# Self-serve Directory Sync

[Directory Sync](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/directory-sync.md) provisions, updates, and deprovisions an Organization's members as its identity provider changes. Until now, your team configured it in the Clerk Dashboard and handed a SCIM endpoint and bearer token to each customer's IT admin. Self-serve Directory Sync moves that setup into the **Security** tab of [`<OrganizationProfile />`](https://clerk.com/docs/reference/components/organization/organization-profile.md), next to [self-serve SSO](https://clerk.com/changelog/2026-06-26-self-serve-sso.md), so the admin who configured the SSO connection can finish provisioning without Dashboard access.

> Self-serve Directory Sync requires [Clerk Organizations](https://clerk.com/docs/guides/organizations/overview.md) and builds on self-serve SSO. It's free in development instances. In production, your application needs the Pro or Business plan and the [B2B Authentication add-on](https://clerk.com/pricing).

## How it works

When self-serve SSO is enabled for an Organization, a **Directory Sync** section appears beneath the SSO section in that Organization's Security tab. An admin with the `org:sys_entconns:manage` permission opens a three-step wizard. Clerk picks the directory provider from the SSO connection, so Okta Workforce, Microsoft Entra ID, Google Workspace, and custom SAML or OIDC connections each get the matching setup.

- **Configure**: For most identity providers, Clerk generates a SCIM endpoint URL and bearer token, along with setup instructions for that IdP. For Google Workspace, Clerk reads the directory through Google's Admin SDK. The admin uploads a service account key and enters the email address of a Workspace admin account for Clerk to act as.
- **Review attributes**: The standard mappings Clerk applies are listed, so the admin knows what will be stored.
- **Test provisioning**: The admin assigns a test user in their IdP and watches it appear. For Google Workspace, they can trigger a sync and see the result of the last run.

Provisioning works before the SSO connection is active, so an admin can populate the Organization's membership first and turn on SSO when they're ready. After setup, the admin can pause, resume, or remove the directory from the same section.

## What your team sees

In the Clerk Dashboard, a self-serve directory looks like any other directory. You still control [Custom attribute mapping](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/custom-attribute-mapping.md) and [Role mapping](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/directory-sync.md#role-mapping), and Role mapping is off by default for self-serve directories..

## Get started

In the [Clerk Dashboard](https://dashboard.clerk.com/~/organizations), select an Organization, open its **Settings**, and turn on **Allow this organization to set up enterprise SSO and Directory Sync** under **Organization permissions**. The Security tab then surfaces wherever your app renders `<OrganizationProfile />`, including through `<OrganizationSwitcher />`.

For setup details and requirements, refer to the [self-serve Directory Sync documentation](https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/self-serve-directory-sync.md).
