---
title: "Connect Figma SCIM to Claude: Control Group Membership & Roles"
slug: connect-figma-scim-to-claude-control-group-membership-roles
date: 2026-10-10
author: Roopendra Talekar
categories: ["AI & Agents"]
excerpt: "Learn how to connect Figma SCIM to Claude via a managed MCP server to automate user provisioning, audit seat roles, and control group memberships securely."
tldr: "A technical guide to integrating Figma SCIM with Claude using Truto's managed MCP server. Covers SCIM patch operations, rate limits, and secure tool execution for identity workflows."
canonical: https://truto.one/blog/connect-figma-scim-to-claude-control-group-membership-roles/
---

# Connect Figma SCIM to Claude: Control Group Membership & Roles


If your IT or DevOps team needs to connect Figma SCIM to Claude to automate user provisioning, audit seat roles, or control group memberships, you need a Model Context Protocol (MCP) server. This server acts as the translation layer between Claude's tool calls and Figma's SCIM (System for Cross-domain Identity Management) REST APIs. You can either build and maintain this infrastructure yourself, or use a managed integration platform like Truto to dynamically generate a secure, authenticated MCP server URL. If your team uses ChatGPT, check out our guide on [connecting Figma SCIM to ChatGPT](https://truto.one/connect-figma-scim-to-chatgpt-manage-user-access-provisioning/) or explore our broader architectural overview on [connecting Figma SCIM to AI Agents](https://truto.one/connect-figma-scim-to-ai-agents-orchestrate-scim-lifecycle-tasks/).

Giving a Large Language Model (LLM) read and write access to your organization's identity management ecosystem is a serious engineering challenge. You have to handle API token lifecycles, map massive, nested SCIM JSON schemas to MCP tool definitions, and deal with Figma's strict API quotas. Every time an endpoint shifts or a schema requirement changes, you have to update your server code, redeploy, and test the integration.

This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for Figma SCIM, connect it natively to Claude Desktop, and execute complex identity management workflows using natural language.

> Want to give your AI agents secure, authenticated access to Figma SCIM and 100+ other SaaS APIs? Let's talk about managed MCP architecture.
>
> [Talk to us](https://truto.one/book-a-demo/)

## The Engineering Reality of the Figma SCIM API

A custom MCP server is a self-hosted integration layer. While the open MCP standard provides a predictable way for models to discover tools, the reality of implementing it against a specific vendor's SCIM API is painful. SCIM is an IETF standard (RFC 7643 and 7644), but every vendor implements it with slight variations. 

If you decide to build a custom MCP server for Figma SCIM, here are the specific integration challenges you will face:

**The Complexity of SCIM Patch Operations**
Figma SCIM supports both full updates (`PUT`) and partial updates (`PATCH`). The `PATCH` endpoint (`/scim/v2/{tenant}/Users/{id}`) requires the standard SCIM PatchOp syntax. For example, replacing a user's seat role requires a payload like `[{"type":"seatType","value":"Dev"}]`. This nested array-of-objects structure is notoriously difficult for LLMs to construct correctly without strict JSON Schema enforcement. A managed MCP server exposes tools like `figma_scim_users_partial_update` with exact schema definitions that force Claude to generate the correct PatchOp arrays, preventing hallucinated payload structures.

**Account Binding and State Transitions**
Figma SCIM has unique behavior when provisioning users. If you send a `POST /scim/v2/{tenant}/Users` request to create a user, and a Figma account with that email already exists, Figma does not return a 409 Conflict. Instead, it silently binds the existing account to SCIM and updates its attributes. An LLM needs explicit instructions in the tool description to understand this state transition so it can accurately interpret the API response and report back to the user.

**Rate Limits and 429 Handling**
Figma enforces rate limits on its SCIM API to protect infrastructure. When building an MCP server, you cannot assume every request will succeed. It is important to note that Truto does not retry, throttle, or apply backoff on rate limit errors automatically. When the Figma SCIM API returns an HTTP 429 Too Many Requests, Truto passes that error directly to the caller. Truto normalizes the upstream rate limit information into standardized headers (`ratelimit-limit`, `ratelimit-remaining`, `ratelimit-reset`) per the IETF specification. The LLM or the agent orchestration framework is responsible for reading these headers and executing the retry/backoff logic.

**Tenant Validation**
Every SCIM request to Figma requires a numeric tenant ID in the path (`/scim/v2/{tenant_id}/...`). If this ID is malformed or the provided Bearer token lacks access to it, the API will reject the request. Building a pre-flight validation check into your MCP server is critical to prevent cascading failures during bulk provisioning tasks.

## Generating the Figma SCIM MCP Server

Truto's MCP servers feature turns your connected Figma SCIM integration into an MCP-compatible tool server instantly. The tool generation is dynamic and documentation-driven. Rather than hand-coding tool definitions, Truto derives them from the integration's defined resources and human-readable documentation records. 

You can generate the MCP server in two ways: via the Truto UI or programmatically via the API.

### Method 1: Via the Truto UI

This is the fastest method for internal IT teams and administrators setting up Claude Desktop.

1. Log into your Truto dashboard.
2. Navigate to the **Integrated Accounts** page and select your connected Figma SCIM account.
3. Click the **MCP Servers** tab.
4. Click **Create MCP Server**.
5. Select your desired configuration. You can restrict the server to specific methods (e.g., read-only) or tag groups.
6. Click **Generate** and copy the resulting MCP server URL (e.g., `https://api.truto.one/mcp/abc123xyz...`).

### Method 2: Via the Truto API

For platform engineers building multi-tenant AI agents, you can generate MCP servers programmatically. Make a `POST` request to the `/integrated-account/:id/mcp` endpoint.

```typescript
// Example: Generating a read-only Figma SCIM MCP Server
const response = await fetch('https://api.truto.one/integrated-account/YOUR_ACCOUNT_ID/mcp', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer YOUR_TRUTO_API_TOKEN',
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    name: "Figma SCIM - Read Only Audit",
    config: { 
      methods: ["read", "list", "get"]
    },
    expires_at: "2026-12-31T23:59:59Z"
  })
});

const data = await response.json();
console.log(data.url); // The MCP server URL to pass to Claude
```

The resulting URL contains a cryptographic token that securely identifies the integrated account and enforces the requested configuration.

## Connecting the MCP Server to Claude

Once you have your Truto MCP server URL, you need to register it with your AI client. The standard MCP JSON-RPC 2.0 protocol allows Claude to send an `initialize` request, discover the available tools via `tools/list`, and execute them via `tools/call`.

### Method A: Via the Claude UI (Desktop/Web)

If you are using Claude Desktop or an enterprise workspace, connecting the server is entirely UI-driven.

1. Open Claude and navigate to **Settings**.
2. Go to **Integrations** -> **Add MCP Server** (or **Connectors** -> **Add custom connector** depending on your tier).
3. Paste the Truto MCP Server URL.
4. Click **Add**.

Claude will immediately perform a handshake with the server and load the Figma SCIM tools into its context window. No additional authentication is required unless you configured the server to require an API token.

### Method B: Via Manual Config File

If you are running Claude Desktop locally and prefer file-based configuration, or if you are using Cursor, you can edit your `claude_desktop_config.json` file to use the Server-Sent Events (SSE) transport.

```json
{
  "mcpServers": {
    "figma-scim-prod": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-sse",
        "--url",
        "https://api.truto.one/mcp/YOUR_SECURE_TOKEN"
      ]
    }
  }
}
```

Restart Claude Desktop. The tools will now be available in your chat interface.

## Hero Tools for Figma SCIM

When Claude calls `tools/list`, Truto dynamically generates the tool schemas. All arguments arrive in a flat input namespace, and Truto automatically routes them to the correct query parameters or HTTP body based on the integration's schema. 

Here are the most critical Figma SCIM tools available to your AI agent.

### figma_scim_tenant_validate

This tool checks whether the connected Figma SCIM tenant ID and bearer token are valid. It is a critical first step before attempting to provision users. A successful response means the tenant ID is valid and accessible. A 400 means the tenant ID is malformed (it must be numeric), and a 404 means it is unknown.

> "Claude, before we run the bulk provisioning script, please validate our Figma SCIM tenant connection to ensure our API token and tenant ID are correct."

### list_all_figma_scim_users

Retrieves SCIM-provisioned users in the Figma organization. It returns full SCIM user resources including `id`, `userName` (email), `active` status, seat role, and enterprise attributes like `department` and `costCenter`. Claude can use the `userName eq "email"` filter to find specific users.

> "Can you list all active Figma SCIM users in the Engineering department? Please filter the results and show me their current seat roles."

### create_a_figma_scim_user

Provisions a new user in Figma via SCIM. If a Figma account with the requested email already exists, Figma automatically binds it to SCIM and updates the attributes. It requires the user's email and active status, and accepts optional parameters for seat role (on Enterprise plans) and `figmaAdmin` flags.

> "We have a new hire starting today. Please create a Figma SCIM user for alex.chen@company.com, set them to active, assign them a 'Dev' seat role, and set their cost center to 'R&D'."

### figma_scim_users_partial_update

Executes a `PATCH` request to change selected attributes of a user without overwriting the entire resource. This is the preferred method for deactivating users (replacing `active` with `false`) or upgrading seat types, utilizing standard SCIM PatchOp syntax.

> "Alex Chen is leaving the company. Please locate his Figma SCIM user ID by his email, and then perform a partial update to set his active status to false. Do not delete his account, just revoke access."

### list_all_figma_scim_groups

Lists SCIM-managed groups in the Figma organization. Each group includes an `id`, `displayName`, and a list of members. Groups whose display names perfectly match an existing Figma workspace or billing group are automatically linked to it.

> "Can you list all Figma SCIM groups and find the one named 'Product Design Workspace'? I need to see how many members currently belong to it."

### create_a_figma_scim_group

Creates a new SCIM group in Figma. If the `displayName` matches an existing Figma workspace (case sensitive), the group is linked, and any members added to this group will inherit access to that workspace.

> "Create a new Figma SCIM group called 'External Contractors'. Once created, add the user ID 109348 to this group as its first member."

To view the complete inventory of available Figma SCIM tools and their exact JSON Schema definitions, visit the [Figma SCIM integration page](https://truto.one/integrations/detail/figmascim).

## Workflows in Action

MCP tools become incredibly powerful when Claude chains them together to solve multi-step IT support tickets or compliance tasks.

### Scenario 1: Onboarding a New Product Designer

IT administrators frequently receive requests to provision new employees with the exact same access as their peers. 

> "We just hired Sarah for the design team (sarah.j@company.com). Please provision her a Figma account with a full design seat. Then, figure out which SCIM group the rest of the 'Product Design' team is in, and add her to that group so she inherits the right workspaces."

**How Claude executes this:**

1. Calls `create_a_figma_scim_user` with `userName: "sarah.j@company.com"`, `active: true`, and the seat role set to the design tier.
2. Calls `list_all_figma_scim_groups` filtering by `displayName eq "Product Design"` to retrieve the group ID.
3. Calls `figma_scim_groups_partial_update` targeting the retrieved group ID, passing a SCIM PatchOp to add Sarah's newly created Figma user ID to the `members` array.

```mermaid
sequenceDiagram
    participant User as IT Admin
    participant Claude as Claude
    participant Figma as Figma SCIM
    User->>Claude: Provision Sarah & add to Design group
    Claude->>Figma: POST /scim/v2/{tenant}/Users (Sarah)
    Figma-->>Claude: Returns User ID (12345)
    Claude->>Figma: GET /scim/v2/{tenant}/Groups?filter=displayName eq "Product Design"
    Figma-->>Claude: Returns Group ID (67890)
    Claude->>Figma: PATCH /scim/v2/{tenant}/Groups/67890 (Add member 12345)
    Figma-->>Claude: 200 OK
    Claude-->>User: Setup complete.
```

### Scenario 2: Offboarding and License Reclamation

When an employee leaves, security compliance dictates that access must be revoked immediately, but their historical assets should remain intact.

> "Marcus (marcus.w@company.com) is offboarding today. Please revoke his access to Figma, but do not permanently delete his account. Just deactivate him so we free up the license."

**How Claude executes this:**

1. Calls `list_all_figma_scim_users` with the filter `userName eq "marcus.w@company.com"` to retrieve Marcus's internal Figma user ID.
2. Calls `figma_scim_users_partial_update` using Marcus's ID, sending a PatchOp to replace the `active` attribute with `false`.
3. Claude confirms to the user that the account has been deactivated, ensuring the seat license is reclaimed without destroying Marcus's design files.

## Security and Access Control

Providing an LLM with write access to your corporate identity provider requires strict guardrails. Truto's MCP architecture provides multiple layers of access control that are enforced at the server level, preventing Claude from executing unauthorized operations.

*   **Method Filtering:** When generating the MCP server, you can restrict it to specific operations via `config.methods`. Setting this to `["read"]` ensures Claude can only call `list` and `get` operations, making the server strictly read-only for audit tasks.
*   **Tag Filtering:** You can restrict the server to only expose tools related to specific resource tags. For example, you could expose `users` tools but hide `groups` tools entirely.
*   **Extra Authentication (`require_api_token_auth`):** By default, possessing the MCP URL is enough to connect. For high-security environments, enabling `require_api_token_auth` forces the client to also provide a valid Truto API Bearer token in the headers, adding a secondary identity check.
*   **Automatic Expiration:** Setting an `expires_at` timestamp creates a short-lived MCP server. This is ideal for giving a temporary contractor or an automated CI/CD pipeline access to SCIM tools for a limited window, after which the server automatically deletes itself.

## Rethink How You Build Agentic Integrations

Connecting Figma SCIM to Claude transforms identity management from a series of manual clicks in an admin portal into a conversational, automated workflow. However, building the required MCP infrastructure from scratch - parsing SCIM schemas, handling PatchOp formatting, and managing token refreshes - is a massive distraction from building your core AI product.

By utilizing a managed integration platform, you offload the entire API lifecycle. You get dynamic, documentation-driven tools that update automatically when schemas change, complete with enterprise-grade access controls.

Stop wrestling with identity APIs and start shipping agentic workflows. Let your LLMs do the heavy lifting while your managed MCP server handles the protocol.
