openapi: 3.2.0 info: contact: email: support@cockroachlabs.com name: Cockroach Labs Support url: https://support.cockroachlabs.com description: An API for managing CockroachDB Cloud resources title: CockroachDB Cloud SCIM API version: '2026-09-15' servers: - url: https://cockroachlabs.cloud security: - Bearer: [] tags: - name: SCIM paths: /api/scim/v2/Groups: get: operationId: CockroachCloud_GetGroups summary: List groups description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string - name: filter in: query schema: type: string - name: count in: query description: 'The maximum number of resources to return. If omitted, defaults to 20. If set to 0, the response will contain no resources but will include metadata such as `totalResults`, complying with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' schema: type: integer format: int32 - name: startIndex in: query description: 'The 1-based index of the first resource to return in the response. If omitted or less than 1, defaults to 1. This behavior complies with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' schema: type: integer format: int32 responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetGroupsResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/Groups?attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE&filter=SOME_STRING_VALUE&count=SOME_INTEGER_VALUE&startIndex=SOME_INTEGER_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" post: operationId: CockroachCloud_CreateGroup summary: Create a group description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateGroupRequest' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimGroup' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request POST \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"displayName\":\"Test SCIM\",\"members\":[],\"schemas\":[\"urn:ietf:params:scim:schemas:core:2.0:Group\"]}'" /api/scim/v2/Groups/.search: post: operationId: CockroachCloud_SearchGroups summary: Search groups description: 'Similar to GetGroups however search parameters are passed via the POST body. See https://www.rfc-editor.org/rfc/rfc7644.html#section-3.4.3 for more details. Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetGroupsRequest' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetGroupsResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request POST \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"count\":20,\"excludedAttributes\":\"string\",\"filter\":\"string\",\"startIndex\":1}'" put: operationId: CockroachCloud_GetGroups2 summary: Search groups (Deprecated) description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetGroupsRequest' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetGroupsResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' deprecated: true tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PUT \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"count\":20,\"excludedAttributes\":\"string\",\"filter\":\"string\",\"startIndex\":1}'" /api/scim/v2/Groups/{id}: delete: operationId: CockroachCloud_DeleteGroup summary: Delete a group based on ID description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' parameters: - name: id in: path required: true schema: type: string responses: '200': description: A successful response. content: application/json: schema: type: object '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request DELETE \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups/{id} \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" get: operationId: CockroachCloud_GetGroup summary: Get a group by ID description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: id in: path required: true schema: type: string - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimGroup' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/Groups/{id}?attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" patch: operationId: CockroachCloud_PatchGroup summary: Patch a group by supplying partial updates description: 'Apply a sequence of operations to modify attributes of a SCIM Group resource. Supports ''add'', ''remove'', and ''replace'' operations per RFC 7644 Section 3.5.2. Operations are applied atomically — if any operation fails, no changes are applied. The request body must include the ''schemas'' field set to ''urn:ietf:params:scim:api:messages:2.0:PatchOp''. Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PatchGroupBody' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimGroup' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PATCH \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups/{id} \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"Operations\":[{\"op\":\"replace\",\"path\":\"displayName\",\"value\":\"Updated Group Name\"},{\"op\":\"replace\",\"path\":\"externalId\",\"value\":\"ext-123\"},{\"op\":\"remove\",\"path\":\"members\"},{\"op\":\"add\",\"path\":\"externalId\",\"value\":\"new-external-id\"},{\"op\":\"add\",\"path\":\"members\",\"value\":[{\"value\":\"45a35c27-23d3-4d03-c4c5-9043c09e7175\"}]}],\"schemas\":[\"urn:ietf:params:scim:api:messages:2.0:PatchOp\"]}'" put: operationId: CockroachCloud_UpdateGroup summary: Update a group by supplying all values of the user object description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateGroupBody' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimGroup' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PUT \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups/{id} \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"displayName\":\"Test SCIM\",\"id\":\"23a35c27-23d3-4c03-b4c5-6443c09e7173\",\"members\":[{\"display\":\"croach@example.com\",\"value\":\"45a35c27-23d3-4d03-c4c5-9043c09e7175\"}],\"schemas\":[\"urn:ietf:params:scim:schemas:core:2.0:Group\"]}'" /api/scim/v2/Groups/{id}/.search: post: operationId: CockroachCloud_SearchGroup summary: Search a group by ID description: 'Similar to GetGroup however search parameters are passed via the POST body. See https://www.rfc-editor.org/rfc/rfc7644.html#section-3.4.3 for more details. Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SearchGroupBody' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimGroup' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request POST \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups/{id}/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"excludedAttributes\":\"string\"}'" put: operationId: CockroachCloud_GetGroup2 summary: Search a group by ID (Deprecated) description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetGroup2Body' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimGroup' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' deprecated: true tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PUT \\\n --url https://cockroachlabs.cloud/api/scim/v2/Groups/{id}/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"excludedAttributes\":\"string\"}'" /api/scim/v2/ResourceTypes: get: operationId: CockroachCloud_GetResourceTypes summary: List the SCIM resource types description: This endpoint may be used by any member of the organization. parameters: - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetResourceTypesResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/ResourceTypes?attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" /api/scim/v2/ResourceTypes/{resourceId}: get: operationId: CockroachCloud_GetResourceType summary: Get a SCIM resource type by ID description: This endpoint may be used by any member of the organization. parameters: - name: resourceId in: path required: true schema: type: string - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimResourceType' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/ResourceTypes/{resourceId}?attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" /api/scim/v2/Schemas: get: operationId: CockroachCloud_GetSchemas summary: List the SCIM schemas description: This endpoint may be used by any member of the organization. parameters: - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetSchemasResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/Schemas?attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" /api/scim/v2/Schemas/{schemaId}: get: operationId: CockroachCloud_GetSchema summary: Get a SCIM schema by ID description: This endpoint may be used by any member of the organization. parameters: - name: schemaId in: path required: true schema: type: string - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimSchema' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/Schemas/{schemaId}?attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" /api/scim/v2/ServiceProviderConfig: get: operationId: CockroachCloud_GetServiceProviderConfig summary: Return the SCIM Service Provider configuration description: This endpoint may be used by any member of the organization. responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetServiceProviderConfigResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url https://cockroachlabs.cloud/api/scim/v2/ServiceProviderConfig \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" /api/scim/v2/Users: get: operationId: CockroachCloud_GetUsers summary: List Users description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: filter in: query schema: type: string - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string - name: count in: query description: 'The maximum number of resources to return. If omitted, defaults to 20. If set to 0, the response will contain no resources but will include metadata such as `totalResults`, complying with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' schema: type: integer format: int32 - name: startIndex in: query description: 'The 1-based index of the first resource to return in the response. If omitted or less than 1, defaults to 1. This behavior complies with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' schema: type: integer format: int32 responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetUsersResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/Users?filter=SOME_STRING_VALUE&attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE&count=SOME_INTEGER_VALUE&startIndex=SOME_INTEGER_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" post: operationId: CockroachCloud_CreateUser summary: Create a user description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateUserRequest' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/CreateUserResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request POST \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"active\":true,\"displayName\":\"Carl Roach\",\"emails\":[{\"primary\":true,\"type\":\"work\",\"value\":\"croach@example.com\"}],\"externalId\":\"11ujl29u0le5T6Aj10h9\",\"name\":{\"familyName\":\"Roach\",\"givenName\":\"Carl\"},\"schemas\":[\"urn:ietf:params:scim:schemas:core:2.0:User\"],\"userName\":\"croach@example.com\"}'" /api/scim/v2/Users/.search: post: operationId: CockroachCloud_SearchUsers summary: Search Users description: 'Similar to GetUsers however search parameters are passed via the POST body. See https://www.rfc-editor.org/rfc/rfc7644.html#section-3.4.3 for more details. Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetUsersRequest' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetUsersResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request POST \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"count\":20,\"excludedAttributes\":\"string\",\"filter\":\"string\",\"startIndex\":1}'" put: operationId: CockroachCloud_GetUsers2 summary: Search User (Deprecated) description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetUsersRequest' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/GetUsersResponse' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' deprecated: true tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PUT \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"count\":20,\"excludedAttributes\":\"string\",\"filter\":\"string\",\"startIndex\":1}'" /api/scim/v2/Users/{id}: delete: operationId: CockroachCloud_DeleteUser summary: Delete a user based on ID description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' parameters: - name: id in: path required: true schema: type: string responses: '200': description: A successful response. content: application/json: schema: type: object '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request DELETE \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users/{id} \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" get: operationId: CockroachCloud_GetUser summary: Get a user by ID description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: id in: path required: true schema: type: string - name: attributes in: query schema: type: string - name: excludedAttributes in: query schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimUser' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request GET \\\n --url 'https://cockroachlabs.cloud/api/scim/v2/Users/{id}?attributes=SOME_STRING_VALUE&excludedAttributes=SOME_STRING_VALUE' \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN'" patch: operationId: CockroachCloud_PatchUser summary: Patch a user by supplying partial updates description: 'Apply a sequence of operations to modify attributes of a SCIM User resource. Supports ''add'', ''remove'', and ''replace'' operations per RFC 7644 Section 3.5.2. Operations are applied atomically — if any operation fails, no changes are applied. The request body must include the ''schemas'' field set to ''urn:ietf:params:scim:api:messages:2.0:PatchOp''. Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PatchUserBody' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimUser' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PATCH \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users/{id} \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"Operations\":[{\"op\":\"replace\",\"path\":\"userName\",\"value\":\"newUserName\"},{\"op\":\"replace\",\"value\":{\"displayName\":\"New Name\",\"emails\":[{\"primary\":true,\"value\":\"new@example.com\"}]}},{\"op\":\"remove\",\"path\":\"externalId\"}],\"schemas\":[\"urn:ietf:params:scim:api:messages:2.0:PatchOp\"]}'" put: operationId: CockroachCloud_UpdateUser summary: Update a user by supplying all values of the user object description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateUserBody' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimUser' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PUT \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users/{id} \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"active\":true,\"emails\":[{\"display\":\"croach@example.com\",\"primary\":true,\"type\":\"work\",\"value\":\"croach@example.com\"}],\"name\":{\"familyName\":\"Roach\",\"givenName\":\"Carl\"},\"schemas\":[\"urn:ietf:params:scim:schemas:core:2.0:User\"]}'" /api/scim/v2/Users/{id}/.search: post: operationId: CockroachCloud_SearchUser summary: Search for a user by ID description: 'Similar to GetUser however search parameters are passed via the POST body. See https://www.rfc-editor.org/rfc/rfc7644.html#section-3.4.3 for more details. Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SearchUserBody' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimUser' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request POST \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users/{id}/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"excludedAttributes\":\"string\"}'" put: operationId: CockroachCloud_GetUser2 summary: Search for a user by ID (Deprecated) description: 'Can be used by the following roles assigned at the organization scope: - ORG_ADMIN - AUDITOR' parameters: - name: id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GetUser2Body' responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/ScimUser' '400': description: Returned when a request field is invalid. content: application/json: schema: {} '401': description: Returned when the token bearer cannot be authenticated. content: application/json: schema: {} '403': description: Returned when the user does not have permission to access the resource. content: application/json: schema: {} '404': description: Returned when the resource does not exist. content: application/json: schema: {} '500': description: Server error content: application/json: schema: {} default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/Status' deprecated: true tags: - SCIM x-codeSamples: - lang: Shell + Curl source: "curl --request PUT \\\n --url https://cockroachlabs.cloud/api/scim/v2/Users/{id}/.search \\\n --header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --json '{\"attributes\":\"string\",\"excludedAttributes\":\"string\"}'" components: schemas: GetGroupsResponse: type: object properties: Resources: type: array items: $ref: '#/components/schemas/ScimGroup' itemsPerPage: type: integer format: int32 schemas: type: array items: type: string startIndex: type: integer format: int32 totalResults: type: integer format: int32 required: - schemas - totalResults title: GetGroupsResponse GetUsersResponse: type: object properties: Resources: type: array items: $ref: '#/components/schemas/ScimUser' itemsPerPage: type: integer format: int32 schemas: type: array items: type: string startIndex: type: integer format: int32 totalResults: type: integer format: int32 required: - schemas - totalResults title: GetUsersResponse Status: type: object properties: code: type: integer format: int32 details: type: array items: $ref: '#/components/schemas/Any' message: type: string GetGroup2Body: type: object properties: attributes: type: string excludedAttributes: type: string title: GetGroupRequest SearchUserBody: type: object properties: attributes: type: string excludedAttributes: type: string title: GetUserRequest ScimGroup: description: SCIM 2.0 Group Resource type: object properties: displayName: type: string externalId: type: string id: type: string members: type: array items: $ref: '#/components/schemas/ScimResource' meta: $ref: '#/components/schemas/ScimMetadata' schemas: type: array items: type: string required: - schemas - id - displayName title: ScimGroup ScimResource: type: object properties: display: type: string ref: type: string type: type: string value: type: string title: SCIM SearchGroupBody: type: object properties: attributes: type: string excludedAttributes: type: string title: GetGroupRequest ScimUser: description: SCIM 2.0 User Resource type: object properties: active: type: boolean displayName: type: string emails: type: array items: $ref: '#/components/schemas/ScimEmail' externalId: type: string groups: type: array items: $ref: '#/components/schemas/ScimResource' id: type: string meta: $ref: '#/components/schemas/ScimMetadata' name: $ref: '#/components/schemas/ScimName' schemas: type: array items: type: string userName: type: string required: - schemas - id title: ScimUser GetUsersRequest: type: object properties: attributes: type: string count: description: 'The maximum number of resources to return. If omitted, defaults to 20. If set to 0, the response will contain no resources but will include metadata such as `totalResults`, complying with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' type: integer format: int32 excludedAttributes: type: string filter: type: string startIndex: description: 'The 1-based index of the first resource to return in the response. If omitted or less than 1, defaults to 1. This behavior complies with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' type: integer format: int32 title: GetUsersRequest ScimSortSupport: type: object properties: supported: type: boolean required: - supported title: ScimSortSupport ScimEmail: type: object properties: display: type: string primary: type: boolean type: type: string value: type: string required: - value PatchGroupBody: type: object properties: Operations: type: array items: $ref: '#/components/schemas/ScimOperations' schemas: description: 'A list of one or more URIs identifying SCIM schemas that define the structure of the attributes in the request. The only supported schema at this time is "urn:ietf:params:scim:api:messages:2.0:PatchOp".' type: array items: type: string example: Operations: - op: replace path: displayName value: Updated Group Name - op: replace path: externalId value: ext-123 - op: remove path: members - op: add path: externalId value: new-external-id - op: add path: members value: - value: 45a35c27-23d3-4d03-c4c5-9043c09e7175 schemas: - urn:ietf:params:scim:api:messages:2.0:PatchOp required: - schemas - Operations title: PatchGroupRequest ScimBulkSupport: type: object properties: maxOperations: type: integer format: int32 maxPayloadSize: type: integer format: int32 supported: type: boolean required: - supported - maxOperations - maxPayloadSize title: ScimBulkSupport UpdateGroupBody: type: object properties: displayName: type: string externalId: type: string members: type: array items: $ref: '#/components/schemas/ScimResource' schemas: type: array items: type: string example: displayName: Test SCIM id: 23a35c27-23d3-4c03-b4c5-6443c09e7173 members: - display: croach@example.com value: 45a35c27-23d3-4d03-c4c5-9043c09e7175 schemas: - urn:ietf:params:scim:schemas:core:2.0:Group required: - schemas - displayName title: UpdateGroupRequest CreateUserResponse: description: Response when creating a new user via SCIM 2.0 type: object properties: active: type: boolean displayName: type: string emails: type: array items: $ref: '#/components/schemas/ScimEmail' externalId: type: string groups: type: array items: $ref: '#/components/schemas/ScimResource' id: type: string meta: $ref: '#/components/schemas/ScimMetadata' name: $ref: '#/components/schemas/ScimName' schemas: type: array items: type: string userName: type: string required: - schemas - id title: CreateUserResponse ScimMetadata: type: object properties: created: type: string lastModified: type: string location: type: string resourceType: type: string title: meta GetSchemasResponse: type: object properties: Resources: type: array items: $ref: '#/components/schemas/ScimSchema' itemsPerPage: type: integer format: int32 schemas: type: array items: type: string startIndex: type: integer format: int32 totalResults: type: integer format: int32 required: - schemas - totalResults title: GetSchemasResponse GetResourceTypesResponse: type: object properties: Resources: type: array items: $ref: '#/components/schemas/ScimResourceType' itemsPerPage: type: integer format: int32 schemas: type: array items: type: string startIndex: type: integer format: int32 totalResults: type: integer format: int32 required: - schemas - totalResults title: GetResourceTypesResponse CreateUserRequest: type: object properties: active: type: boolean displayName: type: string emails: type: array items: $ref: '#/components/schemas/ScimEmail' externalId: type: string name: $ref: '#/components/schemas/ScimName' schemas: type: array items: type: string userName: type: string example: active: true displayName: Carl Roach emails: - primary: true type: work value: croach@example.com externalId: 11ujl29u0le5T6Aj10h9 name: familyName: Roach givenName: Carl schemas: - urn:ietf:params:scim:schemas:core:2.0:User userName: croach@example.com required: - schemas - emails title: CreateUserRequest ScimChangePasswordSupport: type: object properties: supported: type: boolean required: - supported title: ScimChangePasswordSupport ScimResourceType: type: object properties: description: type: string endpoint: type: string id: type: string meta: $ref: '#/components/schemas/ScimMetadata' name: type: string schema: type: string schemas: type: array items: type: string required: - name - endpoint - schema title: ScimResourceType GetGroupsRequest: type: object properties: attributes: type: string count: description: 'The maximum number of resources to return. If omitted, defaults to 20. If set to 0, the response will contain no resources but will include metadata such as `totalResults`, complying with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' type: integer format: int32 excludedAttributes: type: string filter: type: string startIndex: description: 'The 1-based index of the first resource to return in the response. If omitted or less than 1, defaults to 1. This behavior complies with [RFC 7644, Section 3.4.2.4: Pagination](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.4).' type: integer format: int32 title: GetGroupsRequest ScimSchema: type: object properties: attributes: type: array items: $ref: '#/components/schemas/ScimSchemaAttribute' description: type: string id: type: string meta: $ref: '#/components/schemas/ScimMetadata' name: type: string required: - id title: ScimSchema ScimFilterSupport: type: object properties: maxResults: type: integer format: int32 supported: type: boolean required: - supported - maxResults title: ScimFilterSupport UpdateUserBody: type: object properties: active: type: boolean displayName: type: string emails: type: array items: $ref: '#/components/schemas/ScimEmail' externalId: type: string name: $ref: '#/components/schemas/ScimName' schemas: type: array items: type: string userName: type: string example: active: true emails: - display: croach@example.com primary: true type: work value: croach@example.com name: familyName: Roach givenName: Carl schemas: - urn:ietf:params:scim:schemas:core:2.0:User title: UpdateUserRequest ScimName: type: object properties: familyName: type: string givenName: type: string title: name ScimAuthenticationScheme: type: object properties: description: type: string documentationUri: type: string name: type: string primary: type: boolean specUri: type: string type: type: string required: - name - description - type title: ScimAuthenticationScheme Any: description: "`Any` contains an arbitrary serialized protocol buffer message along with a\nURL that describes the type of the serialized message.\n\nIn its binary encoding, an `Any` is an ordinary message; but in other wire\nforms like JSON, it has a special encoding. The format of the type URL is\ndescribed on the `type_url` field.\n\nProtobuf APIs provide utilities to interact with `Any` values:\n\n- A 'pack' operation accepts a message and constructs a generic `Any` wrapper\n around it.\n- An 'unpack' operation reads the content of an `Any` message, either into an\n existing message or a new one. Unpack operations must check the type of the\n value they unpack against the declared `type_url`.\n- An 'is' operation decides whether an `Any` contains a message of the given\n type, i.e. whether it can 'unpack' that type.\n\nThe JSON format representation of an `Any` follows one of these cases:\n\n- For types without special-cased JSON encodings, the JSON format\n representation of the `Any` is the same as that of the message, with an\n additional `@type` field which contains the type URL.\n- For types with special-cased JSON encodings (typically called 'well-known'\n types, listed in https://protobuf.dev/programming-guides/json/#any), the\n JSON format representation has a key `@type` which contains the type URL\n and a key `value` which contains the JSON-serialized value.\n\nThe text format representation of an `Any` is like a message with one field\nwhose name is the type URL in brackets. For example, an `Any` containing a\n`foo.Bar` message may be written `[type.googleapis.com/foo.Bar] { a: 2 }`." type: object properties: '@type': description: 'Identifies the type of the serialized Protobuf message with a URI reference consisting of a prefix ending in a slash and the fully-qualified type name. Example: type.googleapis.com/google.protobuf.StringValue This string must contain at least one `/` character, and the content after the last `/` must be the fully-qualified name of the type in canonical form, without a leading dot. Do not write a scheme on these URI references so that clients do not attempt to contact them. The prefix is arbitrary and Protobuf implementations are expected to simply strip off everything up to and including the last `/` to identify the type. `type.googleapis.com/` is a common default prefix that some legacy implementations require. This prefix does not indicate the origin of the type, and URIs containing it are not expected to respond to any requests. All type URL strings must be legal URI references with the additional restriction (for the text format) that the content of the reference must consist only of alphanumeric characters, percent-encoded escapes, and characters in the following set (not including the outer backticks): `/-.~_!$&()*+,;=`. Despite our allowing percent encodings, implementations should not unescape them to prevent confusion with existing parsers. For example, `type.googleapis.com%2FFoo` should be rejected. In the original design of `Any`, the possibility of launching a type resolution service at these type URLs was considered but Protobuf never implemented one and considers contacting these URLs to be problematic and a potential security issue. Do not attempt to contact type URLs.' type: string additionalProperties: {} PatchUserBody: type: object properties: Operations: type: array items: $ref: '#/components/schemas/ScimOperations' schemas: description: 'A list of one or more URIs identifying SCIM schemas that define the structure of the attributes in the request. The only supported schema at this time is "urn:ietf:params:scim:api:messages:2.0:PatchOp".' type: array items: type: string example: Operations: - op: replace path: userName value: newUserName - op: replace value: displayName: New Name emails: - primary: true value: new@example.com - op: remove path: externalId schemas: - urn:ietf:params:scim:api:messages:2.0:PatchOp required: - schemas - Operations title: PatchUserRequest ScimEtagSupport: type: object properties: maxResults: type: integer format: int32 supported: type: boolean required: - supported title: ScimEtagSupport GetUser2Body: type: object properties: attributes: type: string excludedAttributes: type: string title: GetUserRequest GetServiceProviderConfigResponse: type: object properties: authenticationSchemes: type: array items: $ref: '#/components/schemas/ScimAuthenticationScheme' bulk: $ref: '#/components/schemas/ScimBulkSupport' changePassword: $ref: '#/components/schemas/ScimChangePasswordSupport' etag: $ref: '#/components/schemas/ScimEtagSupport' filter: $ref: '#/components/schemas/ScimFilterSupport' meta: $ref: '#/components/schemas/ScimMetadata' schemas: type: array items: type: string sort: $ref: '#/components/schemas/ScimSortSupport' required: - schemas - bulk - filter - changePassword - sort - etag - authenticationSchemes title: GetServiceProviderConfigResponse CreateGroupRequest: type: object properties: displayName: type: string externalId: type: string members: type: array items: $ref: '#/components/schemas/ScimResource' schemas: type: array items: type: string example: displayName: Test SCIM members: [] schemas: - urn:ietf:params:scim:schemas:core:2.0:Group required: - schemas - displayName title: CreateGroupRequest ScimOperations: type: object properties: op: type: string path: type: string value: {} required: - op ScimSchemaAttribute: type: object properties: canonicalValues: type: array items: type: string caseExact: type: boolean description: type: string multiValued: type: boolean mutability: type: string name: type: string referenceTypes: type: array items: type: string required: type: boolean returned: type: string subAttributes: type: array items: $ref: '#/components/schemas/ScimSchemaAttribute' type: type: string uniqueness: type: string securitySchemes: Bearer: type: http scheme: bearer externalDocs: description: Use the CockroachDB Cloud API url: https://www.cockroachlabs.com/docs/cockroachcloud/cloud-api.html