BrowserStack user provisioning with OneLogin
Connect your OneLogin IdP with BrowserStack.
OneLogin’s integration with BrowserStack enables end-users to enable Single Sign-on and Auto User Provisioning for their BrowserStack account. This document describes how to configure auto User Provisioning when OneLogin is your identity provider.
If you’re a new BrowserStack customer, to assign roles and products, see Assign roles using Automated User Provisioning and Assign product access using Automated User Provisioning.
Prerequisites
- Enterprise plan on BrowserStack.
- You need to have administrator access to your organization’s OneLogin instance.
- Your OneLogin SSO needs to be enabled before User Provisioning. Follow the instructions given here to set up SSO with OneLogin.
- User with Owner permissions can setup user provisioning on BrowserStack.
Supported features
The OneLogin & BrowserStack User Provisioning integration is configurable on BrowserStack, currently supports the following features:
- User provisioning & de-provisioning
- Attribute assignment for users on BrowserStack:
- Role assignment
- Product access
- Team assignment
BrowserStack provisions individual users only and does not support group provisioning. Assign each user’s team, role, and product access using the custom attributes on this page.
Configuring for user provisioning
-
Log-in to BrowserStack as Owner.
-
Go to Account > Security and select Authentication from the side-nav menu.
-
Under Auto User Provisioning, select Configure.

-
Select the user attributes that you want to control via IDP

-
Copy the Access Key only, it will be used on OneLogin for authentication

-
If you set up SSO before setting up User Provisioning, you already have the BrowserStack app added on OneLogin, skip this step. Follow these steps if you have not set up User Provisioning: a. Go to Applications. b. Click Add App, and find the BrowserStack app under Add Application on OneLogin. c. Add it to your OneLogin tenant, give it an identifiable name under “Display Name” and click Save.

- Head to BrowserStack App on OneLogin, and go to the Configuration tab.
- You should have SSO configured via this tab already, if not, use the OneLogin user guide link to set it up.
- You should have SSO configured via this tab already, if not, use the OneLogin user guide link to set it up.
- Add the Access Key from BrowserStack in the SCIM Bearer Token field on OneLogin.
- Click Enable. OneLogin will give a green Enabled text confirmation.
- Click Enable. OneLogin will give a green Enabled text confirmation.
- Head to Provisioning, to start pushing users to BrowserStack
- Make sure that the following are selected:
- Create user
- Delete user
- Update user
- Select Delete as the action when users are deleted on OneLogin.
- Select Do Nothing as the action when users are suspended on OneLogin. (Suspension is not supported on BrowserStack.)
- Make sure that the following are selected:
-
Go to Parameters, and click on SCIM username under Required Parameters. Set the value to Email.
-
Save the current state. We will enable Provisioning on BrowserStack before coming back and enabling it on OneLogin. You can enable it via the provisioning tab at this step, but the users will not be pushed into BrowserStack till we enable it on BrowserStack.
- On BrowserStack, enable Auto User Provisioning once you have set it up on OneLogin, otherwise, you will be locked out of inviting new users via BrowserStack UI.
Managing users via OneLogin application

Depending on the configuration that you select while setting up Auto User Provisioning on BrowserStack. You will need to create the appropriate Custom User Fields and assign in the Parameters tab.

Ensure that you check the box next to Include in User Provisioning.
Provisioning & Deprovisioning users
- By assigning the app to the user, the user will get provisioned on the BrowserStack platform.
- You can remove a user and his/her access by removing the user from the app.
- You cannot delete the current Owner from OneLogin. Assign Owner role to another user, before deleting the current Owner.
- Updating the owner will log out the current owner as well as the old owner from their current session for security reasons.
If you’re a new BrowserStack customer, to assign roles and products, see Assign roles using Automated User Provisioning and Assign product access using Automated User Provisioning.
Role assignment
- Attribute Name: primary_role
- Default assignment as User, in case of
- Unexpected, empty or no value
- Role attribute controlled by BrowserStack UI
- Expected values when attribute controlled by OneLogin:
| Attribute Value | Role Update |
|---|---|
| User | User will be assigned |
| Admin | Admin will be assigned |
| Owner | Owner will be assigned The current owner will be replaced with the new owner. The current owner will become a user. |
|
No Value Empty or Any other value |
The user is created as User by default. |
Team assignment
- Attribute Name: primary_team
- Default assignment as Group User, in case of:
- Empty or no value
- Attribute controlled by BrowserStack UI
- Expected values when attribute controlled by OneLogin:
| Attribute Value | Team Update |
|---|---|
| team_name | The user gets added to the existing team if a team exists with the same name. Otherwise, a new team will be created with the passed attribute value. |
| No value/Empty | The user is assigned as part of Group |
Product assignment
- Attribute Name: primary_product
- Default assignment no product access, in case of
- Unexpected, empty or no value
- Attribute controlled by BrowserStack UI
- Expected values when attribute controlled by OneLogin:
| Attribute values | Product Update |
|---|---|
| Browser-Testing | Live Automate |
| Visual-Testing | Percy |
| Automate-Testing | Automate |
| Live-Testing | Live |
| Mobile-App-Testing | App Live App Automate |
| App-Automate-Testing | App Automate |
| App-Live-Testing | App Live |
| App-Percy | App-Percy |
| App-Accessibility-Testing | App Accessibility |
| Accessibility-Testing | Accessibility Testing |
| Test-Management | Test Management |
| Test-Reporting-&-Analytics | Test Reporting & Analytics |
| Low-Code-Automation | Low Code Automation |
| Bug-Capture | Bug Capture |
| Requestly | Requestly |
| Testing-Toolkit | Testing Toolkit |
| Central-Scanner | Central Scanner |
| Automate-turboscale | Automate TurboScale |
| Accessibility-Design-Toolkit | Accessibility Design Toolkit |
| Load-Testing | Load Testing |
- You can pass multiple values for product access in a comma-separated string. Example:
Browser-Testing,Visual-Testing - If product access is controlled through an IdP, you can update product roles as part of the product access attributes. For example:
Percy:Product Admin, Test-Management:Product User. - If RBAC is enabled, refer to the Assign roles using Automated User Provisioning and Assign product access using Automated User Provisioning documentation for details.
BrowserStack SCIM endpoints
OneLogin talks to the BrowserStack SCIM server on the following endpoints. Use them to check which SCIM features BrowserStack supports, look up the structure of the custom attributes, and interpret the responses that appear in your OneLogin event logs.
Service provider configuration
The Service Provider Config endpoint returns the BrowserStack server’s authentication scheme and the optional or configurable SCIM features it supports. Service Provider Config objects are defined by RFC 7643, section 5.
GET https://www.browserstack.com/scim/v2/ServiceProviderConfig
Sample response:
{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig"],
"documentationUri": "https://www.browserstack.com/docs/enterprise/auto-user-provisioning",
"patch": { "supported": true },
"bulk": { "supported": false, "maxOperations": 0, "maxPayloadSize": 0 },
"filter": { "supported": true, "maxResults": 500 },
"changePassword": { "supported": false },
"sort": { "supported": false },
"etag": { "supported": false },
"authenticationSchemes": [
{
"name": "OAuth Bearer Token",
"description": "Authentication scheme using the OAuth Bearer Token Standard",
"specUri": "http://tools.ietf.org/html/rfc6750",
"type": "oauthbearertoken"
}
],
"meta": {
"resourceType": "ServiceProviderConfig",
"location": "https://www.browserstack.com/scim/v2/ServiceProviderConfig"
}
}
Resource types
The Resource Types endpoint lists all of the SCIM resource types configured for use on the BrowserStack server. Use the response to determine the endpoint, core schema, and extension schemas of any resource type that the server supports. This endpoint does not provide resource type information about SCIM sub-resources.
The response is formatted as a list response, with one or more resource type objects in the Resources field. Resource type objects are defined by RFC 7643, section 6.
GET https://www.browserstack.com/scim/v2/ResourceTypes
Sample response:
{
"schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
"totalResults": 1,
"Resources": [
{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:ResourceType"],
"id": "Users",
"name": "Users",
"endpoint": "/Users",
"schema": "urn:ietf:params:scim:schemas:core:2.0:User"
}
]
}
User resource type
The Resource Type endpoint retrieves a specific SCIM resource type, specified by its ID. BrowserStack supports the User resource only. Resource type objects are defined by RFC 7643, section 6. This endpoint does not provide resource type information about SCIM sub-resources.
GET https://www.browserstack.com/scim/v2/ResourceTypes/User
Sample response:
{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:ResourceType"],
"id": "Users",
"name": "Users",
"endpoint": "/Users",
"description": "User Account",
"schema": "urn:ietf:params:scim:schemas:core:2.0:User",
"meta": {
"location": "https://www.browserstack.com/scim/v2/ResourceTypes/User",
"resourceType": "ResourceType"
}
}
- To update an existing user resource, use the
PUTendpoint. - If your IdP does not support the
PUTendpoint, use thePATCH /scim/v2/Users/{id}endpoint.
Example request body for a PATCH request:
{
"schemas": [
"urn:ietf:params:scim:schemas:core:2.0:User"
],
"Operations":[{"op": "add", "path" : "urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_product", "value" : "App-Live-Testing,App-Automate-Testing"}]
}
Schemas
The Schemas endpoint lists the SCIM schemas configured for use on the BrowserStack server, which define the attributes available to resource types. Use this endpoint to check the structure of the custom primary_role, primary_team, and primary_product attributes. This endpoint does not provide schema information about SCIM sub-resources.
The response is formatted as a list response, with one or more schema objects in the Resources field. Schema objects are defined by RFC 7643, section 7.
GET https://www.browserstack.com/scim/v2/Schemas
Sample response:
{
"schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
"totalResults": 1,
"Resources": [
{
"id": "urn:ietf:params:scim:schemas:core:2.0:User",
"name": "User",
"description": "User Schema",
"attributes": [
{
"name": "userName",
"type": "string",
"multiValued": false,
"required": true,
"caseExact": false,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "server",
"description": "Unique identifier for the User, typically used by the user to directly authenticate to the service provider. Each User MUST include a non-empty userName value. This identifier MUST be unique across the service provider's entire set of Users."
},
{
"name": "name",
"type": "complex",
"multiValued": false,
"required": false,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "none",
"description": "The components of the user's real name. Providers MAY return just the full name as a single string in the formatted sub-attribute, or they MAY return just the individual component attributes using the other sub-attributes, or they MAY return both. If both variants are returned, they SHOULD be describing the same name, with the formatted name indicating how the component attributes should be combined.",
"subAttributes": [
{
"name": "familyName",
"type": "string",
"multiValued": false,
"required": false,
"caseExact": false,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "none",
"description": "The family name of the User, or last name in most Western languages (e.g., 'Jensen' given the full name 'Ms. Barbara J Jensen, III')."
},
{
"name": "givenName",
"type": "string",
"multiValued": false,
"required": false,
"caseExact": false,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "none",
"description": "The given name of the User, or first name in most Western languages (e.g., 'Barbara' given the full name 'Ms. Barbara J Jensen, III')."
}
]
},
{
"name": "active",
"type": "boolean",
"multiValued": false,
"required": true,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "none",
"description": "A Boolean value indicating the User's status."
},
{
"name": "bstack_team",
"type": "string",
"multiValued": false,
"required": false,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "none",
"description": "A String value indicating the User's Team in BrowserStack"
},
{
"name": "bstack_role",
"type": "string",
"multiValued": false,
"required": false,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "none",
"description": "A String value indicating the User's Role in BrowserStack"
},
{
"name": "bstack_product",
"type": "string",
"multiValued": true,
"required": false,
"mutability": "readWrite",
"returned": "default",
"uniqueness": "none",
"description": "A String value indicating the User's Product accesses in BrowserStack"
}
],
"meta": {
"resourceType": "Schema",
"location": "https://www.browserstack.com/scim/v2/Schemas/urn:ietf:params:scim:schemas:core:2.0:User"
}
}
]
}
Individual schema
The Schema endpoint retrieves a specific SCIM schema, specified by its ID, which is always a URN. BrowserStack supports the User schema only. Schema objects are defined by RFC 7643, section 7. This endpoint does not provide schema information about SCIM sub-resources.
GET https://www.browserstack.com/scim/v2/Schemas/urn:ietf:params:scim:schemas:core:2.0:User
The response is the same User schema object that the Schemas endpoint returns in its Resources array, returned on its own without the list wrapper. For the full object, see the Schemas sample response.
Replace a user
The Replace User endpoint updates an existing user by replacing the resource with the values in the request body. You can update the name, role, team, and product attributes, and change the email through userName. Attributes that are controlled by the BrowserStack dashboard as per the current configuration cannot be updated through this endpoint.
PUT https://www.browserstack.com/scim/v2/Users/{id}
A successful request returns 200 with the full user resource, including externalId, active, and the custom bstack_* attributes:
{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
"id": 12345,
"externalId": "john.doe",
"userName": "john.doe@example.com",
"active": true,
"name": { "givenName": "John", "familyName": "Doe" },
"emails": [{ "primary": true, "value": "john.doe@example.com" }],
"bstack_role": "Admin",
"bstack_team": "Engineering",
"bstack_product": "Live,Automate",
"meta": {
"resourceType": "User",
"created": "2026-01-10T08:12:33.000Z",
"lastModified": "2026-07-15T09:00:00.000Z",
"location": "https://www.browserstack.com/scim/v2/Users/12345"
}
}
In this response, userName carries the user’s email, and externalId carries the BrowserStack username.
Some fields are returned conditionally based on your SCIM configuration:
-
bstack_role,bstack_team, andbstack_productare returned only when that attribute is controlled by the IdP in your SCIM configuration. -
metais returned only for accounts enabled for the SCIM metadata response. -
idis an integer by default, and a string for accounts enabled for string user IDs.
Update a user
The Update User endpoint applies a partial update to an existing user using a SCIM PatchOp request. A replace operation that sets active to false de-provisions the user.
PATCH https://www.browserstack.com/scim/v2/Users/{id}
A successful request returns 200 with the full user resource, in the same shape as the Replace a user response, including the conditional fields described earlier:
{
"schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
"id": 12345,
"externalId": "john.doe",
"userName": "john.doe@example.com",
"active": true,
"name": { "givenName": "John", "familyName": "Doe" },
"emails": [{ "primary": true, "value": "john.doe@example.com" }],
"bstack_role": "Admin",
"bstack_team": "Engineering",
"bstack_product": "Live,Automate",
"meta": {
"resourceType": "User",
"created": "2026-01-10T08:12:33.000Z",
"lastModified": "2026-07-15T09:00:00.000Z",
"location": "https://www.browserstack.com/scim/v2/Users/12345"
}
}
Error responses
When a request fails, all endpoints return the same SCIM error envelope with an HTTP status code such as 400, 403, 404, or 422:
{
"schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"],
"detail": "Human-readable error message",
"status": "404"
}
Common cases include:
-
403: Missing or invalid credentials. -
404: The requested resource is not found. -
400or422: Invalid request, or an attribute that is controlled by the BrowserStack dashboard as per the current configuration.
Troubleshooting
Below is a list of possible errors that might be encountered and how to resolve them:
User already present on BrowserStack
Resolution: User already presents on BrowserStack under a different organization, please get the account deleted before provisioning the user.

Invalid parameter/attribute values passed for Role or Product
Resolution: Role/Product is not a valid use-case, please use the attribute values provided above.

Owner deletion
Incompatible attributes
Resolution: You are assigning incompatible user attributes, for example Owner cannot have a team assigned.

Licenses unavailability
Resolution: You have used up all your licenses for the product, please unassign users or add more licenses. Contact your Account Executive to get information on adding licenses.
Escalation/Support
Contact us for any escalations or support.
We're sorry to hear that. Please share your feedback so we can do better
Contact our Support team for immediate help while we work on improving our docs.
We're continuously improving our docs. We'd love to know what you liked
We're sorry to hear that. Please share your feedback so we can do better
Contact our Support team for immediate help while we work on improving our docs.
We're continuously improving our docs. We'd love to know what you liked
Thank you for your valuable feedback!