Skip to content
mcp/skillhub

Microsoft Entra SCIM MCP Server

by darrenjrobinsonio.github.darrenjrobinson/entra-scim-mcpv0.3.0

Microsoft Entra SCIM 2.0 Provisioning API: user and group lifecycle, with a local mock.

2Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active10d ago

Install Microsoft Entra SCIM MCP server

Install in Claude Code

claude mcp add entra-scim -e ENTRA_CLIENT_SECRET='<entra-client-secret>' -e ENTRA_CLIENT_CERT_PASSWORD='<entra-client-cert-password>' -e ENTRA_SCIM_STATIC_TOKEN='<entra-scim-static-token>' -- npx -y entra-scim-mcp

Configuration

VariableRequiredSecretDescription
ENTRA_TENANT_ID——Directory (tenant) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN, which supply their own placeholder.
ENTRA_CLIENT_ID——App registration (client) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN.
ENTRA_CLIENT_SECRET—yesClient secret value. For a live tenant set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH; a certificate is preferred for anything long-lived.
ENTRA_CLIENT_CERT_PATH——Path to a PEM holding the certificate and its private key. Set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH.
ENTRA_CLIENT_CERT_PASSWORD—yesPassword for the PEM, if it is encrypted.
ENTRA_SCIM_BASE_URL——Override the SCIM base URL (default https://graph.microsoft.com/rp/scim). Point it at the bundled mock to try the tools without a tenant.
ENTRA_SCIM_STATIC_TOKEN—yesUse a fixed bearer token instead of Azure AD. Refuses any microsoft.com/microsoft.us host and requires ENTRA_SCIM_BASE_URL; intended for the local mock only.
ENTRA_SCIM_DRY_RUN——Set to 1 to run every client-side validation and return the request that would have been sent, without sending it or acquiring a token.

Freshness

Active — last maintenance signal 10d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-09-30 · 10d ago · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-30 · 10d ago · official registry · v0.3.0

FAQ

›How do I install the Microsoft Entra SCIM MCP server in Claude Code?

Run: claude mcp add entra-scim -e ENTRA_CLIENT_SECRET='<entra-client-secret>' -e ENTRA_CLIENT_CERT_PASSWORD='<entra-client-cert-password>' -e ENTRA_SCIM_STATIC_TOKEN='<entra-scim-static-token>' -- npx -y entra-scim-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Microsoft Entra SCIM require an API key?

Yes. It expects ENTRA_CLIENT_SECRET, ENTRA_CLIENT_CERT_PASSWORD, ENTRA_SCIM_STATIC_TOKEN, of which 3 are secrets.

›Can I use Microsoft Entra SCIM as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Microsoft Entra SCIM in the official MCP registry?

Yes, as io.github.darrenjrobinson/entra-scim-mcp.