Enterprise
Cursor SCIM Provisioning: Setup, Directory Groups & Spend Limits
SCIM 2.0 on Cursor Enterprise adds and removes users automatically from your identity provider assignment to the Cursor SCIM app. It also syncs directory groups read-only into Cursor and lets admins set per-group spend limits, where users in multiple groups get the highest limit. SSO must be configured first; user and group changes must be made in your IdP, not in Cursor.
On this page
What do we need before turning on SCIM?
SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. rides on top of SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition., so the gating item is an active SAMLSecurity Assertion Markup Language. The XML-era enterprise standard that powers single sign-on: your identity provider vouches for you to each app. Older than OIDC but still what many enterprise tools speak. Press Enter for the full definition. connection. You also need the Enterprise plan and admin access on both sides, your identity provider and the Cursor org. Without all three in place, the SCIM controls never appear.
- Cursor Enterprise plan (contact sales if SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. is not visible).
- SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. already working: SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. requires an active SAMLSecurity Assertion Markup Language. The XML-era enterprise standard that powers single sign-on: your identity provider vouches for you to each app. Older than OIDC but still what many enterprise tools speak. Press Enter for the full definition. connection.
- Admin access to your IdP (Okta, Entra ID, Google Workspace, etc.) and Cursor org admin.
The ordering is not a preference, and it should change how you plan the work. Treat SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. as its own project with its own test user and its own rollback story, then begin SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. once that is verified. Teams that try to land both inside one change window tend to spend the window on SAMLSecurity Assertion Markup Language. The XML-era enterprise standard that powers single sign-on: your identity provider vouches for you to each app. Older than OIDC but still what many enterprise tools speak. Press Enter for the full definition., which leaves the provisioning half untested at the point where everyone is already switched over.
Worth settling who owns each half before you start, too. Setup needs an admin on the Cursor side and an admin on the identity provider side, and in most companies those are different people with different queues. The provider-specific instructions Cursor links to are WorkOS integration guides, covering Okta, Azure AD, Google Workspace and others.
This exact topic is a hands-on lesson: SSO, SCIM and Identity — about 5 minutes, free to read.
How does SCIM change day-to-day admin work?
Once SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. is live, membership stops being something you manage in Cursor. Three things flow in from your identity provider: users, directory groups and optional per-group spend limits. Cursor mirrors them read-only. What syncs automatically:
- Users
- Assigned in IdP → appear in Cursor; unassigned → removed.
- Directory groups
- Group membership mirrors IdP; Cursor display is read-only.
- Spend limits
- Optional per-directory-group caps; highest limit wins for multi-group users.
Once SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. is live, add, remove and regroup users only in your identity provider. Changes propagate to Cursor in real time. Manual invites and domain-matching self-join are replaced by IdP assignment.
The shift is bigger than that feature list makes it sound. Membership stops being something an admin does inside Cursor and becomes something the directory does, which is the point, and it also means the Cursor dashboard is no longer where you go to fix a membership problem. One thing does not travel with the users: roles. Everyone lands as a Member, so admin promotions happen by hand in the dashboard afterwards (members and roles has the detail).
Existing users are not removed automatically when SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. comes online either. You either remove them by hand or sync them once through SCIM and then deprovision them from the identity provider, which leaves the directory holding the whole record. Skip it and you get a members list longer than the directory group, with nobody certain which one is correct.
Per-group spend limits are probably the most underused thing on this page. A directory group limit takes precedence over the team-level per-user limit, and somebody in several groups receives the highest limit that applies, so the effective rule is that the most generous number wins. Put the tighter figure at team level and widen it for the groups that need room.
How do we configure SCIM step by step?
Setup runs across two consoles. You copy the endpoint and bearer token out of Cursor, then wire them into the Cursor SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. app in your identity provider and push users and groups. Confirm SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. works first, because the wizard only appears once SAMLSecurity Assertion Markup Language. The XML-era enterprise standard that powers single sign-on: your identity provider vouches for you to each app. Older than OIDC but still what many enterprise tools speak. Press Enter for the full definition. is verified.
- 1Confirm SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. login works for a test user.
- 2Open Dashboard → Members & Groups → Directory Groups (or the Active Directory subtab).
- 3Start the SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. setup wizard after SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. verification and copy the endpoint and bearer token.
- 4In your IdP, create or configure the Cursor SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. app; enable user and group push provisioning; run a connection test.
- 5Optionally set per-group spend limits on synced directory groups in Cursor.
Parts of that sequence fail quietly. Group push provisioning is configured separately from user provisioning in most identity providers, so a first run that syncs people and no groups is normal rather than broken. And a provisioned user does not show on the Cursor members dashboard until they sign in for the first time, which reads like a partial sync when it is an empty seat waiting for its owner.
Run the connection test before you push everyone. Sync is real-time with a brief delay on large bulk operations, and an attribute-mapping mistake is much cheaper to find with four users assigned than with four hundred.
Why are users or groups missing after SCIM setup?
Most missing-user and missing-group cases trace back to assignment in the identity provider rather than a bug in Cursor. A person in a group elsewhere still has to be assigned to the SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. app directly. If the SCIM controls themselves are hidden, the cause is upstream: SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. is not verified yet.
- Users: they must be explicitly assigned to the SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. application in the IdP, not only in a group elsewhere.
- Groups: confirm group push provisioning is enabled and groups are assigned to the SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. app.
- SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. UI hidden: SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. is not verified yet; fix SAMLSecurity Assertion Markup Language. The XML-era enterprise standard that powers single sign-on: your identity provider vouches for you to each app. Older than OIDC but still what many enterprise tools speak. Press Enter for the full definition. before SCIM controls appear.
Assignment is the root cause under most of that list: SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. only sees what the identity provider explicitly hands to the Cursor SCIM application. That is also the usual explanation when spend limits look broken and are not. Check group membership first, since the limit follows the group, and somebody who sits in the group in your directory but not in the pushed copy of it falls back to the team default.
If a change does not land at all, remember that Cursor is read-only here. There is no edit to make on this side, and the fix is in the directory, which is worth telling the admin who has spent twenty minutes hunting for a button that was never there.
How is SCIM different from billing groups?
Directory groups (SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition.) drive identity and optional spend limits. Billing groups attribute usage for chargebacks and can also sync from IdP groups but serve finance reporting. They are related concepts with different dashboards; large orgs often use both. See the billing groups guide for spend attribution rules.
Both sync from identity provider groups, which is exactly why they get confused. Directory groups answer who is on the team and what they may spend; billing groups answer whose budget a request lands against once it is spent. A large org runs both, on different pages, and one reorg touches both: billing groups has the attribution rules.
If somebody's spend limit and their chargeback line look like they disagree, they are answers to different questions rather than a conflict, and regrouping them in one place will not change the other.
Frequently asked questions
Can we mix SCIM and manual invites?
Not for SCIM-managed users. Membership is owned by the IdP. Non-SCIM domain controls apply only when you are not provisioning through SCIM.
Which identity providers are supported?
Cursor documents SCIM with WorkOS integration guides covering Okta, Azure AD, Google Workspace and others. Follow the provider-specific steps linked from the SCIM doc.
Do directory group spend limits override team defaults?
Yes. Group limits take precedence over team-wide per-user limits; users in multiple groups receive the highest applicable limit.
Sources & last verified
Cursor ships frequently. Last updated July 28, 2026.
Keep reading
Rather do it than read about it? Run 11 interactive Cursor walkthroughs in a simulated editor. Free, no account needed.