Group SCIM identities
When a group’s identity provider provisions users over SCIM, GitLab keeps a SCIM identity linking each user to the provider’s ID for them. These actions list a group’s SCIM identities, read one, change the ID it is linked to, and delete it.
Sample questions
Section titled “Sample questions”- “List the SCIM identities of group acme”
- “Which GitLab user is SCIM identity 7f3a?”
- “Unlink the SCIM identity of a departed employee”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such asgroup_scim.delete, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_group_scimwithactionset to the action’s name, such asdelete, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_delete_group_scim_identity, with its parameters as the arguments.
Availability
Section titled “Availability”How many of these actions an instance serves at each tier, out of a total of 4:
- Free: 0
- Premium: 4
- Ultimate: 4
Read-only actions: 2 of 4, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).
| Action | Individual |
|---|---|
group_scim.delete | gitlab_delete_group_scim_identity |
group_scim.get | gitlab_get_group_scim_identity |
group_scim.list | gitlab_list_group_scim_identities |
group_scim.update | gitlab_update_group_scim_identity |
group_scim.delete
Section titled “group_scim.delete”Delete a SCIM identity from a top-level group by its SCIM external UID. Returns: a success confirmation naming the deleted SCIM identity and group. See also:
group_scim.get,group_scim.list,group_scim.update.
- Meta-tool:
gitlab_group_scim, actiondelete - Individual tool:
gitlab_delete_group_scim_identity - Tier: Premium
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
uid | string | yes | SCIM external UID of the user |
group_scim.get
Section titled “group_scim.get”Get one SCIM identity of a top-level group by its SCIM external UID. Returns: the identity’s external_uid, user_id, and active status. See also:
group_scim.list,group_scim.update,group_scim.delete.
- Meta-tool:
gitlab_group_scim, actionget - Individual tool:
gitlab_get_group_scim_identity - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
uid | string | yes | SCIM external UID of the user |
group_scim.list
Section titled “group_scim.list”List a top-level group’s SCIM identities provisioned through SAML SSO SCIM. Returns: each identity with external_uid, user_id, and active status. See also:
group_scim.get,group_scim.update,group_scim.delete.
- Meta-tool:
gitlab_group_scim, actionlist - Individual tool:
gitlab_list_group_scim_identities - Tier: Premium
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
group_scim.update
Section titled “group_scim.update”Update the extern_uid of an existing group SCIM identity. Returns: a confirmation that the SCIM identity’s external UID was rewritten. See also:
group_scim.get,group_scim.list,group_scim.delete.
- Meta-tool:
gitlab_group_scim, actionupdate - Individual tool:
gitlab_update_group_scim_identity - Tier: Premium
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
extern_uid | string | yes | New external UID value |
group_id | string/integer | yes | Group ID or URL-encoded path |
uid | string | yes | SCIM external UID of the user |