## 1. Enable SCIM integration in MyJoan

1. Go to the [user directory](https://my.getjoan.com/settings/people/overview) and click **SCIM**.
2. In the window that opens, enable the integration.
3. Generate a new token. You will use it to authenticate the connection between OneLogin and Joan.

![scim 2](https://getjoan.com/help/api/media/file/scim-2.png)

## 2. Create a new application in your OneLogin account.

1. On the **Applications** subpage, search for "*scim*".
2. Select **SCIM Provisioner with SAML (SCIM v2 Enterprise)**. This is a generic SCIM integration application provided by OneLogin.

![Screenshot 2021 03 25 at 10.59.56](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-10.59.56.png)

3. Enter the application display name (e.g. Joan Integration) and click **Save**.

![Screenshot 2021 03 25 at 12.02.33](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.02.33.png)

A new application is created. In the next steps, you configure it to connect to your Joan account.

## 3. Configure Joan SCIM OneLogin application

1. Go to the **Configuration** subpage of the new application.
2. Enter the following values:

**SCIM Base URL:** [https://portal.getjoan.com/api/scim/v2](https://portal.getjoan.com/api/scim/v2/)\
**SCIM Bearer Token:** copy it from Joan SCIM configuration page.\
**SCIM JSON Template:**

```plaintext
{
  "schemas": [
    "urn:scim:schemas:core:2.0"
  ],
  "active": "{$user.status}",
  "userName": "{$user.email}",
  "name": {
    "givenName": "{$user.firstname}",
    "familyName": "{$user.lastname}"
  },
  "externalId":"{$user.external_id}",
  "userType":"{$user.custom_fields.userType}"
}
```

All fields, apart from the "userType" are mandatory. A "userType" field is used to properly map roles from your OneLogin directory to Joan. It helps you automatically manage roles and permissions in your Joan account. If the "userType" field is not included or empty all created users will have a default "User" role assigned in your Joan account.

Currently supported Joan account roles:

- User
- Office Manager

![Screenshot 2021 03 25 at 12.04.34](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.04.34.png)

3. Click **Save**.

To sync roles automatically from OneLogin, continue with [step 3a](#TwoA) below. If not, continue with [step 4](#Three).

## {#TwoA}3a.  [Optional] Configure userType custom field

To sync roles automatically with Joan, configure the mappings in OneLogin as follows.

## a. Create a new Custom User Field

1. Go to **Users > Custom User Fields** and click **New User Field**.

![Screenshot 2021 03 25 at 12.14.13](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.14.13.png)

![Screenshot 2021 03 25 at 12.15.05](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.15.05.png)

2. Enter these values:\
**Name:** userType\
**Shortname:** userType
3. Click **Save**.

![Screenshot 2021 03 25 at 12.15.32](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.15.32.png)

## b. Add a new userType application parameter

1. Go to **Applications** and select the Joan integration you created.
2. In the left menu, click **Parameters**, then click **+** to add a new one.

![Screenshot 2021 03 25 at 12.07.59](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.07.59.png)

3. In **Field name**, type "userType" and tick **Include in SAML assertion**.
4. Click **Save**.

![Screenshot 2021 03 25 at 12.09.02](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.09.02.png)

5. Edit the new parameter. For **Value**, select the custom user field "userType" you created.
6. Click **Save**.

![Screenshot 2021 03 25 at 12.11.10](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.11.10.png)

## c. Create mapping

Now map your OneLogin roles to Joan roles. Joan currently supports the following account roles:

- User
- Office Manager

All users from OneLogin get the "User" role by default, so you only need one mapping, for "Office Manager".

1. Go to **Users > Mappings** and create a new mapping.

![Screenshot 2021 03 25 at 12.16.04](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.16.04.png)

2. In the **Actions** dropdown, select **Set userType** and set the mapping to "Office Manager".
3. Click **Save**.

![Screenshot 2021 03 25 at 12.17.46](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.17.46.png)

### {#Three}4.  Enable integration

1. Go to **Configuration > API Connection** and click **Enable**. The API Status changes to green/Enabled.

![Screenshot 2021 03 25 at 12.06.49](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.06.49.png)

2. Go to the **Provisioning** subpage and make sure the following checkboxes and values are set:

![Screenshot 2021 03 25 at 12.12.09](https://getjoan.com/help/api/media/file/Screenshot-2021-03-25-at-12.12.09.png)

You can now start adding users. They sync automatically with your Joan account.

If you encounter any issues, please contact [support@getjoan.com](mailto:support@getjoan.com).
