scim2-server
Lightweight SCIM2 server prototype
Decision gist · record as of 2026-08-14
Yes, if you need a working SCIM2 server for testing, prototyping, or learning. The active maintenance, low install friction, permissive Apache 2.0 license, and zero known vulnerabilities make it safe to use. However, do not use the in-memory backend in production—it is explicitly designed as a reference implementation. For production deployments, you must implement a persistent backend and add proper authentication and authorization.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; stores all resources in memory and loses them on process exit unless --dump-resources is used.
- Low install friction with a pure-Python wheel distribution.
- Maintenance status is active with recent releases.
License · maintenance · safety
permissive license (permissive) — Licensed under Apache License 2.0, a permissive license allowing commercial use, modification, and distribution with minimal restrictions—suitable for both open-source and proprietary projects.
last release 2026-03-27 (140 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 113,861 downloads/mo, #12,325 on PyPI
Alternatives
Verify before relying
pip install scim2-server
scim2-server --port 8080 --bearer-token my-token
# Server listens on http://127.0.0.1:8080 with SCIM2 endpoints- Performance characteristics under load or with large resource sets
- Whether the in-memory backend is suitable for your scale requirements
- Production deployment guidance beyond the notes in the description
What it is and what it does
scim2-server is a SCIM2 (System for Cross-domain Identity Management) protocol server implementation designed as a prototype and reference implementation. It exposes standard SCIM2 endpoints for user and resource provisioning, supporting discovery endpoints, full CRUD operations, filtering, searching, sorting, ETags, and HTTP PATCH. The server runs as a WSGI application using werkzeug and stores all resources in memory, making it suitable for testing, prototyping, and integration scenarios rather than production deployments.
The package is built on three runtime dependencies: scim2-models for SCIM data structures, scim2-filter-parser for query filtering, and werkzeug for the HTTP layer. It has been tested against live Microsoft Entra and Okta systems. The documentation notes that for production use, you would typically replace the in-memory backend with a persistent data store, add proper OAuth authorization, and deploy behind a production WSGI server rather than werkzeug's development server.
Use it for
- Testing SCIM2 client integrations against a compliant server without setting up a full identity provider
- Prototyping user provisioning workflows for identity management systems
- Learning SCIM2 protocol implementation and RFC 7643/7644 compliance
- Validating SCIM2 requests and responses in development environments
- Building a custom provisioning backend by subclassing the provided Backend class
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need a working SCIM2 server for testing, prototyping, or learning.
The active maintenance, low install friction, permissive Apache 2.0 license, and zero known vulnerabilities make it safe to use. However, do not use the in-memory backend in production—it is explicitly designed as a reference implementation. For production deployments, you must implement a persistent backend and add proper authentication and authorization.
Install
scim2-server on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Maintenance status is active with recent releases. Requires Python 3.10 or later.
Requires Python 3.10 or later; stores all resources in memory and loses them on process exit unless --dump-resources is used.
License in practice
Licensed under Apache License 2.0, a permissive license allowing commercial use, modification, and distribution with minimal restrictions—suitable for both open-source and proprietary projects.
Quickstart
pip install scim2-server
scim2-server --port 8080 --bearer-token my-token
# Server listens on http://127.0.0.1:8080 with SCIM2 endpoints
Verify before relying
- Performance characteristics under load or with large resource sets
- Whether the in-memory backend is suitable for your scale requirements
- Production deployment guidance beyond the notes in the description
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesscim2-filter-parserscim2-modelswerkzeug |
| Maintenance | Actively maintained 140 days since the last release |
| First released | |
| Downloads | 113,861 / month, #12,325 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaEnvironment :: Web EnvironmentIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: Implementation :: CPython |
Evidence: scim2_server-0.1.9-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “scim2 server implementation”
- scim2-serverProvides a lightweight SCIM2 server implementation that handles user…
- scim2-modelsProvides Pydantic models for SCIM2 (System for Cross-domain Identity…
- webauthnImplements server-side WebAuthn validation for passwordless…
Give your agent the search over MCP, or paste the wish link into any chat.
More Dynamic Content packages
MarkupSafe provides a text object that escapes special characters so untrusted strings can be safely embedded in HTML and XML without injection attacks.
Jinja2 is a templating engine that renders dynamic content by combining templates with Python-like syntax and data, supporting template inheritance, macros, autoescaping, and sandboxed execution.
Soupsieve is a CSS selector library designed to work with Beautiful Soup 4 to select, match, and filter HTML and XML elements using modern CSS selectors from CSS level 1 through CSS level 4 specifications.
Install it if you use Beautiful Soup for HTML or XML parsing and want modern CSS selector support.
Werkzeug is a WSGI utility library providing request/response objects, URL routing, an interactive debugger, HTTP utilities, and a development server for building web applications.
Flask is a lightweight WSGI web application framework for building web applications in Python, from simple single-page sites to complex multi-route applications.
Mako compiles Python-embedded templates into Python modules for fast rendering, supporting layout inheritance, custom functions, and direct Python expressions within template syntax.
See also django-scim2 · scim2-filter-parser · scim2-models · pydantic-scim · WSGIProxy2 · wsgidav · httplib2 · pecan