Yes, Jaapi integrates with Rippling. Rippling pushes employee data to your swag store using SCIM 2.0, the same standard identity providers like Okta and Entra ID use. New hires get a store account on day one, departing employees are deactivated automatically, and their unspent credit returns to the company. Setup is self-serve and takes a Rippling admin about half an hour.
How does the Rippling integration work?
Rippling is an identity provider: it provisions employee data outbound to downstream apps like Jaapi. You don’t pull data from Rippling. Rippling pushes it to your store the moment something changes in HR. The connection runs over SCIM 2.0, so it behaves exactly like the provisioning you may already run from Okta or Entra ID.
The data flows one direction, from Rippling into your Jaapi store, and stays in sync as employees join, change roles, or leave.
What syncs from Rippling to Jaapi?
A SCIM connection keeps your store’s user list as a live mirror of the people Rippling says work at your company. Concretely, it handles the full user lifecycle:
- Onboarding. A new hire who meets the app’s access rules in Rippling gets a store account created automatically, on the day you choose.
- Profile updates. Name and email changes in Rippling flow through to the store.
- Offboarding. When someone leaves, their account is deactivated and any unspent credit is reclaimed to an admin wallet, so budget never walks out the door.
- Rehires. If a former employee returns, their original account is reactivated with history intact.
- Identity mapping. Rippling’s employee ID is stored as the user’s
externalId, keeping records matched across both systems.
How do I set up Rippling provisioning?
Setup lives in the Rippling admin dashboard plus your Jaapi store settings. No code, no Jaapi engineering involvement. Rippling’s custom app is an install wizard, and the SCIM form is only its first page: provisioning starts once the later pages are done too.
- In your Jaapi store, go to Settings → API Tokens and generate a SCIM token. It’s shown once.
- In Rippling, open IT → Third-Party Access, add a custom integration, and tick User Management via SCIM.
- On the SCIM form, enter your store’s SCIM base URL, choose Bearer Token, tick Supports pagination, select Use email address as username, and leave Supports groups unticked. Jaapi has no groups.
- Install the app. This is where Rippling asks for the token from step 1, and where you switch on Offboarding.
- Set the App Access Rules (who gets an account) and the Provision Time (when).
- On Account Matching, confirm employees who already have store accounts and tick Create New for those who don’t.
- In Attribute mapping, set every attribute’s cadence to On user creation and updates.
Within a few minutes the people you selected appear on your store’s People page. The step-by-step guide with every Rippling screen and field name is at /docs/rippling on your store, for example store.jaapi.store/docs/rippling.
Why is Rippling connected but nobody is provisioned?
Rippling has no test-connection button. It reads your store’s user list every night whether or not it is provisioning, so a healthy-looking connection proves nothing on its own. Almost always one of the wizard’s later pages was skipped: the access rules select nobody, the people you expected were already matched to existing accounts, someone was set to Ignore, or the provision time is a start date in the future. Open the app under Third-Party Access, resume the install if it shows as unfinished, and check those pages in that order.
What Rippling SCIM does not carry
SCIM is an identity protocol, so it carries name, email, active status, and external ID, but not HR context like department, hire date, location, or budget tier. It also can’t tell the store how much credit an employee should receive.
If you only need “create on hire, deactivate on termination,” SCIM is the cleanest option. If you want HR data to also drive credit (monthly budgets, new-hire welcome kits, anniversary gifts) pair it with an HRIS CSV sync, which can carry any field you like. Many customers run both: SCIM for identity, CSV sync for budget logic. They don’t conflict.
Is Rippling provisioning secure?
Yes. Every request is authenticated with a Bearer token scoped to a single store, all traffic is HTTPS, and new accounts are validated against your store’s allowed email domain. Every provisioning action is written to an audit trail, and admin accounts are protected from deletion via SCIM. Jaapi is ISO 27001:2022 certified with EU-hosted data.