SAP connectivity and authorizations
This page is for SAP BASIS and network administrators. It describes the HTTP endpoints the orchestration engine in Neptune DXP - Open Edition uses on a connected Neptune DXP - SAP Edition system during metadata ingestion and during request execution, and the authorizations each requires. Configuring a data source itself does not require this detail; use this page when opening network paths, assigning API Factory policies, or diagnosing connectivity.
Successful calls require valid HTTP authentication and the applicable SAP-side authorizations. Authentication for ingestion and for runtime is assigned separately. API Factory dynamic libraries are non-executable by default until a policy, or Unrestricted API Engine, is enabled.
All paths are relative to the base URL of the configured remote SAP system. The
sap-client parameter comes from the remote system configuration in
Neptune DXP - Open Edition.
HTTP surfaces
The orchestration engine uses five HTTP surfaces against the remote SAP system. Connection settings (URL, client) come from the remote system. Credentials depend on the phase: ingestion uses the proxy authentication on the remote system. The runtime uses the proxy authentication on the SAP data source.
| Surface | Base path | Purpose |
|---|---|---|
API Factory (dynamic) |
|
Business Object Repository access, function-module discovery and execution, DDIC metadata, search helps, and conversion exits. Non-executable by default; requires a policy or Unrestricted API Engine. |
Context Hub |
|
Application component hierarchy, business-object metadata, and OData capability check. |
SAP Edition API discovery |
|
Retrieval of customer REST APIs created in the Neptune DXP - SAP Edition API Designer, and each API’s OpenAPI specification through its swagger URL. |
SAP Gateway (OData) |
|
OData |
SAP Integration Hub |
|
SAP Integration Hub system information, API list, swagger, and Hub API runtime. No API policy concept. |
Some Neptune paths contain a double slash, for example after dynamic or
after /neptune/api. This is the published routing for the API Factory and SAP
Context Hub. Do not remove the double slash when diagnosing connectivity.
|
If the first business-object or function-module ingestion request fails, verify
remote-system authentication, the API Factory policy, and the dynamic ICF
node before investigating OData or Context Hub.
Authentication and access control
Authorization is applied in successive layers. A request may be rejected at any layer independently of the others.
| Access layer | Configuration location | Effect |
|---|---|---|
HTTP authentication (call identity) |
Remote system for ingestion; SAP data source for runtime |
Supplies credentials to the remote SAP system, for example basic authentication or principal propagation. |
API Factory policy |
API Factory Cockpit on Neptune DXP - SAP Edition |
Determines whether dynamic API Factory endpoints are executable for the authenticated user or entity set. |
API Designer policy (optional) |
Customer API definition in the API Designer |
Applies optional restrictions to selected Neptune DXP - SAP Edition REST APIs. Customer APIs are not subject to the deny-by-default model of API Factory dynamic artifacts. |
SAP Integration Hub |
Not applicable |
SAP Integration Hub APIs do not use an API Factory policy model. Access depends solely on ABAP authorization checks in the provider. |
ABAP |
Target SAP artifact (BAPI, function module, OData service, or equivalent) |
Enforces business and development authorizations that Neptune DXP cannot override. Failuresare returned as SAP application or security errors after the HTTP request has been accepted. |
Ingestion authentication (remote system)
Ingestion uses the proxy authentication assigned on the remote system in Neptune DXP - Open
Edition. The authenticated identity must be authorized to complete the required ingestion
requests: API Factory dynamic artifacts, and Context Hub, discovery, OData $metadata, or
Hub list requests when those sources are in scope.
Ingestion retrieves technical metadata for SAP development artifacts (repository trees, function-module definitions, OpenAPI specifications, and DDIC attributes). Use either:
-
Principal propagation, with ingestion initiated by a user that holds sufficient developer authorizations on the SAP system, or
-
A static technical user dedicated to development and repository metadata access.
The ingestion identity must also hold the API Factory policy assignments for the
dynamic artifacts used during ingestion. Policy assignment alone is insufficient
if ABAP AUTHORITY-CHECK statements in the called artifacts deny development
or repository access.
Runtime authentication (SAP data source)
Request execution uses the proxy authentication assigned on the SAP data source, on its Authentication tab. This assignment is independent of the remote-system authentication used for ingestion, and runtime does not fall back to remote-system credentials.
Runtime authentication is assigned for the business or technical users that execute BAPIs, function modules, OData operations, and customer APIs. These identities typically require business authorization on the target artifacts rather than developer authorization. When the execution plan invokes BAPIs or function modules through the API Factory, the runtime identity must also hold a policy that permits execute on the dynamic artifacts.
API Factory policy (dynamic artifacts)
By default, API Factory dynamic APIs are non-executable. Until access is enabled, Neptune DXP - Open Edition cannot retrieve OpenAPI specifications for those libraries, search function modules through the Repository Infosystem, or execute BAPIs through the runtime library.
Enable access by either:
-
Assigning a policy to the SAP user associated with the relevant proxy authentication, or
-
Setting Unrestricted API Engine (Visible to all) to YES on the corresponding API Factory class.
When an API uses entity references, policies can be assigned to specific entity sets.
The deny-by-default policy model applies to API Factory dynamic artifacts. Customer APIs created in API Designer may define policies, but they are not non-executable solely because of the dynamic-library default. SAP Integration Hub APIs do not implement an API Factory policy model.
Configuration checklist
Ingestion (remote-system authentication):
-
Assign proxy authentication on the remote system with credentials accepted by Neptune DXP - SAP Edition.
-
Ensure the SAP user holds the developer or repository authorizations required for metadata ingestion (principal propagation with a developer user, or a static development user).
-
Assign a policy, or enable Unrestricted API Engine, for the dynamic artifacts used during ingestion, including repository and function-module libraries, data elements, and search helps.
-
For standalone function-module search, grant the entity sets that permit Repository Infosystem searches for function modules (
ff) and function groups (f). Missing grants frequently result inNO_ENTITY_SETS_EVAL_POSITIVE.
Runtime (SAP data source authentication):
-
Assign role-based proxy authentication on the SAP data source Authentication tab. Runtime does not reuse the remote-system ingestion credentials.
-
Ensure the SAP user holds business authorization for the operations the execution plan selects.
-
Assign a policy, or Unrestricted API Engine, that permits execute on the same dynamic artifacts used at runtime, not only OpenAPI or metadata access. Ingestion can succeed while every BAPI or function-module call fails if execute remains blocked.
-
For customer APIs from API Designer, assign any policies defined on those APIs to the runtime user.
-
ABAP
AUTHORITY-CHECKfailures can still occur if the runtime user lacks authorization within the target artifact. These checks are enforced by SAP and are outside Neptune DXP configuration.
For where the two identities sit in the product, see Data security and governance.
Endpoint reference
Ingestion builds the catalog (business objects, function modules, OData services, Neptune DXP - SAP Edition REST APIs, SAP Integration Hub APIs, and DDIC enrichment) and authenticates with the remote-system proxy authentication. Runtime executes user or agent requests and authenticates with the SAP data source proxy authentication. The same dynamic artifacts are often used in both phases, so assign policy for both identities when they differ.
API Factory: business objects and function modules
Path prefix: /neptune/api/dynamic//neptune/cl_dr_lib_src_func_x/…
| Method | Path | Phase | Purpose |
|---|---|---|---|
POST |
|
Ingestion |
Business Object Repository tree |
POST |
|
Ingestion |
Function-module parameter and documentation metadata |
GET |
|
Ingestion |
OpenAPI specification for the function module |
POST |
|
Runtime |
Execute the function module or BAPI |
POST |
|
Ingestion |
Data-element documentation (DOCU_GET) |
POST |
|
Ingestion |
Structure field information |
Transparent-table helpers, for example RFC_READ_TABLE, also use …/{functionModule}/execute.
API Factory: function-module search (Repository Infosystem)
Used when ingesting standalone function modules not attached exclusively through a business object.
| Method | Path | Phase | Purpose |
|---|---|---|---|
POST |
|
Ingestion |
Search function modules |
POST |
|
Ingestion |
Search function groups |
Filters use ABAP selection ranges (function group, module name, package, application
component). These searches require the ff and f entity-set grants.
API Factory: data elements (DDIC)
Path prefix: /neptune/api/dynamic//neptune/cl_dr_lib_ddic_dtel_x/{dataElement}/…
| Method | Suffix | Phase | Purpose |
|---|---|---|---|
GET |
|
Ingestion; runtime fallback |
Type, length, CONVEXIT, and related attributes |
GET |
|
Ingestion |
Domain fixed values |
GET |
|
Runtime |
External or display value to SAP internal format |
GET |
|
Runtime |
SAP internal format to external or display value |
API Factory: search helps
Path prefix: /neptune/api/dynamic//neptune/cl_dr_lib_ddic_shlp_x/{type}/{name}/…
| Method | Suffix | Phase | Purpose |
|---|---|---|---|
GET |
|
Ingestion |
Search-help definition |
GET |
|
Ingestion |
Expand collective search helps |
POST |
execute |
Runtime |
Value-help lookup, including enhanced selection options where available |
Context Hub
Base path: /neptune/api//neptune/ai/contexthub
Context Hub requires an available Neptune HTTP endpoint and remote-system authentication. It
is not governed by the API Factory policy that applies to /neptune/api/dynamic/….
| Method | Path | Phase | Purpose |
|---|---|---|---|
POST |
|
Ingestion |
Application components and linked OData services |
GET |
|
Ingestion |
Whether the SAP Edition system supports OData ingestion |
POST |
|
Ingestion |
Metadata for one business object ( |
SAP Edition REST APIs (API Designer)
| Method | Path | Phase | Purpose |
|---|---|---|---|
GET |
|
Ingestion |
List customer APIs |
GET |
swagger URL from discovery |
Ingestion |
OpenAPI specification for that API |
(any) |
|
Runtime |
Execute operations on that API |
Neptune platform APIs (Context Hub, server helpers, and dynamic DDIC libraries) are excluded from the selectable business API catalog. Customer APIs may define policies in API Designer; configure those for the runtime user when present.
OData
| Method | Path | Phase | Purpose |
|---|---|---|---|
GET |
|
Ingestion |
Entity and operation model |
GET / POST / PATCH / DELETE |
|
Runtime |
Read and change data |
Authorizations for OData are the SAP Gateway and OData service authorizations for the authenticated user.
SAP Integration Hub
The SAP Integration Hub requires the SAP Integration Hub (SAP Connector) transport
and an active ICF path under /sap/bc/http/neptune/dxp. If the SAP Integration
Hub is not installed, ingestion skips it and continues with the other sources.
SAP Integration Hub APIs do not use an API Factory policy.
| Method | Path | Phase | Purpose |
|---|---|---|---|
GET |
|
Ingestion |
System information and presence check |
POST |
|
Ingestion |
List customer Hub APIs |
GET |
|
Ingestion |
OpenAPI specification for a Hub API |
(any) |
|
Runtime |
Execute Hub operations |
Troubleshooting
| Symptom | Probable cause | Corrective action |
|---|---|---|
HTTP 401 during ingestion |
Remote-system proxy authentication missing or invalid |
Correct the proxy authentication assignment on the remote system. |
HTTP 401 during request execution |
SAP data source authentication missing or invalid |
Assign role-based authentication on the SAP data source Authentication tab. |
|
API Factory policy missing, or entity sets not granted for function-module search |
Assign a policy to the SAP user for the relevant proxy authentication, grant the required entity sets, or enable Visible to all / Unrestricted API Engine as appropriate. |
HTTP 403 on |
|
Activate |
|
Calling source system not permitted |
Add the Neptune DXP - Open Edition source system in the API Factory configuration. |
Ingestion succeeds; every BAPI or function-module call fails with policy errors |
Execute not authorized for the runtime identity (policy permits OpenAPI or metadata only, or was assigned only to the ingestion identity) |
Extend the policy for the SAP data source runtime identity on the same dynamic libraries. |
Ingestion or execution fails with SAP authorization / |
ABAP authorization missing on the artifact |
Grant the required SAP authorizations to the ingestion or runtime identity. Neptune DXP cannot bypass these checks. |
HTTP 403 or empty catalog for OData only |
Gateway or OData service authorization |
Verify OData service activation and authorizations for the authenticated user. |
Integration Hub does not appear |
Connector transport missing or ICF inactive |
Install the Integration Hub transport and activate |
Discovery lists an API Designer API; execution fails |
Policy or ABAP authorization on that customer API |
Review the policies defined on the API in the API Designer and the runtime identity’s SAP authorizations. |
Neptune DXP - Open Edition maps common API Factory failures to diagnostic messages in the user interface and logs, so initial analysis does not require inspecting a raw exception payload.