SCIM 2.0 provisioning automatically manages your team members and directory groups through your identity provider. Available on Enterprise plans with SSO enabled.
Users are automatically added to Cursor when assigned to the SCIM application in your identity provider. When unassigned, they’re removed. Changes sync in real-time.
Directory groups and their membership sync from your identity provider. Group and user management must be done through your identity provider - Cursor displays this information as read-only.
Set different per-user spend limits for each directory group. Directory group limits take precedence over team-level limits. Users in multiple groups receive the highest applicable spend limit.
Once SSO is verified, you’ll see a link for step-by-step SCIM setup. Click
this to begin the configuration wizard.
4
Configure SCIM in your identity provider
In your identity provider: - Create or configure your SCIM application - Use
the SCIM endpoint and token provided by Cursor - Enable user and push group
provisioning - Test the connection
5
Configure spend limits (optional)
Back in Cursor’s Active Directory Management page: - View your synchronized
directory groups - Set per-user spend limits for specific groups as needed -
Review which limits apply to users in multiple groups
All user and group management must be done through your identity provider.
Changes made in your identity provider will automatically sync to Cursor, but
you cannot modify users or groups directly in Cursor.