Skip to content

Group SCIM identities

When a group’s identity provider provisions users over SCIM, GitLab keeps a SCIM identity linking each user to the provider’s ID for them. These actions list a group’s SCIM identities, read one, change the ID it is linked to, and delete it.

  • “List the SCIM identities of group acme”
  • “Which GitLab user is SCIM identity 7f3a?”
  • “Unlink the SCIM identity of a departed employee”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as group_scim.delete, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_group_scim with action set to the action’s name, such as delete, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_delete_group_scim_identity, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 4:

  • Free: 0
  • Premium: 4
  • Ultimate: 4

Read-only actions: 2 of 4, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
group_scim.deletegitlab_delete_group_scim_identity
group_scim.getgitlab_get_group_scim_identity
group_scim.listgitlab_list_group_scim_identities
group_scim.updategitlab_update_group_scim_identity

Delete a SCIM identity from a top-level group by its SCIM external UID. Returns: a success confirmation naming the deleted SCIM identity and group. See also: group_scim.get, group_scim.list, group_scim.update.

  • Meta-tool: gitlab_group_scim, action delete
  • Individual tool: gitlab_delete_group_scim_identity
  • Tier: Premium
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
uidstringyesSCIM external UID of the user

Get one SCIM identity of a top-level group by its SCIM external UID. Returns: the identity’s external_uid, user_id, and active status. See also: group_scim.list, group_scim.update, group_scim.delete.

  • Meta-tool: gitlab_group_scim, action get
  • Individual tool: gitlab_get_group_scim_identity
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
uidstringyesSCIM external UID of the user

List a top-level group’s SCIM identities provisioned through SAML SSO SCIM. Returns: each identity with external_uid, user_id, and active status. See also: group_scim.get, group_scim.update, group_scim.delete.

  • Meta-tool: gitlab_group_scim, action list
  • Individual tool: gitlab_list_group_scim_identities
  • Tier: Premium
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path

Update the extern_uid of an existing group SCIM identity. Returns: a confirmation that the SCIM identity’s external UID was rewritten. See also: group_scim.get, group_scim.list, group_scim.delete.

  • Meta-tool: gitlab_group_scim, action update
  • Individual tool: gitlab_update_group_scim_identity
  • Tier: Premium
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
extern_uidstringyesNew external UID value
group_idstring/integeryesGroup ID or URL-encoded path
uidstringyesSCIM external UID of the user