Good summary update:
"SCIM is handled via a REST-based API for provisioning, change, and de-provisioning — all of which lie outside the realm of OAuth and SAML. With the rise of web APIs and microservices<http://nordicapis.com/3-ways-to-build-microservices/>, SAML, has been deemed by some as too heavy with it’s verbose XML. SCIM rather calls for authentication and access tokens in compact JSON, passed via HTTP headers."
http://nordicapis.com/scim-building-the-identity-layer-for-the-internet/