SailPoint Provisioning for IssueBadge

Bring IssueBadge under SailPoint governance. Use SailPoint's SCIM 2.0 connector to aggregate accounts, provision joiners, update movers and disable leavers, with certification campaigns covering IssueBadge like any other application.

  • Standard SCIM 2.0 connector, no custom code
  • Account aggregation, create, update and disable
  • Owner account protected from accidental disable
  • Works alongside Okta, Entra ID or any other sign-in provider

IssueBadge in SailPoint

SCIM 2.0 source

ConnectorSCIM 2.0
AuthenticationBearer token
Aggregation✓ Users
Provisioning✓ Create, update, disable

✓ Disable never deletes. Certificates and history are kept.

Governance for your certificate platform

IssueBadge behaves like any other SCIM source in SailPoint.

Aggregate

Pull every IssueBadge account into SailPoint with its email, name and active flag for certifications and access reviews.

Provision

Roles and access profiles that include IssueBadge create the account with the role you configure.

Revoke

Leaver events disable the account the same day. Reactivation is a single update.

Connect SailPoint in 3 steps

You need a SailPoint admin and the owner login of your IssueBadge workspace.

1

Generate a provisioning token in IssueBadge

Open Settings → Single sign-on and provisioning and click Generate token. Copy the token and the SCIM base URL. Choose the role new accounts should receive.

2

Add a SCIM 2.0 source in SailPoint

In Identity Security Cloud go to Admin → Connections → Sources → Create, pick SCIM 2.0, enter the SCIM base URL, choose OAuth 2.0 bearer token authentication and paste the token.

3

Map attributes and aggregate

Use the default schema: userName is the email, name.givenName and name.familyName hold the name, active is the enable flag. Run an account aggregation, then add IssueBadge to the access profiles that should provision it.

IssueBadge exposes only the User resource. Group and entitlement aggregation are not needed.

Values you will need

Setting Value
Connector typeSCIM 2.0
SCIM base URLhttps://app.issuebadge.com/scim/v2
AuthenticationBearer token (Authorization header)
Account identifierid
Account nameuserName (email)
Enable flagactive
Supported operationsGET, POST, PUT, PATCH, DELETE (disable)

The exact redirect and initiate-login URLs for your workspace are shown in IssueBadge under Settings → Single sign-on.

Frequently asked questions

Does SailPoint handle sign-in too?

SailPoint governs accounts. For sign-in, connect Okta, Microsoft Entra ID or any OpenID Connect provider in the same IssueBadge settings page.

What happens on DELETE?

IssueBadge disables the account instead of deleting it, so issued certificates and audit history stay intact. Setting active to true restores access.

Can SailPoint disable the workspace owner?

No. Requests to disable the owner are refused with a SCIM mutability error so the workspace cannot lock itself out.

Does this work with IdentityIQ?

Yes. IdentityIQ's SCIM 2.0 connector uses the same endpoints and bearer token.

Does this cost extra?

No. SCIM provisioning is included on every IssueBadge plan.

IssueBadge, governed by SailPoint

One token, one connector, every account accounted for.

Start free with IssueBadge