
MatthewH.10249 (State of Iowa) asked a question.
We have several Salesforce apps set up using the OIN catalog template and while authentication works find we get an error when trying to get SCIM provisioning set up. We can call the SCIM APIs via POSTMAN with no issues but get an error in Okta. We think the issue might be related to custom URLs but since we cannot set a URL in SCIM when using the OIN template we want to know if anyone has ran into this same issue and has a fix. We are opening a support case with Salesforce as the error states to have a Salesforce admin investigate but when we looking in Salesforce we see no log activity related to this so no idea what is the cause of the error. Thanks in advance for any suggestions!

Okta support provided us the following "Knowledge Base" article and the value we had set for "Callback URL" (see step #2 - b - iii) was not the value correct. When we changed the value in Salesforce "https://system-admin.okta.com/admin/app/generic/oauth20redirect" it took awhile for cache to sync but by the next day it worked. When I say "worked" I mean that we were able to press the "Authenticate with Salesforce.com" on the Okta Provisioning tab page for our Salesforce app and it opened a popup window with a Salesforce login screen. We had to click the “Use custom domain” link on that popup page before entering the service account we created username and local Salesforce password. We had to grant that Service Account elevated permissions in order for SCIM APIs to run under that account.
https://support.okta.com/help/s/article/Configuration-Guide-for-Salesforce-REST-Integration?language=en_US