
--.20920 (Customer) asked a question.
Question About Unified On-prem SCIM Agent and OPA/OPS Architecture
Hello,
We would like to perform a test using the unified Okta On-prem SCIM Agent referenced in the previous Support response.
Currently, under Settings > Downloads in the Okta Admin Console, we can only see the Okta On-prem SCIM Server. There is no separate download option available for the unified Okta On-prem SCIM Agent.
Could you please clarify the following?
- Where can we download the unified Okta On-prem SCIM Agent?
- Does the feature require any Feature Flag, Early Access, or other enablement?
- If available, could you please provide the official installation and configuration documentation?
Additionally, we would like to confirm the supported architecture for the legacy Okta Provisioning Agent (OPA) + Okta On-prem SCIM Server (OPS) configuration.
Is it officially supported for a single OPA instance to communicate with multiple OPS instances?
For example:
1 OPA → Multiple OPS
Or is a strict 1:1 relationship between OPA and OPS required?
If a 1 architecture is supported, please also advise whether there are any limitations, prerequisites, or recommended deployment guidelines for this configuration.
Thank you.

Hello @--.20920 (Customer) Thank you for posting on our Community page!
You are asking where to download the unified Okta On-prem SCIM Agent, whether it requires feature enablement, where to find installation documentation, and whether a single Okta Provisioning Agent can communicate with multiple On-prem SCIM Server instances.
1. For standard On-Premises Provisioning, the architecture relies on two distinct components:
You only need to download the standard Okta Provisioning Agent, which is available in your Admin Console under Settings > Downloads.
Enablement & Prerequisites
Standard On-Premises Provisioning does not require a specific Feature Flag or Early Access enablement to download the agent. However, please note that Okta officially supports custom on-premises SCIM integrations only when the implementation is performed by Okta Professional Services, a Certified Partner, or when using the OIG Okta On-Prem Connector.
2. Supported Architecture (OPA to OPS)
Yes, it is officially supported for a single Okta Provisioning Agent (OPA) to communicate with multiple Okta On-Prem SCIM Servers (OPS). A strict 1:1 relationship is not required.
Okta's official documentation states: "You can connect your Okta Provisioning Agent to multiple on-premises apps, but you must provide a unique SCIM server URL for each app."
In a 1 OPA → Multiple OPS architecture, the OPA acts as a router. In the Okta Admin Console (under the Provisioning > Integration tab for each respective application), you simply select the same OPA from the "Connect to these agents" dropdown and specify the unique base URL for that specific app's downstream SCIM connector.
3. Limitations and Deployment Guidelines
While routing multiple SCIM servers through a single OPA is fully supported, you should keep the following guidelines in mind:
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Thank you very much for your detailed response.
I apologize if my previous question was not clear enough. I would like to clarify what I am specifically trying to confirm.
In my previous inquiry regarding the Okta Provisioning Agent (OPA) and the Okta On-prem SCIM Server (OPS), I was informed that Okta had introduced a unified Okta On-prem SCIM Agent that replaces both the OPA and OPS, combining their functionality into a single agent.
Based on that information, I wanted to test this unified On-prem SCIM Agent and checked Settings > Downloads in the Okta Admin Console.
However, I can currently see only the Okta Provisioning Agent and On-prem SCIM Server as separate components, and I cannot find any download option specifically named On-prem SCIM Agent.
Therefore, my question is not about how to download and use the existing OPA and OPS separately.
I would specifically like to confirm the following:
I would greatly appreciate your clarification, as I would like to test the unified agent specifically rather than the existing separate OPA + OPS architecture.
Thank you again for your assistance.