Configuring KeyCloak SCIM integration for Nintex Automation K2

Use this guide to configure and install the SCIM test app in KeyCloak as your method of identity provisioning.

Supported features

The following items are the current features supported by the KeyCloak SCIM integration for Nintex Automation K2:

  • SP-initiated SSO
  • Create Users
  • Update User Attributes
  • Deactivate/Reactivate Users
  • Group Push

Considerations

  • SharePoint OnPrem/Online login with K2 configured using OIDC not supported

  • K2 Mobile Workspace (API authentication limitations)

  • We do not take responsibility for issues caused by the keycloak-scim provider or its compatibility with specific Keycloak versions. Customers use this third-party component at their own risk.

  • SCIM was tested with Keycloak v26.4.5 (latest at the time of Nintex Automation K2 (5.9) testing), and later versions v26.4.6 and v26.4.7 are not compatible due to a Keycloak defect that prepends a “/” to the user ID, causing user lookup to fail before any SCIM call is made.