This version was released on July 2, 2026.
We're introducing SCIM provisioning, so your identity provider can manage who has access to your Supernova workspace automatically. Once configured, assigned users are created in Supernova automatically, profile changes sync in, and deactivated users lose access without any manual cleanup.
SCIM provisioning
SCIM (System for Cross-domain Identity Management) requires SSO to already be configured for your workspace. Supernova supports SCIM 2.0 with Okta and Microsoft Entra ID, using the same application already set up for SSO.
User provisioning
Users assigned to the Supernova application in your identity provider are created automatically as workspace members. New users are created with the Viewer role and no seat assigned — an admin still handles role and seat assignment in Supernova. The user's email must match one of the workspace's allowed SSO email domains.
Profile sync
Name, display name, nickname, email, and avatar stay in sync with the identity provider. Email is treated as the stable identifier, so attempts to change or remove it are rejected.
Deactivation and deletion
When a provider deactivates a user, Supernova suspends their workspace access and preserves their data — they can be reactivated at any time. When a provider deletes a user, they're fully removed from Supernova; if the same person is provisioned again later, they come back as a new user.
Managing your SCIM connection
Base URL and token setup, token rotation, and disabling SCIM are all handled from Settings → Security & login → SSO. Learn more about setting up SCIM provisioning, including step-by-step Okta and Microsoft Entra ID configuration.
Backwards compatible
SCIM provisioning is available on the Enterprise plan and is opt-in. Workspaces that don't enable it are unaffected — existing member management workflows continue to work unchanged.
For a list of smaller improvements and bug fixes, visit our Bug fixes page here: