SCIM is a paid add-on for Pro and Premium plans: $125 per month on top of your subscription (billed annually on yearly plans), covering one directory connection. It requires an active paid subscription, so it can’t be enabled during a trial. On Enterprise plans SCIM is included, with no add-on charge. Workspace owners can enable it self-service under Settings → Security. Enterprise customers looking to purchase multiple licenses can reach out to sales@tella.com.
What does SCIM do in Tella?
With SCIM enabled, your identity provider becomes the source of truth for your Tella workspace membership:- Provision users: when you assign someone to Tella in your identity provider, they’re automatically added to your workspace.
- Deprovision users: when you remove someone, their Tella workspace access is revoked and their sessions are signed out.
- Keep attributes in sync: names and roles in your directory are kept in sync with Tella.
Which directories are supported?
SCIM provisioning works with any SCIM 2.0-compatible directory, including:- Okta
- Azure Active Directory (Entra ID)
- Google Workspace
- OneLogin
- JumpCloud
- PingFederate
Set up SCIM
- Enable the add-on: as a workspace owner, go to Settings → Security, select Directory sync (SCIM), and click Enable SCIM. The $125/month add-on is added to your existing workspace subscription, prorated for the current billing period (on Enterprise plans there’s no charge. SCIM is included). SCIM is typically set up alongside SSO.
- Connect your directory: once the add-on is active, click Connect your directory to open the guided setup. Pick your identity provider and follow the steps; you’ll get the SCIM endpoint URL and API token to enter in your provider’s directory sync settings, and you’ll be returned to Tella when you’re done.
- Assign users: assign users or groups to the Tella application in your identity provider. They’ll be provisioned automatically.
Need help, or on a custom enterprise agreement? Contact us and we’ll set SCIM up with you.