Skip to main content

Self-serve Directory Sync

Category
SSO
Published

Your customers' IT admins can set up Directory Sync for their own SSO connection, including Google Workspace, from the Security tab in <OrganizationProfile />.

Directory Sync provisions, updates, and deprovisions an Organization's members as its identity provider changes. Until now, your team configured it in the Clerk Dashboard and handed a SCIM endpoint and bearer token to each customer's IT admin. Self-serve Directory Sync moves that setup into the Security tab of <OrganizationProfile />, next to self-serve SSO, so the admin who configured the SSO connection can finish provisioning without Dashboard access.

Note

Self-serve Directory Sync requires Clerk Organizations and builds on self-serve SSO. It's free in development instances. In production, your application needs the Pro or Business plan and the B2B Authentication add-on.

How it works

When self-serve SSO is enabled for an Organization, a Directory Sync section appears beneath the SSO section in that Organization's Security tab. An admin with the org:sys_entconns:manage permission opens a three-step wizard. Clerk picks the directory provider from the SSO connection, so Okta Workforce, Microsoft Entra ID, Google Workspace, and custom SAML or OIDC connections each get the matching setup.

  • Configure: For most identity providers, Clerk generates a SCIM endpoint URL and bearer token, along with setup instructions for that IdP. For Google Workspace, Clerk reads the directory through Google's Admin SDK. The admin uploads a service account key and enters the email address of a Workspace admin account for Clerk to act as.
  • Review attributes: The standard mappings Clerk applies are listed, so the admin knows what will be stored.
  • Test provisioning: The admin assigns a test user in their IdP and watches it appear. For Google Workspace, they can trigger a sync and see the result of the last run.

Provisioning works before the SSO connection is active, so an admin can populate the Organization's membership first and turn on SSO when they're ready. After setup, the admin can pause, resume, or remove the directory from the same section.

What your team sees

In the Clerk Dashboard, a self-serve directory looks like any other directory. You still control Custom attribute mapping and Role mapping, and Role mapping is off by default for self-serve directories..

Get started

In the Clerk Dashboard, select an Organization, open its Settings, and turn on Allow this organization to set up enterprise SSO and Directory Sync under Organization permissions. The Security tab then surfaces wherever your app renders <OrganizationProfile />, including through <OrganizationSwitcher />.

For setup details and requirements, refer to the self-serve Directory Sync documentation.

Contributors
Jim Kalafut
Gabriel Melo

Share this article