User Provisioning (SCIM)
With SCIM, your identity provider keeps PeekHire in step with your directory. Assign someone the PeekHire app and their account appears. Change their name and it updates. Remove them, and they lose access without anyone logging into PeekHire to do it.
This is the piece that answers the offboarding question: when a person leaves the company, their access ends where every other access ends.
User provisioning is part of the Business plan and is available during the 7-day trial. Owners and admins can set it up.
Before You Start
Set up Single Sign-On first and verify at least one email domain. Provisioning only ever touches addresses on a domain you have proven you own, so without a verified domain there is nothing it can do.
Connecting Your Identity Provider
Go to Account → Single Sign-On and find Automatic User Provisioning (SCIM).
- Copy the base URL. It ends in
/scim/v2. - Create a token. Give it a name you will recognise later, such as the provider and environment. The token is shown once. Copy it now.
- Paste both into your provider. In Okta this is the Provisioning tab of the application, with SCIM connector base URL and HTTP Header as the authentication mode. In Microsoft Entra it is the Provisioning blade, with Tenant URL and Secret Token. Then use the provider's own Test Connection button.
- Choose what to sync. Create, update and deactivate are the three actions worth enabling.
What Gets Synced
| From your directory | In PeekHire |
|---|---|
userName or primary email | The member's email address |
name.givenName, name.familyName | First and last name |
active | Whether the person can sign in |
externalId | Kept so your provider can find the person again |
New people join as members. Promote anyone who needs more to admin from Account → Members. Roles are not taken from directory groups, so a role you set in PeekHire is never overwritten by a sync.
Deactivating and Removing
When your provider deactivates someone, or removes them from the application, they can no longer sign in by any route: not through single sign-on, not with a password, not with Google or Microsoft. Their ratings, notes and comments stay attached to the candidates they belong to, and they stop consuming a seat.
Reactivating them in your provider restores access with the same account.
A delete from your provider deactivates rather than erases, for the same reason. To remove the account and its personal data entirely, remove the member from Account → Members.
What Provisioning Will Not Do
It will not touch the workspace owner. An attempt to deactivate the owner is refused. Transfer ownership first if the owner is leaving.
It will not reach outside your verified domains. An address on any other domain is refused, even if your provider asks for it.
It will not take over an address that belongs to another workspace. You get a conflict, and that person keeps their existing account.
It does not sync groups. Group push is not supported; assign the application to people rather than to groups, or let your provider flatten groups into individual assignments.
Rotating a Token
Create a second token, paste it into your provider, confirm the sync still works, then revoke the old one. Both work at the same time, so there is no gap.
Revoke a token immediately if it may have leaked. Revoke asks for confirmation, then provisioning stops at once; sign-in is unaffected.
Troubleshooting
Your provider reports 401. The token is wrong or was revoked. Create a new one and paste it again.
Your provider reports 403. Either the workspace is no longer on the Business plan, or the sync tried to deactivate the owner.
Your provider reports 400 for one person. Their address is not on a verified domain. Check the domain under Single Sign-On.
Your provider reports 409 for one person. Either that address already has an account in a different PeekHire workspace, or your workspace has no seat left — free one up or upgrade your plan.