Skip to main content
No Result Found
Get your setup working faster. Join our Discord for optimisation tips from elite testers. Join our DiscordJoin our Discord

BrowserStack user provisioning with OneLogin

Connect your OneLogin IdP with BrowserStack.

OneLogin’s integration with BrowserStack enables end-users to enable Single Sign-on and Auto User Provisioning for their BrowserStack account. This document describes how to configure auto User Provisioning when OneLogin is your identity provider.

If you’re a new BrowserStack customer, to assign roles and products, see Assign roles using Automated User Provisioning and Assign product access using Automated User Provisioning.

Prerequisites

  • Enterprise plan on BrowserStack.
  • You need to have administrator access to your organization’s OneLogin instance.
  • Your OneLogin SSO needs to be enabled before User Provisioning. Follow the instructions given here to set up SSO with OneLogin.
  • User with Owner permissions can setup user provisioning on BrowserStack.
Note: Owner can also allow user provisioning setup access to one of the Admin(s). For more information, see the Authentication & Security Settings section.

Supported features

The OneLogin & BrowserStack User Provisioning integration is configurable on BrowserStack, currently supports the following features:

  • User provisioning & de-provisioning
  • Attribute assignment for users on BrowserStack:
    • Role assignment
    • Product access
    • Team assignment

BrowserStack provisions individual users only and does not support group provisioning. Assign each user’s team, role, and product access using the custom attributes on this page.

Configuring for user provisioning

  1. Log-in to BrowserStack as Owner.

  2. Go to Account > Security and select Authentication from the side-nav menu.

  3. Under Auto User Provisioning, select Configure. Under auto user provisioning, select configure

  4. Select the user attributes that you want to control via IDP Auto User Provisioning - One Login User Attributes

  5. Copy the Access Key only, it will be used on OneLogin for authentication Credentials for integration with your IDP

  6. If you set up SSO before setting up User Provisioning, you already have the BrowserStack app added on OneLogin, skip this step. Follow these steps if you have not set up User Provisioning: a. Go to Applications. b. Click Add App, and find the BrowserStack app under Add Application on OneLogin. c. Add it to your OneLogin tenant, give it an identifiable name under “Display Name” and click Save. Click Add App in Applications and find BrowserStack App under Add Aplication on OneLogin. Add it to your OneLogin tenant and give and identifiable name under Display Name

  7. Head to BrowserStack App on OneLogin, and go to the Configuration tab.
  8. Add the Access Key from BrowserStack in the SCIM Bearer Token field on OneLogin.
    • Click Enable. OneLogin will give a green Enabled text confirmation. Green tick is displayed on clicking enable
  9. Head to Provisioning, to start pushing users to BrowserStack
    • Make sure that the following are selected:
      • Create user
      • Delete user
      • Update user
    • Select Delete as the action when users are deleted on OneLogin.
    • Select Do Nothing as the action when users are suspended on OneLogin. (Suspension is not supported on BrowserStack.) Head to provisioning, to start pushing users to browserstack
  10. Go to Parameters, and click on SCIM username under Required Parameters. Set the value to Email.

  11. Save the current state. We will enable Provisioning on BrowserStack before coming back and enabling it on OneLogin. You can enable it via the provisioning tab at this step, but the users will not be pushed into BrowserStack till we enable it on BrowserStack.

  12. On BrowserStack, enable Auto User Provisioning once you have set it up on OneLogin, otherwise, you will be locked out of inviting new users via BrowserStack UI. Account Settings Page after OneLogin setup

Managing users via OneLogin application

Note: We would suggest that as a first step, please put all the users you currently have on the BrowserStack account into the OneLogin app via the assignment tab. This would avoid any discrepancies between the user lists on OneLogin and BrowserStack.

Managing users on OneLogin and BrowserStack

Depending on the configuration that you select while setting up Auto User Provisioning on BrowserStack. You will need to create the appropriate Custom User Fields and assign in the Parameters tab. Set up Auto User Provisioning on BrowserStack

Ensure that you check the box next to Include in User Provisioning.

Provisioning & Deprovisioning users

  1. By assigning the app to the user, the user will get provisioned on the BrowserStack platform.
  2. You can remove a user and his/her access by removing the user from the app.
Note:
  1. You cannot delete the current Owner from OneLogin. Assign Owner role to another user, before deleting the current Owner.
  2. Updating the owner will log out the current owner as well as the old owner from their current session for security reasons.

If you’re a new BrowserStack customer, to assign roles and products, see Assign roles using Automated User Provisioning and Assign product access using Automated User Provisioning.

Role assignment

  1. Attribute Name: primary_role
  2. Default assignment as User, in case of
    • Unexpected, empty or no value
    • Role attribute controlled by BrowserStack UI
  3. Expected values when attribute controlled by OneLogin:
Attribute Value Role Update
User User will be assigned
Admin Admin will be assigned
Owner Owner will be assigned The current owner will be replaced with the new owner. The current owner will become a user.
No Value
Empty or Any other value
The user is created as User by default.

Team assignment

  1. Attribute Name: primary_team
  2. Default assignment as Group User, in case of:
    • Empty or no value
    • Attribute controlled by BrowserStack UI
  3. Expected values when attribute controlled by OneLogin:
Attribute Value Team Update
team_name The user gets added to the existing team if a team exists with the same name. Otherwise, a new team will be created with the passed attribute value.
No value/Empty The user is assigned as part of Group

Product assignment

  1. Attribute Name: primary_product
  2. Default assignment no product access, in case of
    • Unexpected, empty or no value
    • Attribute controlled by BrowserStack UI
  3. Expected values when attribute controlled by OneLogin:
Attribute values Product Update
Browser-Testing Live
Automate
Visual-Testing Percy
Automate-Testing Automate
Live-Testing Live
Mobile-App-Testing App Live
App Automate
App-Automate-Testing App Automate
App-Live-Testing App Live
App-Percy App-Percy
App-Accessibility-Testing App Accessibility
Accessibility-Testing Accessibility Testing
Test-Management Test Management
Test-Reporting-&-Analytics Test Reporting & Analytics
Low-Code-Automation Low Code Automation
Bug-Capture Bug Capture
Requestly Requestly
Testing-Toolkit Testing Toolkit
Central-Scanner Central Scanner
Automate-turboscale Automate TurboScale
Accessibility-Design-Toolkit Accessibility Design Toolkit
Load-Testing Load Testing
Note:

BrowserStack SCIM endpoints

OneLogin talks to the BrowserStack SCIM server on the following endpoints. Use them to check which SCIM features BrowserStack supports, look up the structure of the custom attributes, and interpret the responses that appear in your OneLogin event logs.

Service provider configuration

The Service Provider Config endpoint returns the BrowserStack server’s authentication scheme and the optional or configurable SCIM features it supports. Service Provider Config objects are defined by RFC 7643, section 5.

GET https://www.browserstack.com/scim/v2/ServiceProviderConfig

Sample response:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig"],
  "documentationUri": "https://www.browserstack.com/docs/enterprise/auto-user-provisioning",
  "patch": { "supported": true },
  "bulk": { "supported": false, "maxOperations": 0, "maxPayloadSize": 0 },
  "filter": { "supported": true, "maxResults": 500 },
  "changePassword": { "supported": false },
  "sort": { "supported": false },
  "etag": { "supported": false },
  "authenticationSchemes": [
    {
      "name": "OAuth Bearer Token",
      "description": "Authentication scheme using the OAuth Bearer Token Standard",
      "specUri": "http://tools.ietf.org/html/rfc6750",
      "type": "oauthbearertoken"
    }
  ],
  "meta": {
    "resourceType": "ServiceProviderConfig",
    "location": "https://www.browserstack.com/scim/v2/ServiceProviderConfig"
  }
}

Resource types

The Resource Types endpoint lists all of the SCIM resource types configured for use on the BrowserStack server. Use the response to determine the endpoint, core schema, and extension schemas of any resource type that the server supports. This endpoint does not provide resource type information about SCIM sub-resources.

The response is formatted as a list response, with one or more resource type objects in the Resources field. Resource type objects are defined by RFC 7643, section 6.

GET https://www.browserstack.com/scim/v2/ResourceTypes

Sample response:

{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
  "totalResults": 1,
  "Resources": [
    {
      "schemas": ["urn:ietf:params:scim:schemas:core:2.0:ResourceType"],
      "id": "Users",
      "name": "Users",
      "endpoint": "/Users",
      "schema": "urn:ietf:params:scim:schemas:core:2.0:User"
    }
  ]
}

User resource type

The Resource Type endpoint retrieves a specific SCIM resource type, specified by its ID. BrowserStack supports the User resource only. Resource type objects are defined by RFC 7643, section 6. This endpoint does not provide resource type information about SCIM sub-resources.

GET https://www.browserstack.com/scim/v2/ResourceTypes/User

Sample response:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:ResourceType"],
  "id": "Users",
  "name": "Users",
  "endpoint": "/Users",
  "description": "User Account",
  "schema": "urn:ietf:params:scim:schemas:core:2.0:User",
  "meta": {
    "location": "https://www.browserstack.com/scim/v2/ResourceTypes/User",
    "resourceType": "ResourceType"
  }
}
  • To update an existing user resource, use the PUT endpoint.
  • If your IdP does not support the PUT endpoint, use the PATCH /scim/v2/Users/{id} endpoint.

Example request body for a PATCH request:

{
    "schemas": [
        "urn:ietf:params:scim:schemas:core:2.0:User"
    ],
    "Operations":[{"op": "add", "path" : "urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_product", "value" : "App-Live-Testing,App-Automate-Testing"}]
}

Schemas

The Schemas endpoint lists the SCIM schemas configured for use on the BrowserStack server, which define the attributes available to resource types. Use this endpoint to check the structure of the custom primary_role, primary_team, and primary_product attributes. This endpoint does not provide schema information about SCIM sub-resources.

The response is formatted as a list response, with one or more schema objects in the Resources field. Schema objects are defined by RFC 7643, section 7.

GET https://www.browserstack.com/scim/v2/Schemas

Sample response:

{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
  "totalResults": 1,
  "Resources": [
    {
      "id": "urn:ietf:params:scim:schemas:core:2.0:User",
      "name": "User",
      "description": "User Schema",
      "attributes": [
        {
          "name": "userName",
          "type": "string",
          "multiValued": false,
          "required": true,
          "caseExact": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "server",
          "description": "Unique identifier for the User, typically used by the user to directly authenticate to the service provider. Each User MUST include a non-empty userName value. This identifier MUST be unique across the service provider's entire set of Users."
        },
        {
          "name": "name",
          "type": "complex",
          "multiValued": false,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "The components of the user's real name. Providers MAY return just the full name as a single string in the formatted sub-attribute, or they MAY return just the individual component attributes using the other sub-attributes, or they MAY return both.  If both variants are returned, they SHOULD be describing the same name, with the formatted name indicating how the component attributes should be combined.",
          "subAttributes": [
            {
              "name": "familyName",
              "type": "string",
              "multiValued": false,
              "required": false,
              "caseExact": false,
              "mutability": "readWrite",
              "returned": "default",
              "uniqueness": "none",
              "description": "The family name of the User, or last name in most Western languages (e.g., 'Jensen' given the full name 'Ms. Barbara J Jensen, III')."
            },
            {
              "name": "givenName",
              "type": "string",
              "multiValued": false,
              "required": false,
              "caseExact": false,
              "mutability": "readWrite",
              "returned": "default",
              "uniqueness": "none",
              "description": "The given name of the User, or first name in most Western languages (e.g., 'Barbara' given the full name 'Ms. Barbara J Jensen, III')."
            }
          ]
        },
        {
          "name": "active",
          "type": "boolean",
          "multiValued": false,
          "required": true,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A Boolean value indicating the User's status."
        },
        {
          "name": "bstack_team",
          "type": "string",
          "multiValued": false,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A String value indicating the User's Team in BrowserStack"
        },
        {
          "name": "bstack_role",
          "type": "string",
          "multiValued": false,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A String value indicating the User's Role in BrowserStack"
        },
        {
          "name": "bstack_product",
          "type": "string",
          "multiValued": true,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A String value indicating the User's Product accesses in BrowserStack"
        }
      ],
      "meta": {
        "resourceType": "Schema",
        "location": "https://www.browserstack.com/scim/v2/Schemas/urn:ietf:params:scim:schemas:core:2.0:User"
      }
    }
  ]
}

Individual schema

The Schema endpoint retrieves a specific SCIM schema, specified by its ID, which is always a URN. BrowserStack supports the User schema only. Schema objects are defined by RFC 7643, section 7. This endpoint does not provide schema information about SCIM sub-resources.

GET https://www.browserstack.com/scim/v2/Schemas/urn:ietf:params:scim:schemas:core:2.0:User

The response is the same User schema object that the Schemas endpoint returns in its Resources array, returned on its own without the list wrapper. For the full object, see the Schemas sample response.

Replace a user

The Replace User endpoint updates an existing user by replacing the resource with the values in the request body. You can update the name, role, team, and product attributes, and change the email through userName. Attributes that are controlled by the BrowserStack dashboard as per the current configuration cannot be updated through this endpoint.

PUT https://www.browserstack.com/scim/v2/Users/{id}

A successful request returns 200 with the full user resource, including externalId, active, and the custom bstack_* attributes:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
  "id": 12345,
  "externalId": "john.doe",
  "userName": "john.doe@example.com",
  "active": true,
  "name": { "givenName": "John", "familyName": "Doe" },
  "emails": [{ "primary": true, "value": "john.doe@example.com" }],
  "bstack_role": "Admin",
  "bstack_team": "Engineering",
  "bstack_product": "Live,Automate",
  "meta": {
    "resourceType": "User",
    "created": "2026-01-10T08:12:33.000Z",
    "lastModified": "2026-07-15T09:00:00.000Z",
    "location": "https://www.browserstack.com/scim/v2/Users/12345"
  }
}

In this response, userName carries the user’s email, and externalId carries the BrowserStack username.

Some fields are returned conditionally based on your SCIM configuration:

  • bstack_role, bstack_team, and bstack_product are returned only when that attribute is controlled by the IdP in your SCIM configuration.
  • meta is returned only for accounts enabled for the SCIM metadata response.
  • id is an integer by default, and a string for accounts enabled for string user IDs.

Update a user

The Update User endpoint applies a partial update to an existing user using a SCIM PatchOp request. A replace operation that sets active to false de-provisions the user.

PATCH https://www.browserstack.com/scim/v2/Users/{id}

A successful request returns 200 with the full user resource, in the same shape as the Replace a user response, including the conditional fields described earlier:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
  "id": 12345,
  "externalId": "john.doe",
  "userName": "john.doe@example.com",
  "active": true,
  "name": { "givenName": "John", "familyName": "Doe" },
  "emails": [{ "primary": true, "value": "john.doe@example.com" }],
  "bstack_role": "Admin",
  "bstack_team": "Engineering",
  "bstack_product": "Live,Automate",
  "meta": {
    "resourceType": "User",
    "created": "2026-01-10T08:12:33.000Z",
    "lastModified": "2026-07-15T09:00:00.000Z",
    "location": "https://www.browserstack.com/scim/v2/Users/12345"
  }
}

Error responses

When a request fails, all endpoints return the same SCIM error envelope with an HTTP status code such as 400, 403, 404, or 422:

{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"],
  "detail": "Human-readable error message",
  "status": "404"
}

Common cases include:

  • 403: Missing or invalid credentials.
  • 404: The requested resource is not found.
  • 400 or 422: Invalid request, or an attribute that is controlled by the BrowserStack dashboard as per the current configuration.

Troubleshooting

Below is a list of possible errors that might be encountered and how to resolve them:

User already present on BrowserStack

Resolution: User already presents on BrowserStack under a different organization, please get the account deleted before provisioning the user.

User already present on BrowserStack

Invalid parameter/attribute values passed for Role or Product

Resolution: Role/Product is not a valid use-case, please use the attribute values provided above.

User could not be updated error

Owner deletion

Note: Owner cannot be directly deleted via OneLogin. Please assign the owner role to another user via BrowserStack UI, and then delete the old owner.

Incompatible attributes

Resolution: You are assigning incompatible user attributes, for example Owner cannot have a team assigned.

Troubleshooting Incomplete attributes in BrowserStack SSO

Licenses unavailability

Resolution: You have used up all your licenses for the product, please unassign users or add more licenses. Contact your Account Executive to get information on adding licenses.

Note: When a user is deactivated on OneLogin, the said user will be deleted from your BrowserStack account. Whenever the user is activated, a new user will be created on BrowserStack. This would lead to a new id being created.

Escalation/Support

Contact us for any escalations or support.

We're sorry to hear that. Please share your feedback so we can do better

Contact our Support team for immediate help while we work on improving our docs.

We're continuously improving our docs. We'd love to know what you liked





Thank you for your valuable feedback

Is this page helping you?

Yes
No

We're sorry to hear that. Please share your feedback so we can do better

Contact our Support team for immediate help while we work on improving our docs.

We're continuously improving our docs. We'd love to know what you liked





Thank you for your valuable feedback!

Talk to an Expert
Download Copy Check Circle