Microsoft Entra SCIM MCP Server
by darrenjrobinsonio.github.darrenjrobinson/entra-scim-mcpv0.3.0
Microsoft Entra SCIM 2.0 Provisioning API: user and group lifecycle, with a local mock.
context tax
queued
security
queued
cold start
queued
freshness
Active10d ago
Install Microsoft Entra SCIM MCP server
Install in Claude Code
claude mcp add entra-scim -e ENTRA_CLIENT_SECRET='<entra-client-secret>' -e ENTRA_CLIENT_CERT_PASSWORD='<entra-client-cert-password>' -e ENTRA_SCIM_STATIC_TOKEN='<entra-scim-static-token>' -- npx -y entra-scim-mcpInstall in Cursor
{
"mcpServers": {
"entra-scim": {
"command": "npx",
"args": [
"-y",
"entra-scim-mcp"
],
"env": {
"ENTRA_CLIENT_SECRET": "<entra-client-secret>",
"ENTRA_CLIENT_CERT_PASSWORD": "<entra-client-cert-password>",
"ENTRA_SCIM_STATIC_TOKEN": "<entra-scim-static-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"entra-scim": {
"command": "npx",
"args": [
"-y",
"entra-scim-mcp"
],
"env": {
"ENTRA_CLIENT_SECRET": "<entra-client-secret>",
"ENTRA_CLIENT_CERT_PASSWORD": "<entra-client-cert-password>",
"ENTRA_SCIM_STATIC_TOKEN": "<entra-scim-static-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"entra-scim": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"entra-scim-mcp"
],
"env": {
"ENTRA_CLIENT_SECRET": "<entra-client-secret>",
"ENTRA_CLIENT_CERT_PASSWORD": "<entra-client-cert-password>",
"ENTRA_SCIM_STATIC_TOKEN": "<entra-scim-static-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"entra-scim": {
"command": "npx",
"args": [
"-y",
"entra-scim-mcp"
],
"env": {
"ENTRA_CLIENT_SECRET": "<entra-client-secret>",
"ENTRA_CLIENT_CERT_PASSWORD": "<entra-client-cert-password>",
"ENTRA_SCIM_STATIC_TOKEN": "<entra-scim-static-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| ENTRA_TENANT_ID | — | — | Directory (tenant) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN, which supply their own placeholder. |
| ENTRA_CLIENT_ID | — | — | App registration (client) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN. |
| ENTRA_CLIENT_SECRET | — | yes | Client secret value. For a live tenant set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH; a certificate is preferred for anything long-lived. |
| ENTRA_CLIENT_CERT_PATH | — | — | Path to a PEM holding the certificate and its private key. Set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH. |
| ENTRA_CLIENT_CERT_PASSWORD | — | yes | Password for the PEM, if it is encrypted. |
| ENTRA_SCIM_BASE_URL | — | — | Override the SCIM base URL (default https://graph.microsoft.com/rp/scim). Point it at the bundled mock to try the tools without a tenant. |
| ENTRA_SCIM_STATIC_TOKEN | — | yes | Use a fixed bearer token instead of Azure AD. Refuses any microsoft.com/microsoft.us host and requires ENTRA_SCIM_BASE_URL; intended for the local mock only. |
| ENTRA_SCIM_DRY_RUN | — | — | Set to 1 to run every client-side validation and return the request that would have been sent, without sending it or acquiring a token. |
Freshness
Active — last maintenance signal 10d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-30 · 10d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-09-30 · 10d ago · official registry · v0.3.0
FAQ
›How do I install the Microsoft Entra SCIM MCP server in Claude Code?
Run: claude mcp add entra-scim -e ENTRA_CLIENT_SECRET='<entra-client-secret>' -e ENTRA_CLIENT_CERT_PASSWORD='<entra-client-cert-password>' -e ENTRA_SCIM_STATIC_TOKEN='<entra-scim-static-token>' -- npx -y entra-scim-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Microsoft Entra SCIM require an API key?
Yes. It expects ENTRA_CLIENT_SECRET, ENTRA_CLIENT_CERT_PASSWORD, ENTRA_SCIM_STATIC_TOKEN, of which 3 are secrets.
›Can I use Microsoft Entra SCIM as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Microsoft Entra SCIM in the official MCP registry?
Yes, as io.github.darrenjrobinson/entra-scim-mcp.