Identity and integrations# Identity and integrations <span class="badge-status">Available</span> <span class="badge-status">Reserved for administrators</span> ## Objective **Settings → Identity and Integrations** covers OIDC/SAML providers, SCIM readiness, service keys and HTTPS webhooks. Each entry has type, provider, name, scopes, and state. ## Creation and secrets Choose the minimum range and activate after validation. A webhook key or secret is only displayed in plain text once: copy it immediately to a vault. Deletion revokes the integration. ## Webhooks and APIs Signatures use HMAC SHA-256 on timestamp and payload. The `/api/v1/service/status` service only reveals organization and scopes. Test rotation and revocation before automation. ## Roadmap SCIM preparation is present in the integrations; do not assume full provisioning without validating the intended journey. ## Create an integration Choose type and vendor, give a name indicating usage and environment, then enter the minimum scopes sepa