SSO and SCIM: SAML, OIDC, Provisioning, and Enterprise

SSO (SAML/OIDC) and SCIM (automated user provisioning) are the two integrations enterprise IT expects before signing.

SSO and SCIM: The Enterprise Table-Stakes You Need Before Selling to IT

SSO (Single Sign-On) lets enterprise employees log into your product using their existing identity provider (Okta, Azure AD, Google Workspace). SCIM (System for Cross-domain Identity Management) automatically provisions and de-provisions users based on IdP group membership. Together they're the two integrations enterprise IT will insist on before signing — and they're where every SaaS company hits the 'we can't sell to enterprise without them' wall.

SAML vs OIDC

Both are enterprise SSO protocols. SAML is older, XML-based, still dominant in enterprise IT. OIDC is newer, JSON-based, easier to implement, standard in modern setups. Enterprise IT will typically request SAML because that's what their IdP admins know; supporting both is the safe answer. Most auth providers (WorkOS, Auth0, Frontegg, Stytch) handle both with one integration.

SCIM in practice

SCIM automates the four lifecycle events: (1) User created in IdP → auto-provisioned in your app. (2) User attribute changed (department, role) → synced. (3) User group membership changed → app permissions updated. (4) User deprovisioned in IdP → deactivated in your app within minutes. Without SCIM, IT admins manually manage users in your app, which they refuse to do at scale.

Build vs buy

Building SSO/SCIM from scratch: 3-6 engineer-months, plus ongoing IdP-specific edge cases. Auth providers (WorkOS, Frontegg, Descope, Stytch) charge $100-$500/enterprise-connection/month and handle the protocols, IdP quirks, and admin UI. For most SaaS companies, buying is the right answer — build only if identity is a core product surface (e.g., you are an auth company).

The 'SSO tax' debate

Historical practice: SSO is gated to Enterprise plans (often at 2-5x the price of Team plans). sso.tax exists as a public shaming site for the practice. The counter-argument: SCIM/SAML integrations require ongoing enterprise-support commitments that free-tier economics can't support. Modern consensus: SAML/SCIM behind Enterprise tier is defensible; blocking basic SSO (Google/Microsoft OAuth on individual accounts) behind Enterprise is not.

What to test before shipping

Test against the top IdPs your customers use (Okta, Azure AD/Entra, Google Workspace, OneLogin, JumpCloud, Ping). Each has quirks — attribute mapping edge cases, deprovisioning delays, group-sync limits. Enterprise buyers will run their own IT test in a sandbox before signing; if the integration breaks in that test, the deal stalls indefinitely.

Frequently asked questions

Do we need SSO for our first enterprise deal?
Yes. Enterprise IT security reviews will fail your app without at least SAML SSO. SCIM is 'strongly preferred' at $50K+ deals and required at $250K+.
Which auth provider should we use?
WorkOS is the market leader for B2B SaaS SSO/SCIM. Auth0 is broader (consumer + B2B). Frontegg, Descope, Stytch are newer challengers. For a pure enterprise B2B use case starting from scratch, WorkOS is usually the fastest path.
How long does SSO/SCIM implementation take?
With an auth provider: 1-3 weeks for SAML SSO, 2-4 weeks for SCIM. From scratch: 2-4 months and ongoing maintenance load.

Related fundraising guides (40)

Investor directory · Fundraising library · Articles A–Z · Company funding database