> ## Documentation Index
> Fetch the complete documentation index at: https://langwatch.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Provision a group

> Creates an access group. Members are given as LangWatch user ids, the same ids the Users endpoints return; an id that is not a member of the organization is skipped rather than failing the call, so a group can be provisioned before everyone in it is. Granting the group access is a separate step: a group carries no permissions until a role binding is created for it.



## OpenAPI

````yaml POST /api/scim/v2/Groups
openapi: 3.1.0
info:
  title: LangWatch API
  version: 1.0.0
  description: LangWatch openapi spec
servers:
  - url: https://app.langwatch.ai
security:
  - project_api_key: []
paths:
  /api/scim/v2/Groups:
    post:
      tags:
        - SCIM
      summary: Provision a group
      description: >-
        Creates an access group. Members are given as LangWatch user ids, the
        same ids the Users endpoints return; an id that is not a member of the
        organization is skipped rather than failing the call, so a group can be
        provisioned before everyone in it is. Granting the group access is a
        separate step: a group carries no permissions until a role binding is
        created for it.
      operationId: scimCreateGroup
      parameters: []
      responses:
        '201':
          description: The provisioned group.
          content:
            application/scim+json:
              schema:
                type: object
                properties:
                  schemas:
                    type: array
                    items:
                      type: string
                    description: The SCIM schema URNs this resource conforms to.
                  id:
                    type: string
                    description: The LangWatch group id.
                  displayName:
                    type: string
                  members:
                    type: array
                    description: >-
                      Omitted when the request excluded the members attribute.
                      Each value is a LangWatch user id.
                    items:
                      type: object
                      properties:
                        value:
                          type: string
                        display:
                          type: string
                  meta:
                    type: object
                    properties:
                      resourceType:
                        type: string
                      created:
                        type: string
                        format: date-time
                      lastModified:
                        type: string
                        format: date-time
        '400':
          description: >-
            The request body is not JSON, or does not match the SCIM schema for
            this operation.
          content:
            application/scim+json:
              schema:
                type: object
                properties:
                  schemas:
                    type: array
                    items:
                      type: string
                    description: The SCIM schema URNs this resource conforms to.
                  status:
                    type: string
                    description: The HTTP status, as a string.
                  detail:
                    type: string
        '401':
          description: >-
            The Authorization header is missing, is not a bearer token, or names
            a token this deployment does not know.
          content:
            application/scim+json:
              schema:
                type: object
                properties:
                  schemas:
                    type: array
                    items:
                      type: string
                    description: The SCIM schema URNs this resource conforms to.
                  status:
                    type: string
                    description: The HTTP status, as a string.
                  detail:
                    type: string
        '403':
          description: >-
            The token is valid but the organization's plan no longer includes
            SCIM provisioning. Entitlement is checked on every call, so a
            directory connection stops the moment the Enterprise plan lapses.
          content:
            application/scim+json:
              schema:
                type: object
                properties:
                  schemas:
                    type: array
                    items:
                      type: string
                    description: The SCIM schema URNs this resource conforms to.
                  status:
                    type: string
                    description: The HTTP status, as a string.
                  detail:
                    type: string
        '409':
          description: >-
            A provisioned group with this displayName already exists in the
            organization.
          content:
            application/scim+json:
              schema:
                type: object
                properties:
                  schemas:
                    type: array
                    items:
                      type: string
                    description: The SCIM schema URNs this resource conforms to.
                  status:
                    type: string
                    description: The HTTP status, as a string.
                  detail:
                    type: string
      security:
        - scim_bearer: []
components:
  securitySchemes:
    project_api_key:
      type: apiKey
      in: header
      name: X-Auth-Token
      description: >-
        Project API key for sending traces and accessing project-scoped
        resources. Format: sk-lw-... (no underscore). Obtain one by creating a
        project via the Admin API or the LangWatch UI.
    scim_bearer:
      type: http
      scheme: bearer
      description: >-
        SCIM token for one organization's directory connection, created with
        POST /api/scim-tokens or in Settings > SCIM. It authenticates
        provisioning calls only, and stops working if the organization's
        Enterprise plan lapses.

````