# SCIM & Organization-Key Scoped API Routes

Where is this feature available?

- Hobby
  - Not Available
- Core
  - Not Available
- Pro
  - Not Available
- Enterprise
  - Available
- Self Hosted
  - Enterprise Edition

Via organization-scoped API keys, you can administer projects, users, and project/organization memberships (see [RBAC docs](/content/docs/administration/rbac/index.html)).

Langfuse is open and meant to be extended via custom workflows and integrations. You can use these endpoints to automate project and user management on your Langfuse organization.

This documentation covers organization management APIs, SCIM-compliant user provisioning endpoints, and includes a comprehensive guide for setting up Okta authentication and user provisioning with Langfuse.

## Authentication

Authenticate with the API using [Basic Auth](https://en.wikipedia.org/wiki/Basic_access_authentication). Organization scoped API keys can be created via the [Instance Management API](/content/self-hosting/administration/instance-management-api/index.html) or in the Organization Settings within the Langfuse UI.

Example:

```bash
curl -u public-key:secret-key https://cloud.langfuse.com/api/public/projects/{projectId}/apiKeys
```

## Organization Management

All applicable endpoints are marked with `(requires organization-scoped API key)`. Those include the following routes:

- `POST /api/public/projects`
- `PUT /api/public/projects/{projectId}`
- `DELETE /api/public/projects/{projectId}`
- `GET /api/public/projects/{projectId}/apiKeys`
- `POST /api/public/projects/{projectId}/apiKeys`
- `DELETE /api/public/projects/{projectId}/apiKeys/{apiKeyId}`
- `PUT /api/public/organizations/memberships`
- `GET /api/public/organizations/memberships`
- `PUT /api/public/projects/{projectId}/memberships`
- `DELETE /api/public/projects/{projectId}/memberships`

See [API Reference](https://api.reference.langfuse.com/) for more details.

## User Management via SCIM

In addition, we implement the following [SCIM](https://datatracker.ietf.org/doc/html/rfc7642) compliant endpoints. Use `/api/public/scim` as the base URI for them.

To create a new user within Langfuse, you can use the SCIM-style endpoints and `POST /Users`. This will create a new user if the email does not exist yet. Then it will add the user to the organization with role `NONE` (unless a `roles` attribute is provided, see [Okta guide below](/content/docs/administration/scim-and-org-api#okta/index.html)).

Afterward, the role can be updated using the membership endpoints either on an organization or a project level (see above).

### SCIM Vendor Guides

#### Okta

This guide covers how to set up Okta user provisioning for Langfuse.

**Okta requires two separate applications.** Okta does not support enabling [SCIM on a custom OIDC app](https://support.okta.com/help/s/article/configure-scim-for-a-custom-oidc-app?language=en_US). Configure:

1. An **OIDC application** for SSO — see [Authentication and SSO → Okta](/content/docs/administration/authentication-and-sso#okta/index.html)
2. A separate **SAML application** for SCIM provisioning — steps below

The SSO settings on the SCIM/SAML application do not need to work; Langfuse uses the OIDC app for authentication.

Langfuse supports the SCIM 2.0 protocol for user provisioning.

### Troubleshooting

- **Users are provisioned with NONE/VIEWER permissions instead of their intended `role`**: This usually happens if the `roles` attribute has an attribute type `Group` instead of `Personal`.
- **User lost their role after enabling SCIM**: During initial SCIM setup, if a user is deprovisioned and re-provisioned, their organization role is overwritten with the value from the SCIM `roles` attribute. If no role is configured in the IdP, the default is `NONE`. To fix this, ensure the correct role (including `OWNER` for organization owners) is set in the IdP profile before provisioning.
