Does Procurement VMS integrate with Okta?
Procurement VMS has not yet confirmed its Okta integration, so treat this page as a draft. An Okta integration gives users single sign-on and, through SCIM, creates and deactivates their accounts in the procurement platform. Okta connects to a SCIM API, and Okta supports OAuth 2.0 for that connection 1.confirm
When accounts are created by hand, access outlives the job. A leaver keeps the ability to approve spend until someone remembers to remove them from each system.
With Okta in front, sign-in follows your identity policies, and provisioning creates and deactivates accounts as people join, move and leave.
What syncs between Okta and Procurement VMS?
Okta is the system of record for identity, and the flow is one-way into the procurement platform. The table shows what a sign-in and provisioning integration covers.
| Data | Okta record | Direction | When | Notes |
|---|---|---|---|---|
| Sign-inconfirm | OIDC or SAML assertion | Okta → Procurement VMS | At every sign-in | Okta authenticates the user and tells the procurement platform who they are. |
| User accountsconfirm | SCIM Users | Okta → Procurement VMS | On assignment and on change | Okta creates, updates and deactivates accounts through a SCIM API 1. |
| Groupsconfirm | SCIM Groups | Okta → Procurement VMS | On change | Group membership can map to roles such as requester, approver or admin. |
| Deactivationconfirm | SCIM user status | Okta → Procurement VMS | When a user is deactivated in Okta | Removes access when someone leaves. |
How the Okta connection works, step by step
Setup is split between an Okta administrator and the Procurement VMS team. Okta documents how a SCIM API is built for it 1.
- Decide on sign-in and provisioningSign-in (OIDC or SAML) and provisioning (SCIM) are separate integrations, and you may want both.Okta administrator with the Procurement VMS team
- Expose a SCIM APIOkta connects to a SCIM API that the application provides, and a facade can translate between SCIM and a proprietary API 1.Procurement VMS team
- Choose the SCIM authenticationOkta supports OAuth 2.0 for SCIM connections, with either the authorization code or the client credentials grant, and custom scopes where needed 13.Okta administrator
- Create the Okta appProvisioning needs an app type that supports it. See the plan-for list below 4.Okta administrator
- Assign users and groupsThe users and groups assigned to the app are the ones provisioned.Okta administrator
- Test joiner, mover and leaverConfirm a new user is created, a role change updates access, and a deactivated user is removed.Everyone above
Who this fits
Okta is common in mid-sized and larger organizations, and the number of apps and groups decides how much structure you need.
SMB
Very small teams often use Google Workspace or Microsoft Entra ID for sign-in. See those pages.
Mid-market · fits
Okta as the identity provider for a few dozen apps. Start with sign-in and basic provisioning, and map one or two groups to roles.
Enterprise · fits
Many groups, strict joiner-mover-leaver controls and audit requirements. Map groups to roles deliberately and test deprovisioning first.
Who does what
What to plan for in Okta
The first three come from Okta's own documentation and support articles. Check all of them before the first sync.
Okta connects to a SCIM API you provide
For provisioning, Okta acts as a client of a SCIM API that the application exposes 1. The application has to implement SCIM before Okta can provision into it.
OAuth 2.0 is supported for SCIM
Okta supports OAuth 2.0 for SCIM connections, and refresh tokens if the application's authorization server supports them 1. Custom scopes can be added for the authorization code and client credentials grants 3.
Okta API scopes are a separate matter
Okta API access tokens with Okta scopes can only be minted by the org authorization server 2. That applies to calling Okta's own APIs, not to SCIM provisioning into an app.
Provisioning depends on the app type
A community answer notes that OIDC apps created from the app wizard do not offer provisioning, while SAML or SWA apps and SCIM catalog apps do 4. Confirm the option for your Okta setup.
Assign the same users to both appsverify source
If sign-in and provisioning use two Okta apps, the same users and groups have to be assigned to both.
Security and access
Okta keeps sign-in policy and provisioning in the identity system, so the procurement platform does not have to keep its own password database.
- Sign-in follows your Okta policies, such as multi-factor authentication, because Okta authenticates the user 1.
- SCIM calls from Okta can be authorized with OAuth 2.0 bearer tokens 13.
- Map Okta groups to roles so that removing someone from a group removes the access.verify source
- Procurement VMS describes its own security posture as SOC 2 Type II aligned and CCPA compliant, with role-based access control 5. Ask for current security documentation during scoping.
Related integrations and guides
Other systems in the same category, and the workflow guides that explain the processes this connection touches.
Okta integration FAQ
Procurement VMS has not yet confirmed its Okta integration, so there is no published support to point to. Use the form on this page and we'll tell you the current status for your setup.
Through OIDC or SAML for sign-in and SCIM 2.0 for provisioning. Okta connects to a SCIM API provided by the application and supports OAuth 2.0 for that connection 1.
Typically sign-in, user accounts, groups and deactivation. Direction is set per record type. The table above shows the proposed split.
Scope sets the timeline: what moves, whether it moves one way or both, and how much mapping your Okta setup needs. Procurement VMS states that the platform as a whole typically goes live in 4 to 8 weeks 5. The Okta connection is scoped within that timeline.
Yes, through SCIM, if the application exposes a SCIM API that Okta can call 1. Sign-in alone does not create accounts.
A community answer says OIDC apps created from the app wizard do not offer provisioning, while SAML, SWA and SCIM catalog apps do 4. Check the option available in your Okta setup.
With SCIM provisioning, Okta deactivates the account in the application, which removes their ability to approve.
Sources and how this page was verified
Facts about Okta on this page were checked against Okta's documentation on the date shown. Where only third-party integration documentation covers a behavior, the source is labelled third-party. Statements about Procurement VMS come from the company's published integration list; anything beyond that is confirmed with the product team before publishing. The Okta integration has not been confirmed for publication, so this page is a review draft.
- Okta Developer: Build your SCIM API servicevendor documentation
- Okta Developer: Implement OAuth for Okta (scopes)vendor documentation
- Okta Help: Adding a custom scope to the SCIM OAuth flowvendor documentation
- Okta Developer Forum: provisioning options for OIDC appsthird-party documentation
- Procurement VMS: platform overview and integration listProcurement VMS
Okta is a trademark of Okta or its affiliates. Procurement VMS is not affiliated with, sponsored by or endorsed by Okta. Platform names are used only to describe compatibility.