UnboundID releases SCIM toolkit beta

Opinion
Jul 22, 20112 mins

One place you could have gone to escape the recent heat wave that encompassed most of the U.S. was Keystone, Colo., where the afternoon temperatures barely reached the mid-70s F (while here in the mid-Atlantic we were stretching from the mid-90s to 100 or so). And while you were there you could have attended the Cloud Identity Summit, ably organized by Ping Identity’s Andre Durand.

Among the many interesting discussions, you would have heard a lot about Simple Cloud Identity Management, (SCIM), a new protocol for provisioning in the cloud which I’m not totally sold on the need for.

BACKGROUND: Got SCIM?

I did spend some time on the phone with UnboundID’s Andy Land (along with Chris LaPointe, Nick Crown and Craig MacDonald) recently and SCIM was one of the major topics of conversation. Primarily, they wanted me to know about a release they were going to make (and, now, have made) at the Summit: a beta version of the industry’s first software development toolkit (SDK) to support SCIM.

The new SCIM toolkit is provided free of charge to developers interested in exploring the delivery of customer and identity data between cloud, mobile and on-premise applications more efficiently and securely. The SDK can be downloaded free of charge from the UnboundID website.

This SDK is the first release from UnboundID Labs, a new research and development division of UnboundID, which will focus on pioneering innovative technologies in the identity management space as well as prototyping extensions to existing UnboundID products.

I’m still not pleased with SCIM; I think enterprise needs are being given short shrift as all development appears to be led by software-as-a-service (SaaS) providers (Salesforce.com, Google, etc.) and not by those in the enterprise or traditional IdM vendors. It may succeed, it may not — history is littered with IdM schemes (CardSpace, Passport, OpenID, DigitalME, et al.) that went nowhere. But on the off chance that SCIM can be made useful you should probably look at the spec and play with the SDK. Better safe than sorry.