-a-resource-group&quot;,&quot;sections&quot;:[],&quot;depth&quot;:3},{&quot;title&quot;:&quot;What happens after linking&quot;,&quot;local&quot;:&quot;what-happens-after-linking&quot;,&quot;sections&quot;:[],&quot;depth&quot;:3},{&quot;title&quot;:&quot;SCIM-managed Resource Groups&quot;,&quot;local&quot;:&quot;scim-managed-resource-groups&quot;,&quot;sections&quot;:[],&quot;depth&quot;:3}],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Supported user attributes&quot;,&quot;local&quot;:&quot;supported-user-attributes&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Deprovisioning&quot;,&quot;local&quot;:&quot;deprovisioning&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2},{&quot;title&quot;:&quot;Supported Identity Providers&quot;,&quot;local&quot;:&quot;supported-identity-providers&quot;,&quot;sections&quot;:[],&quot;depth&quot;:2}],&quot;depth&quot;:1}"><!-- HEAD_svelte-u9bgzb_END --> <p></p> <div class="items-center shrink-0 min-w-[100px] max-sm:min-w-[50px] justify-end ml-auto flex" style="float: right; margin-left: 10px; display: inline-flex; position: relative; z-index: 10;"><div class="inline-flex rounded-md max-sm:rounded-sm"><button class="inline-flex items-center gap-1 h-7 max-sm:h-7 px-2 max-sm:px-1.5 text-sm font-medium text-gray-800 border border-r-0 rounded-l-md max-sm:rounded-l-sm border-gray-200 bg-white hover:shadow-inner dark:border-gray-850 dark:bg-gray-950 dark:text-gray-200 dark:hover:bg-gray-800" aria-live="polite"><span class="inline-flex items-center justify-center rounded-md p-0.5 max-sm:p-0 hover:text-gray-800 dark:hover:text-gray-200"><svg class="sm:size-3.5 size-3" xmlns="http://www.w3.org/2000/svg" aria-hidden="true" fill="currentColor" focusable="false" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 32 32"><path d="M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z" transform="translate(0)"></path><path d="M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z" transform="translate(0)"></path><rect fill="none" width="32" height="32"></rect></svg></span> <span>Copy page</span></button> <button class="inline-flex items-center justify-center w-6 max-sm:w-5 h-7 max-sm:h-7 disabled:pointer-events-none text-sm text-gray-500 hover:text-gray-700 dark:hover:text-white rounded-r-md max-sm:rounded-r-sm border border-l transition border-gray-200 bg-white hover:shadow-inner dark:border-gray-850 dark:bg-gray-950 dark:text-gray-200 dark:hover:bg-gray-800" aria-haspopup="menu" aria-expanded="false" aria-label="Open copy menu"><svg class="transition-transform text-gray-400 overflow-visible sm:size-3.5 size-3 rotate-0" width="1em" height="1em" viewBox="0 0 12 7" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M1 1L6 6L11 1" stroke="currentColor"></path></svg></button></div> </div> <h1 class="relative group"><a id="user-provisioning-scim" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#user-provisioning-scim"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>User Provisioning (SCIM)</span></h1> <blockquote class="warning" data-svelte-h="svelte-jxebfy"><p>This feature is part of the <a href="https://huggingface.co/enterprise">Enterprise</a> and <a href="https://huggingface.co/contact/sales?from=enterprise" target="_blank">Enterprise Plus</a> plans.</p></blockquote> <p data-svelte-h="svelte-2oz6cw">SCIM (System for Cross-domain Identity Management) is a standard for automating user provisioning. It allows you to connect your Identity Provider (IdP) to Hugging Face to manage your organization’s members.</p> <p data-svelte-h="svelte-e8z89x">SCIM works differently depending on your SSO model. For a detailed comparison, see the <a href="./enterprise-sso#user-provisioning-scim">SSO overview</a>.</p> <h2 class="relative group"><a id="basic-sso-invitation-based-provisioning" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#basic-sso-invitation-based-provisioning"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>Basic SSO: invitation-based provisioning</span></h2> <p data-svelte-h="svelte-11pv7zo">With <a href="./security-sso-basic">Basic SSO</a> (Enterprise plan), SCIM automates the <strong>invitation</strong> of existing Hugging Face users to your organization.</p> <ul data-svelte-h="svelte-nq5syq"><li>Users <strong>must already have a Hugging Face account</strong> before they can be provisioned via SCIM</li> <li>When your IdP provisions a user, Hugging Face sends them an <strong>invitation email</strong> to join the organization</li> <li>The user must <strong>accept the invitation</strong> to become a member — provisioning does not grant immediate access</li> <li>SCIM <strong>cannot modify</strong> user profile information (name, email, username) — the user retains full control of their Hugging Face account</li> <li>When a user is deprovisioned in your IdP, their invitation is deactivated and their access to the organization is revoked</li></ul> <h2 class="relative group"><a id="managed-sso-full-lifecycle-provisioning" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#managed-sso-full-lifecycle-provisioning"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>Managed SSO: full lifecycle provisioning</span></h2> <p data-svelte-h="svelte-106b5to">With <a href="./enterprise-advanced-sso">Managed SSO</a> (Enterprise Plus plan), SCIM manages the <strong>entire user lifecycle</strong> on Hugging Face.</p> <ul data-svelte-h="svelte-y2eiir"><li>SCIM <strong>creates a new Hugging Face account</strong> when a user is provisioned — no pre-existing account is needed</li> <li>The user is <strong>immediately added</strong> to the organization as a member, with no invitation step</li> <li>SCIM <strong>can update</strong> user profile information (name, email, username) as changes occur in your IdP</li> <li>When a user is deprovisioned in your IdP, their Hugging Face account is deactivated and their access is revoked</li></ul> <h2 class="relative group"><a id="how-to-enable-scim" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#how-to-enable-scim"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>How to enable SCIM</span></h2> <p data-svelte-h="svelte-1hlfjb6">To enable SCIM, go to your organization’s settings, navigate to the <strong>SSO</strong> tab, and then select the <strong>SCIM</strong> sub-tab.</p> <p data-svelte-h="svelte-1vlagnf">You will find the <strong>SCIM Tenant URL</strong> and a button to generate a <strong>SCIM token</strong>. You will need both of these to configure your IdP. The SCIM token is a secret and should be stored securely in your IdP’s configuration.</p> <div class="flex justify-center" data-svelte-h="svelte-lg246v"><img class="block dark:hidden" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-settings.png"> <img class="hidden dark:block" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-settings-dark.png"></div> <p data-svelte-h="svelte-tf3k17">Once SCIM is enabled in your IdP, provisioned users will appear in the <strong>Users Management</strong> tab and provisioned groups will appear in the <strong>SCIM</strong> tab in your organization’s settings.</p> <h2 class="relative group"><a id="group-provisioning" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#group-provisioning"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>Group provisioning</span></h2> <p data-svelte-h="svelte-wwselg">In addition to user provisioning, SCIM supports <strong>group provisioning</strong>. Groups pushed from your IdP are stored as SCIM groups on Hugging Face and can be linked to <a href="./enterprise-resource-groups">Resource Groups</a> from the <strong>SCIM</strong> tab in your organization’s settings.</p> <h3 class="relative group"><a id="linking-a-scim-group-to-a-resource-group" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#linking-a-scim-group-to-a-resource-group"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>Linking a SCIM group to a Resource Group</span></h3> <p data-svelte-h="svelte-1ae7xe4">To link a SCIM group, go to your organization’s <strong>SSO → SCIM</strong> tab. Provisioned groups are listed in a table. In the <strong>Resource Groups</strong> column, each group shows either a <strong>Link resource groups</strong> button (if no links exist yet) or the number of currently linked resource groups (e.g. “2 resource groups”). Clicking either opens a modal where you can add one or more Resource Groups, each with its own role assignment. You can also change or remove existing links from the same modal.</p> <p data-svelte-h="svelte-46qc4y">Before linking, make sure the following conditions are met:</p> <ul data-svelte-h="svelte-1oj1mth"><li>The Resource Group must have <strong>no existing members</strong>. Linking to a non-empty Resource Group is not allowed.</li> <li>The Resource Group must <strong>not have auto-join enabled</strong>. Auto-join (which automatically adds every new org member to the RG) is mutually exclusive with SCIM management. Disable auto-join on the RG before linking.</li></ul> <p data-svelte-h="svelte-dw6xag">A SCIM group can be linked to multiple Resource Groups, each with its own role.</p> <h3 class="relative group"><a id="what-happens-after-linking" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#what-happens-after-linking"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>What happens after linking</span></h3> <p data-svelte-h="svelte-1gdlgvz">Once a SCIM group is linked to a Resource Group:</p> <ul data-svelte-h="svelte-e2awjg"><li><strong>Backfill</strong>: Any members already in the SCIM group are immediately added to the Resource Group at the configured role.</li> <li><strong>Ongoing sync</strong>: Membership changes in your IdP are automatically reflected:
<ul><li>When a user is <strong>added</strong> to the group in your IdP, they are added to all linked Resource Groups.</li> <li>When a user is <strong>removed</strong> from the group in your IdP, they are removed from all linked Resource Groups, except those the user is linked to through other SCIM groups. For those, the user’s role will be updated to the “highest” role granted by the other SCIM groups.</li> <li>When a SCIM group is <strong>deleted</strong> in your IdP, all its members are removed from the linked Resource Groups, except for users who belong to those Resource Groups through other SCIM groups. For each of those Resource Groups, users’ roles are updated to the “highest” role granted by the other SCIM groups.</li></ul></li> <li><strong>Role changes</strong>: If you update the role on a link, all current group members’ roles in that Resource Group are updated immediately.</li></ul> <h3 class="relative group"><a id="scim-managed-resource-groups" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#scim-managed-resource-groups"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>SCIM-managed Resource Groups</span></h3> <p data-svelte-h="svelte-1sbievt">A Resource Group linked to a SCIM group is considered <strong>SCIM-managed</strong>. The IdP is the sole source of truth for its membership. As a result:</p> <ul data-svelte-h="svelte-1f3f2p8"><li>Manual membership changes via the Hub UI or API are <strong>blocked</strong> — any attempt to add, remove, or change a member’s role on a SCIM-managed Resource Group will return a <code>403</code> error.</li> <li>Auto-join <strong>cannot be enabled</strong> on a SCIM-managed Resource Group. To re-enable auto-join, first remove the SCIM link.</li></ul> <p data-svelte-h="svelte-nghesc">Group provisioning works the same way for both Basic SSO and Managed SSO.</p> <h2 class="relative group"><a id="supported-user-attributes" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#supported-user-attributes"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>Supported user attributes</span></h2> <p data-svelte-h="svelte-npn80i">The Hugging Face SCIM endpoint supports the following user attributes:</p> <table data-svelte-h="svelte-15ioq5j"><thead><tr><th>Attribute</th> <th>Description</th> <th>Basic SSO</th> <th>Managed SSO</th></tr></thead> <tbody><tr><td><code>userName</code></td> <td>Hugging Face username</td> <td>Read-only</td> <td>Read/Write</td></tr> <tr><td><code>name.givenName</code></td> <td>First name</td> <td>Read-only</td> <td>Read/Write</td></tr> <tr><td><code>name.familyName</code></td> <td>Last name</td> <td>Read-only</td> <td>Read/Write</td></tr> <tr><td><code>emails[type eq &quot;work&quot;].value</code></td> <td>Email address</td> <td>Read-only</td> <td>Read/Write</td></tr> <tr><td><code>externalId</code></td> <td>IdP-assigned identifier</td> <td>Read/Write</td> <td>Read/Write</td></tr> <tr><td><code>active</code></td> <td>Whether the user is an active member</td> <td>Read/Write</td> <td>Read/Write</td></tr></tbody></table> <p data-svelte-h="svelte-1raq40l">With Basic SSO, only <code>active</code> and <code>externalId</code> can be modified via SCIM — all other attributes are controlled by the user on their Hugging Face account.</p> <p data-svelte-h="svelte-1h69t05">For group provisioning, the supported attributes are <code>displayName</code>, <code>members</code>, and <code>externalId</code>.</p> <h2 class="relative group"><a id="deprovisioning" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#deprovisioning"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>Deprovisioning</span></h2> <p data-svelte-h="svelte-e1l2h0">Deprovisioning behavior depends on how the user is removed and which SSO model you use.</p> <p data-svelte-h="svelte-v3n7bs"><strong>Setting <code>active</code> to <code>false</code></strong> (soft deprovision):</p> <ul data-svelte-h="svelte-poytm6"><li>The user loses access to the organization</li> <li>With Basic SSO: the invitation is deactivated</li> <li>With Managed SSO: the user is removed from the organization but their account and content are preserved — this is <strong>reversible</strong> by setting <code>active</code> back to <code>true</code></li></ul> <p data-svelte-h="svelte-qct4sf"><strong>Deleting the user via SCIM</strong> (hard deprovision):</p> <ul data-svelte-h="svelte-11cykg"><li>With Basic SSO: the user is removed from the organization and all its resource groups. Their Hugging Face account and personal content are <strong>not affected</strong> — they simply lose membership in your organization.</li> <li>With Managed SSO: the user’s Hugging Face account is <strong>permanently deleted</strong>, along with all content they created. This action is <strong>irreversible</strong>.</li></ul> <h2 class="relative group"><a id="supported-identity-providers" class="header-link block pr-1.5 text-lg no-hover:hidden with-hover:absolute with-hover:p-1.5 with-hover:opacity-0 with-hover:group-hover:opacity-100 with-hover:right-full" href="#supported-identity-providers"><span><svg class="" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 256 256"><path d="M167.594 88.393a8.001 8.001 0 0 1 0 11.314l-67.882 67.882a8 8 0 1 1-11.314-11.315l67.882-67.881a8.003 8.003 0 0 1 11.314 0zm-28.287 84.86l-28.284 28.284a40 40 0 0 1-56.567-56.567l28.284-28.284a8 8 0 0 0-11.315-11.315l-28.284 28.284a56 56 0 0 0 79.196 79.197l28.285-28.285a8 8 0 1 0-11.315-11.314zM212.852 43.14a56.002 56.002 0 0 0-79.196 0l-28.284 28.284a8 8 0 1 0 11.314 11.314l28.284-28.284a40 40 0 0 1 56.568 56.567l-28.285 28.285a8 8 0 0 0 11.315 11.314l28.284-28.284a56.065 56.065 0 0 0 0-79.196z" fill="currentColor"></path></svg></span></a> <span>Supported Identity Providers</span></h2> <p data-svelte-h="svelte-1qpjay6">We support SCIM with any IdP that implements the SCIM 2.0 protocol. We have specific guides for some of the most popular providers:</p> <ul data-svelte-h="svelte-1i046mv"><li><a href="./security-sso-entra-id-scim">How to configure SCIM with Microsoft Entra ID</a></li> <li><a href="./security-sso-okta-scim">How to configure SCIM with Okta</a></li></ul> <a class="!text-gray-400 !no-underline text-sm flex items-center not-prose mt-4" href="https://github.com/huggingface/hub-docs/blob/main/docs/hub/enterprise-scim.md" target="_blank"><svg class="mr-1" xmlns="http://www.w3.org/2000/svg" aria-hidden="true" fill="currentColor" focusable="false" role="img" width="1em" height="1em" preserveAspectRatio="xMidYMid meet" viewBox="0 0 32 32"><path d="M31,16l-7,7l-1.41-1.41L28.17,16l-5.58-5.59L24,9l7,7z"></path><path d="M1,16l7-7l1.41,1.41L3.83,16l5.58,5.59L8,23l-7-7z"></path><path d="M12.419,25.484L17.639,6.552l1.932,0.518L14.351,26.002z"></path></svg> <span data-svelte-h="svelte-zjs2n5"><span class="underline">Update</span> on GitHub</span></a> <p></p>
<script>
{
__sveltekit_1bollga = {
assets: "/docs/hub/pr_2521/en",
base: "/docs/hub/pr_2521/en",
env: {}
};
const element = document.currentScript.parentElement;
const data = [null,null];
Promise.all([
import("/docs/hub/pr_2521/en/_app/immutable/entry/start.d19e5ca7.js"),
import("/docs/hub/pr_2521/en/_app/immutable/entry/app.98ab229a.js")
]).then(([kit, app]) => {
kit.start(app, element, {
node_ids: [0, 81],
data,
form: null,
error: null
});
});
}
</script>

Xet Storage Details

Size:
30.1 kB
·
Xet hash:
3a35224c9e964c9d6c8cb4edcf76d4514163005bad5144885643dd513568ea1a

Xet efficiently stores files, intelligently splitting them into unique chunks and accelerating uploads and downloads. More info.