Skip to content
Joan Help

Provision and manage users from OneLogin

Joan uses a System for Cross-Domain Identity Management (SCIM) to enable the automatic provisioning of users from OneLogin. When enabled, all user management will be done only in OneLogin and disabled on Joan's side.

1. Enable SCIM integration in MyJoan

  1. Go to the user directory and click SCIM.
  2. In the window that opens, enable the integration.
  3. Generate a new token. You will use it to authenticate the connection between OneLogin and Joan.
scim 2

2. Create a new application in your OneLogin account.

  1. On the Applications subpage, search for "scim".
  2. Select SCIM Provisioner with SAML (SCIM v2 Enterprise). This is a generic SCIM integration application provided by OneLogin.
Screenshot 2021 03 25 at 10.59.56
  1. Enter the application display name (e.g. Joan Integration) and click Save.
Screenshot 2021 03 25 at 12.02.33

A new application is created. In the next steps, you configure it to connect to your Joan account.

3. Configure Joan SCIM OneLogin application

  1. Go to the Configuration subpage of the new application.
  2. Enter the following values:

SCIM Base URL: https://portal.getjoan.com/api/scim/v2
SCIM Bearer Token: copy it from Joan SCIM configuration page.
SCIM JSON Template:

{
  "schemas": [
    "urn:scim:schemas:core:2.0"
  ],
  "active": "{$user.status}",
  "userName": "{$user.email}",
  "name": {
    "givenName": "{$user.firstname}",
    "familyName": "{$user.lastname}"
  },
  "externalId":"{$user.external_id}",
  "userType":"{$user.custom_fields.userType}"
}

All fields, apart from the "userType" are mandatory. A "userType" field is used to properly map roles from your OneLogin directory to Joan. It helps you automatically manage roles and permissions in your Joan account. If the "userType" field is not included or empty all created users will have a default "User" role assigned in your Joan account.

Currently supported Joan account roles:

  • User
  • Office Manager
Screenshot 2021 03 25 at 12.04.34
  1. Click Save.

To sync roles automatically from OneLogin, continue with step 3a below. If not, continue with step 4.

3a. [Optional] Configure userType custom field

To sync roles automatically with Joan, configure the mappings in OneLogin as follows.

a. Create a new Custom User Field

  1. Go to Users > Custom User Fields and click New User Field.
Screenshot 2021 03 25 at 12.14.13Screenshot 2021 03 25 at 12.15.05
  1. Enter these values:
    Name: userType
    Shortname: userType
  2. Click Save.
Screenshot 2021 03 25 at 12.15.32

b. Add a new userType application parameter

  1. Go to Applications and select the Joan integration you created.
  2. In the left menu, click Parameters, then click + to add a new one.
Screenshot 2021 03 25 at 12.07.59
  1. In Field name, type "userType" and tick Include in SAML assertion.
  2. Click Save.
Screenshot 2021 03 25 at 12.09.02
  1. Edit the new parameter. For Value, select the custom user field "userType" you created.
  2. Click Save.
Screenshot 2021 03 25 at 12.11.10

c. Create mapping

Now map your OneLogin roles to Joan roles. Joan currently supports the following account roles:

  • User
  • Office Manager

All users from OneLogin get the "User" role by default, so you only need one mapping, for "Office Manager".

  1. Go to Users > Mappings and create a new mapping.
Screenshot 2021 03 25 at 12.16.04
  1. In the Actions dropdown, select Set userType and set the mapping to "Office Manager".
  2. Click Save.
Screenshot 2021 03 25 at 12.17.46

4. Enable integration

  1. Go to Configuration > API Connection and click Enable. The API Status changes to green/Enabled.
Screenshot 2021 03 25 at 12.06.49
  1. Go to the Provisioning subpage and make sure the following checkboxes and values are set:
Screenshot 2021 03 25 at 12.12.09

You can now start adding users. They sync automatically with your Joan account.

If you encounter any issues, please contact support@getjoan.com.

Was this helpful?