Skip to main content
SCIM group mappings connect groups from your identity provider to OpenRouter workspaces. Once a group is mapped, members of that group are automatically granted the chosen role in the mapped workspace — and access stays in sync as people join and leave groups in your IdP.
SCIM group mappings are available for organizations on Enterprise plans and require an active SSO connection.

Prerequisites

  • Your organization must be on an Enterprise plan
  • You must be an organization admin
  • Your organization must have an SSO connection — see Single Sign-On (SSO)
  • Your identity provider must push groups to OpenRouter via SCIM provisioning
If no SSO connection exists yet, the SCIM Mappings tab prompts you to set one up first.

Viewing Your Groups

While in your organization context, navigate to Settings > Members and select the SCIM Mappings tab. Groups pushed by your identity provider appear here as cards, each showing the group name and how many workspaces it’s mapped to. You can:
  • Filter groups by all / mapped / unmapped
  • Refresh from IdP to pull the latest groups on demand — the “Last synced” timestamp shows when groups were last refreshed
  • View audit log to see a history of mapping and membership changes
Groups also sync automatically as your identity provider pushes changes. Use Refresh from IdP if you’ve just configured provisioning and don’t see your groups yet.

Creating a Mapping

1

Find the group

Locate the group card you want to map (use the unmapped filter to see groups without any mappings).
2

Add a mapping

Click Add mapping, then choose a workspace and a role — Member or Admin. The role defaults to Member (or Admin, for groups whose name contains “admin”).
3

Confirm

Click Add mapping to save. Everyone in the group is granted the chosen role in that workspace.
A group can be mapped to any number of workspaces, with one mapping per group–workspace pair.

How Membership Sync Works

  • Joining a group: when someone is added to a mapped group in your identity provider, they’re automatically added to the mapped workspaces with the mapping’s role.
  • Leaving a group: when someone is removed from a mapped group, workspace access granted by that mapping is removed as well.
  • Multiple groups: if a member belongs to several groups mapped to the same workspace, they get the highest role across those mappings — Admin wins over Member.

Changing a Mapping’s Role

Use the role selector on any mapping row to switch between Member and Admin. Existing members provisioned by the mapping are updated to their new effective role. Highest role still wins: a member who also gets Admin from another mapped group keeps Admin even if you lower this mapping to Member.

Removing a Mapping

Click the delete button on a mapping row. Because members may have been added to the workspace by this mapping, you’ll be asked what should happen to them:
  • Keep members: the mapping is removed, but members added by it stay in the workspace. Their memberships become manually managed (keeping their current role), so group changes in your identity provider no longer affect them.
  • Remove members: the mapping is removed, and members whose access came from this mapping are removed from the workspace
Members who belong to another group still mapped to the same workspace keep their access either way — only access that came solely from the deleted mapping is affected.

Audit Log

Every change made through SCIM mappings is recorded. Click View audit log on the SCIM Mappings tab to see:
  • Mappings created, role changes, and deletions — with the admin who made the change
  • Members added to, removed from, or changed in workspaces — including changes triggered automatically by your identity provider
Entries link to the affected member and workspace so you can trace exactly why someone’s access changed.

Frequently Asked Questions

The tab is available to organization admins on Enterprise plans. If you’re on an Enterprise plan and still don’t see it, contact support@openrouter.ai.
Groups appear once your identity provider pushes them via SCIM provisioning. Check your IdP’s provisioning configuration, then click Refresh from IdP. You also need an active SSO connection.
Yes. Add as many mappings as you need on a group’s card — each workspace can have its own role for that group.
Once the deletion syncs (automatically, or via Refresh from IdP), the group is deactivated on OpenRouter and stops granting access through its mappings. Members who aren’t entitled through another mapped group lose the access it granted, and the removals are recorded in the audit log.
No. Mappings work alongside manually managed members. Manually added members are unaffected by mapping changes.

Getting Help

  • Setup assistance: Email support@openrouter.ai
  • Enterprise plans: Contact our sales team to enable SCIM group mappings for your organization