- Short answer
- Yes, for Plus organizations only — SCIM creates users, assigns groups and deactivates them; deletion depends on your identity provider.
- Prerequisites
- A verified domain and SAML authentication come first; both are Plus-only, like generating the SCIM token.
- Who it can manage
- Only users associated with a domain you've verified; no Shopify page we read says whether POS-only staff are covered.
- New users
- Users created through SCIM don't receive an invitation email.
- Identity providers
- Okta, OneLogin and Entra have configuration steps; for others, Shopify gives a base URL to use if asked.
- As of
- Shopify's SCIM, advanced security features, verify-domain and SAML help pages, read September 14, 2026.
Which Shopify organizations and users can SCIM manage?
SCIM is one of the additional security settings a Plus organization adds from the Users > Security section of its Shopify admin, next to the rest of what stays Plus-only inside an organization.
SCIM user management is available only for organizations on the Shopify Plus plan.
Inside that organization, the reach stops at your domain: "You can only manage users who are associated with a domain that you've verified for your organization."
No Shopify page we have read — the SCIM, advanced security features, verify-domain and SAML help pages, as of September 14, 2026 — says whether SCIM also covers POS-only staff.
What can your identity provider do in Shopify through SCIM?
Once you give the SCIM API token to your identity provider, Shopify lists three actions you can take through it:
- Create users
- Assign or update groups
- Deactivate users
Users created through SCIM don't receive an invitation email — the user must log in through the identity provider to activate the account — so plan to tell new hires about it yourself.
If the pull toward SCIM is headcount rather than a directory, which plans can bulk-import users with a CSV file is a separate answer.
Does removing someone in your identity provider delete them from Shopify?
Not necessarily — the outcome depends on what you do in the provider and on whose account it is.
What a removal in your identity provider does in Shopify
| In your identity provider | In your Shopify organization |
|---|---|
| Remove an active user's access | The user is suspended in your organization |
| Permanently delete a user | They might be deleted, depending on your identity provider setup |
| Remove a store owner or organization owner | Not possible through an identity service provider |
Plan offboarding around suspension, the outcome Shopify states for an active user, and check how your own provider handles a permanent delete before you count on the account disappearing. Shopify's SAML page adds a caveat about sessions: "If you remove a user from the Shopify application in your identity provider, then they can still access Shopify for up to 14 days." Owner accounts can't be removed that way — Shopify says both types of ownership must be transferred before the user can be removed — so keep them on your manual offboarding list.
Whether a departing account should be suspended or removed at all is a decision of its own.
What do you need before generating a SCIM token?
SCIM is the last step of a chain, and Shopify documents each step on its side as available only on the Shopify Plus plan:
- Verify a domain for your organization.
- Set up SAML authentication for the organization.
- Generate the SCIM API token, then give it to your identity provider.
On the provider side, Shopify's SCIM page carries configuration steps for Okta, OneLogin and Entra, each starting in the Shopify Plus app inside that provider. With any other provider you might need a base URL as well as the token; if it asks for one, use https://shopifyscim.com/scim/v2/.
SAML itself is the condition; its Required enforcement level is your choice, and under it "All users with email addresses matching your domain must use SAML to log in" — store owners and outside users included. That setting also replaces all individual security requirements for your users.
How SAML fits the wider questions enterprise IT asks — SSO, audit and compliance — is covered in the enterprise security section of our B2B on Shopify Plus guide.
This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.
Editorial Policy