vulns.co
/
GKData.io MCP

Provisioning and invites

Provisioning is who is allowed to create a user, change a role, or accept an invite. Test SCIM, directory sync, and invite acceptance with two orgs you belong to. An invite token in a URL is a lead, not a takeover.

Skill: Provisioning and invites

Ask: Can a token I hold create a user or change a role in an org I belong to, when that route should refuse me?

Stop: Two orgs you belong to are named, and one write is either refused or stored. No user was created in a third org.

Open the skill

Checklists

None linked for this class yet.

Disclosures

No public card yet.

Playbooks

  • SCIM, directory sync, and invites - Provisioning bugs are authorization bugs on user creation. Compare two orgs you belong to. Do not create users in a tenant that is not yours.

Tools

  • Burp Suite - The industry-standard intercepting proxy for manual web testing. Community edition is free; Pro adds the active scanner and automation.

Questions

SCIM is an admin API. Do I need an admin account?

Use the role the program gave you. The question is whether a member token can call a route that should be admin, or whether an invite for org A is accepted inside org B. Both orgs have to be yours.

The invite link has a token. Which hunt is that?

Start here for who can issue it and which org it joins. If the question is reuse or a second browser, open the reset brief as well and say which behavior you showed.

This page is the linked pack hunt_brief("provision") returns on the MCP connector. Authorized testing only.