npm · entra-scim-mcp
$npx -y entra-scim-mcp@0.3.0 ENTRA_TENANT_ID — Directory (tenant) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN, which supply their own placeholder.
ENTRA_CLIENT_ID — App registration (client) GUID. Required to authenticate against a live tenant; not needed for ENTRA_SCIM_DRY_RUN or ENTRA_SCIM_STATIC_TOKEN.
ENTRA_CLIENT_SECRET · secret — Client secret value. For a live tenant set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH; a certificate is preferred for anything long-lived.
ENTRA_CLIENT_CERT_PATH — Path to a PEM holding the certificate and its private key. Set exactly one of ENTRA_CLIENT_SECRET or ENTRA_CLIENT_CERT_PATH.
ENTRA_CLIENT_CERT_PASSWORD · secret — Password for the PEM, if it is encrypted.
ENTRA_SCIM_BASE_URL — Override the SCIM base URL (default https://graph.microsoft.com/rp/scim). Point it at the bundled mock to try the tools without a tenant.
ENTRA_SCIM_STATIC_TOKEN · secret — Use a fixed bearer token instead of Azure AD. Refuses any microsoft.com/microsoft.us host and requires ENTRA_SCIM_BASE_URL; intended for the local mock only.
ENTRA_SCIM_DRY_RUN — Set to 1 to run every client-side validation and return the request that would have been sent, without sending it or acquiring a token.