This article explains the meaning of the "Pending SCIM" user status in Figma and provides steps to resolve the issue. This status is typically not an error but an expected state during the initial user provisioning and Single Sign-On (SSO) process.
- Figma
- System for Cross-domain Identity Management (SCIM) provisioning
- Single Sign On (SSO)
- Okta Integration Network (OIN)
The "Pending SCIM" status indicates that the user's account has been successfully created and provisioned in Figma via the Okta SCIM integration. However, the user has not yet completed their first login via Single Sign-On (SSO). The finalization of the account, including the full synchronization of SCIM-related metadata, requires the user to authenticate through the SSO flow. This process confirms the user's identity and fully links their Okta profile with their Figma account.
The Okta System Log will not show any errors because the SCIM provisioning request was successfully sent and received by Figma. The issue is a matter of user action, not a technical failure of the provisioning process.
Follow these steps to resolve the "Pending SCIM" user status:
-
Instruct the User to Log In via SSO. The user must initiate a login directly through the organization's Okta login page or the Figma login page using the SSO option.
-
Figma Login Page
-
Direct the user to the Figma login page and have them enter their email address. They should then be redirected to the Okta sign-in page to complete authentication.
-
-
Okta Dashboard
-
The user can also log in to their Okta dashboard and click on the Figma application tile. This will automatically initiate the SSO flow.
-
Verify SCIM and SSO Configuration (if the issue persists) as if the user has already attempted to log in via SSO, and the status remains "Pending SCIM," there may be a configuration issue.
-
Check Attribute Mapping
-
In the Okta Admin Console, navigate to the Figma application. Go to Provisioning > To App and review the Attribute Mappings. Ensure that the userName and email attributes are correctly mapped from Okta to the corresponding Figma user attributes.
-
-
Validate SCIM API Token
-
Confirm that the SCIM API token configured in the Okta provisioning settings is still valid in Figma. If necessary, generate a new token in Figma and update it in the Okta application's provisioning settings.
