Provisioning and lifecycle

User provisioning and lifecycle, automated via API and SDK

Automate the entire user lifecycle — joiner, mover, and leaver — through a REST API and native TypeScript and .NET SDKs, with no manual data entry and no need to rewrite your infrastructure.

In short

With LoginMaster you automate user provisioning and lifecycle through a complete REST API and native TypeScript and .NET SDKs: you invite and link accounts to projects directly from your HR system or identity provider, and at offboarding you revoke project access (API keys and sessions are revoked from their respective controls). Lifecycle webhooks and native SCIM 2.0 support are on the roadmap; today synchronization happens via the REST API and SDKs.

How you automate provisioning and lifecycle

Provisioning, lifecycle management, and deprovisioning are available today via the REST API and SDKs. Lifecycle webhooks and native SCIM 2.0 support are on the roadmap.

Provisioning via REST API and SDK

Available

Create, update, and link users to projects through the REST API and the TypeScript and .NET SDKs, integrating LoginMaster with your HR system or identity provider and eliminating manual account entry.

Lifecycle events (webhooks on the roadmap)

Available

Real-time webhooks on lifecycle events are on the roadmap. Today you keep your systems aligned by querying the REST API or through the SDKs when a user changes role or project.

Deprovisioning and offboarding

Available

When you revoke a user you remove project access in one step; API keys and sessions are revoked from their respective controls, closing the risk window of orphaned accounts.

SCIM 2.0 standard

On the roadmap

Native SCIM 2.0 support — automatic synchronization of users and groups with providers such as Okta and Microsoft Entra ID — is on the platform roadmap; today the same outcome is achievable through the REST API, SDKs, and webhooks.

One automation for joiner, mover, and leaver

Cover every stage of the identity lifecycle with the same REST API and SDKs.

Joiner — Automated onboarding

When a person joins, you create the account and link it to the right projects via REST API or SDK, integrating LoginMaster with your HR system or identity provider. No manual entry, no configuration errors.

Mover — Role change

When a user changes role or project, keep your systems aligned by querying the REST API on every context change (lifecycle webhooks are on the roadmap).

Leaver — Immediate offboarding

When a person leaves, you revoke project access and remove API keys and sessions from their respective controls. Immediate deprovisioning eliminates orphaned accounts, a key requirement for NIS2 and ISO 27001.

The integration surface for developers

Everything you need to orchestrate provisioning from your services, securely and via open standards.

REST API

A complete REST API to create, update, link, and disable users and projects programmatically.

TypeScript and .NET SDKs

Native SDKs to integrate provisioning and authentication into JavaScript/TypeScript and .NET applications. Any other language integrates via the REST API.

Webhooks (roadmap)

Real-time notifications of lifecycle and authentication events, for downstream automation with no polling.

Server-to-server API keys

Dedicated API keys for secure automation of integrations between your services and LoginMaster.

Tenant · Users
LoginMaster Tenant console: provisioned users with role and projects, and the SSO user import action.
Provisioned users and SSO import in the console · real screenshot with anonymized data.

How it works, in three steps

From integration to offboarding, without rewriting your existing infrastructure.

1

Integrate the SDK or REST API

Connect LoginMaster to your services with the TypeScript and .NET SDKs or the REST API, and configure API keys for server-to-server communication.

2

Automate joiner and mover

Create and update accounts from your HR system or identity provider and sync role or project changes through the REST API and SDKs.

3

Revoke at leaver

At offboarding, revoke project access and remove API keys and sessions from their respective controls, closing the risk window of orphaned accounts.

See the full developer integration guide

Provisioning via REST API and SDK, in practice

Automate the whole lifecycle — joiner, mover, leaver — with REST calls authenticated via API key or with the native TypeScript and .NET SDKs. Illustrative examples.

REST API — create a user (joiner)

curl -X POST https://api.loginmaster.it/v1/tenants/{tenantId}/users \
  -H "Authorization: Bearer $LOGINMASTER_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "mario.rossi@azienda.it",
    "projectId": "crm-app",
    "role": "member",
    "mfaPolicy": "required"
  }'

TypeScript SDK — mover and leaver

import { LoginMaster } from "@loginmaster/sdk";

const lm = new LoginMaster({ apiKey: process.env.LOGINMASTER_API_KEY });

// mover: cambio ruolo
await lm.users.update(userId, { role: "admin" });

// leaver: disattivazione (deprovisioning)
await lm.users.disable(userId);

Webhooks (roadmap) — sync lifecycle events

// [Roadmap] LoginMaster notificherà la tua app in tempo reale
{
  "event": "user.disabled",
  "tenantId": "acme",
  "projectId": "crm-app",
  "userId": "usr_9f2c...",
  "occurredAt": "2026-01-15T09:24:00Z"
}

SCIM 2.0 support for automatic provisioning from enterprise IdPs is on the roadmap. Endpoints and method names are illustrative: see the documentation for the up-to-date reference.

Provisioning FAQ

LoginMaster exposes a complete REST API and native SDKs for TypeScript and .NET. From your services, your HR system, or your identity provider you invite, update, suspend, and link users to projects programmatically via the REST API (the SDKs cover invitation and self-service). Real-time webhooks on events are on the roadmap. At offboarding, you revoke project access and remove API keys and sessions from their respective controls.

Native SCIM 2.0 support is on the platform roadmap. Today the same outcome — automatic synchronization of users and groups with providers such as Okta and Microsoft Entra ID — is achievable through the REST API, the TypeScript/.NET SDKs, and webhooks.

LoginMaster offers native SDKs for TypeScript/JavaScript and for .NET. Any other language or platform can integrate directly with the REST API and with the OAuth 2.0 and OpenID Connect standards.

When you revoke a user you remove their project access; API keys and sessions are revoked from their respective controls. If the user signs in via federated SSO (Microsoft Entra ID, Google Workspace), disabling the upstream corporate account automatically ends access to the connected services. Immediate deprovisioning eliminates orphaned accounts, a key requirement for NIS2 and ISO 27001.

No. Provisioning creates and manages accounts, but as an architectural constraint neither administrators nor LoginMaster can read or set users' passwords: credentials and the second factor remain under the user's exclusive control. Passwords are protected with Argon2 hashing and split-salt.

No. You integrate LoginMaster progressively through the TypeScript/.NET SDKs or the REST API, without rewriting your existing infrastructure. Server-to-server automation uses dedicated API keys and your services keep running during the migration.

Automate your users' lifecycle today

Request a demo and discover how to integrate provisioning and deprovisioning into your infrastructure with a REST API and SDKs.