SAP connectivity and authorizations

This page is for SAP BASIS and network administrators. It describes the HTTP endpoints the orchestration engine in Neptune DXP - Open Edition uses on a connected Neptune DXP - SAP Edition system during metadata ingestion and during request execution, and the authorizations each requires. Configuring a data source itself does not require this detail; use this page when opening network paths, assigning API Factory policies, or diagnosing connectivity.

Successful calls require valid HTTP authentication and the applicable SAP-side authorizations. Authentication for ingestion and for runtime is assigned separately. API Factory dynamic libraries are non-executable by default until a policy, or Unrestricted API Engine, is enabled.

All paths are relative to the base URL of the configured remote SAP system. The sap-client parameter comes from the remote system configuration in Neptune DXP - Open Edition.

HTTP surfaces

The orchestration engine uses five HTTP surfaces against the remote SAP system. Connection settings (URL, client) come from the remote system. Credentials depend on the phase: ingestion uses the proxy authentication on the remote system. The runtime uses the proxy authentication on the SAP data source.

Surface Base path Purpose

API Factory (dynamic)

/neptune/api/dynamic/…​

Business Object Repository access, function-module discovery and execution, DDIC metadata, search helps, and conversion exits. Non-executable by default; requires a policy or Unrestricted API Engine.

Context Hub

/neptune/api//neptune/ai/contexthub/…​

Application component hierarchy, business-object metadata, and OData capability check.

SAP Edition API discovery

/neptune/api/server/discovery

Retrieval of customer REST APIs created in the Neptune DXP - SAP Edition API Designer, and each API’s OpenAPI specification through its swagger URL.

SAP Gateway (OData)

/sap/opu/odata…​ or /sap/opu/odata4…​

OData $metadata retrieval and runtime operations.

SAP Integration Hub

/sap/bc/http/neptune/dxp/…​

SAP Integration Hub system information, API list, swagger, and Hub API runtime. No API policy concept.

Some Neptune paths contain a double slash, for example after dynamic or after /neptune/api. This is the published routing for the API Factory and SAP Context Hub. Do not remove the double slash when diagnosing connectivity.

If the first business-object or function-module ingestion request fails, verify remote-system authentication, the API Factory policy, and the dynamic ICF node before investigating OData or Context Hub.

Authentication and access control

Authorization is applied in successive layers. A request may be rejected at any layer independently of the others.

Access layer Configuration location Effect

HTTP authentication (call identity)

Remote system for ingestion; SAP data source for runtime

Supplies credentials to the remote SAP system, for example basic authentication or principal propagation.

API Factory policy

API Factory Cockpit on Neptune DXP - SAP Edition

Determines whether dynamic API Factory endpoints are executable for the authenticated user or entity set.

API Designer policy (optional)

Customer API definition in the API Designer

Applies optional restrictions to selected Neptune DXP - SAP Edition REST APIs. Customer APIs are not subject to the deny-by-default model of API Factory dynamic artifacts.

SAP Integration Hub

Not applicable

SAP Integration Hub APIs do not use an API Factory policy model. Access depends solely on ABAP authorization checks in the provider.

ABAP AUTHORITY-CHECK

Target SAP artifact (BAPI, function module, OData service, or equivalent)

Enforces business and development authorizations that Neptune DXP cannot override. Failuresare returned as SAP application or security errors after the HTTP request has been accepted.

Ingestion authentication (remote system)

Ingestion uses the proxy authentication assigned on the remote system in Neptune DXP - Open Edition. The authenticated identity must be authorized to complete the required ingestion requests: API Factory dynamic artifacts, and Context Hub, discovery, OData $metadata, or Hub list requests when those sources are in scope.

Ingestion retrieves technical metadata for SAP development artifacts (repository trees, function-module definitions, OpenAPI specifications, and DDIC attributes). Use either:

  • Principal propagation, with ingestion initiated by a user that holds sufficient developer authorizations on the SAP system, or

  • A static technical user dedicated to development and repository metadata access.

The ingestion identity must also hold the API Factory policy assignments for the dynamic artifacts used during ingestion. Policy assignment alone is insufficient if ABAP AUTHORITY-CHECK statements in the called artifacts deny development or repository access.

Runtime authentication (SAP data source)

Request execution uses the proxy authentication assigned on the SAP data source, on its Authentication tab. This assignment is independent of the remote-system authentication used for ingestion, and runtime does not fall back to remote-system credentials.

Runtime authentication is assigned for the business or technical users that execute BAPIs, function modules, OData operations, and customer APIs. These identities typically require business authorization on the target artifacts rather than developer authorization. When the execution plan invokes BAPIs or function modules through the API Factory, the runtime identity must also hold a policy that permits execute on the dynamic artifacts.

API Factory policy (dynamic artifacts)

By default, API Factory dynamic APIs are non-executable. Until access is enabled, Neptune DXP - Open Edition cannot retrieve OpenAPI specifications for those libraries, search function modules through the Repository Infosystem, or execute BAPIs through the runtime library.

Enable access by either:

  • Assigning a policy to the SAP user associated with the relevant proxy authentication, or

  • Setting Unrestricted API Engine (Visible to all) to YES on the corresponding API Factory class.

When an API uses entity references, policies can be assigned to specific entity sets.

The deny-by-default policy model applies to API Factory dynamic artifacts. Customer APIs created in API Designer may define policies, but they are not non-executable solely because of the dynamic-library default. SAP Integration Hub APIs do not implement an API Factory policy model.

Configuration checklist

Ingestion (remote-system authentication):

  1. Assign proxy authentication on the remote system with credentials accepted by Neptune DXP - SAP Edition.

  2. Ensure the SAP user holds the developer or repository authorizations required for metadata ingestion (principal propagation with a developer user, or a static development user).

  3. Assign a policy, or enable Unrestricted API Engine, for the dynamic artifacts used during ingestion, including repository and function-module libraries, data elements, and search helps.

  4. For standalone function-module search, grant the entity sets that permit Repository Infosystem searches for function modules (ff) and function groups (f). Missing grants frequently result in NO_ENTITY_SETS_EVAL_POSITIVE.

Runtime (SAP data source authentication):

  1. Assign role-based proxy authentication on the SAP data source Authentication tab. Runtime does not reuse the remote-system ingestion credentials.

  2. Ensure the SAP user holds business authorization for the operations the execution plan selects.

  3. Assign a policy, or Unrestricted API Engine, that permits execute on the same dynamic artifacts used at runtime, not only OpenAPI or metadata access. Ingestion can succeed while every BAPI or function-module call fails if execute remains blocked.

  4. For customer APIs from API Designer, assign any policies defined on those APIs to the runtime user.

  5. ABAP AUTHORITY-CHECK failures can still occur if the runtime user lacks authorization within the target artifact. These checks are enforced by SAP and are outside Neptune DXP configuration.

For where the two identities sit in the product, see Data security and governance.

Endpoint reference

Ingestion builds the catalog (business objects, function modules, OData services, Neptune DXP - SAP Edition REST APIs, SAP Integration Hub APIs, and DDIC enrichment) and authenticates with the remote-system proxy authentication. Runtime executes user or agent requests and authenticates with the SAP data source proxy authentication. The same dynamic artifacts are often used in both phases, so assign policy for both identities when they differ.

API Factory: business objects and function modules

Path prefix: /neptune/api/dynamic//neptune/cl_dr_lib_src_func_x/…​

Method Path Phase Purpose

POST

…​/rpy_bor_tree_init/execute

Ingestion

Business Object Repository tree

POST

…​/function_import_doku/execute

Ingestion

Function-module parameter and documentation metadata

GET

…​/{functionModule}/swagger.json

Ingestion

OpenAPI specification for the function module

POST

…​/{functionModule}/execute

Runtime

Execute the function module or BAPI

POST

…​/docu_get/execute

Ingestion

Data-element documentation (DOCU_GET)

POST

…​/ddif_fieldinfo_get/execute

Ingestion

Structure field information

Transparent-table helpers, for example RFC_READ_TABLE, also use …​/{functionModule}/execute.

API Factory: function-module search (Repository Infosystem)

Used when ingesting standalone function modules not attached exclusively through a business object.

Method Path Phase Purpose

POST

/neptune/api/dynamic//neptune/cl_dr_lib_src/ff/search

Ingestion

Search function modules

POST

/neptune/api/dynamic//neptune/cl_dr_lib_src/f/search

Ingestion

Search function groups

Filters use ABAP selection ranges (function group, module name, package, application component). These searches require the ff and f entity-set grants.

API Factory: data elements (DDIC)

Path prefix: /neptune/api/dynamic//neptune/cl_dr_lib_ddic_dtel_x/{dataElement}/…​

Method Suffix Phase Purpose

GET

/metadata

Ingestion; runtime fallback

Type, length, CONVEXIT, and related attributes

GET

/fixedValues

Ingestion

Domain fixed values

GET

/conversionExitInput

Runtime

External or display value to SAP internal format

GET

/conversionExitOutput

Runtime

SAP internal format to external or display value

API Factory: search helps

Path prefix: /neptune/api/dynamic//neptune/cl_dr_lib_ddic_shlp_x/{type}/{name}/…​

Method Suffix Phase Purpose

GET

/metadata

Ingestion

Search-help definition

GET

/expand

Ingestion

Expand collective search helps

POST

execute

Runtime

Value-help lookup, including enhanced selection options where available

Context Hub

Base path: /neptune/api//neptune/ai/contexthub

Context Hub requires an available Neptune HTTP endpoint and remote-system authentication. It is not governed by the API Factory policy that applies to /neptune/api/dynamic/…​.

Method Path Phase Purpose

POST

…​/applicationCompGetHierarchy

Ingestion

Application components and linked OData services

GET

…​/isODataSupported

Ingestion

Whether the SAP Edition system supports OData ingestion

POST

…​/businessObjectsRead

Ingestion

Metadata for one business object (IV_OBJTYPE)

SAP Edition REST APIs (API Designer)

Method Path Phase Purpose

GET

/neptune/api/server/discovery

Ingestion

List customer APIs

GET

swagger URL from discovery

Ingestion

OpenAPI specification for that API

(any)

/neptune/api/<apiPath>/…​

Runtime

Execute operations on that API

Neptune platform APIs (Context Hub, server helpers, and dynamic DDIC libraries) are excluded from the selectable business API catalog. Customer APIs may define policies in API Designer; configure those for the runtime user when present.

OData

Method Path Phase Purpose

GET

{servicePath}/$metadata

Ingestion

Entity and operation model

GET / POST / PATCH / DELETE

{servicePath}/…​

Runtime

Read and change data

Authorizations for OData are the SAP Gateway and OData service authorizations for the authenticated user.

SAP Integration Hub

The SAP Integration Hub requires the SAP Integration Hub (SAP Connector) transport and an active ICF path under /sap/bc/http/neptune/dxp. If the SAP Integration Hub is not installed, ingestion skips it and continues with the other sources. SAP Integration Hub APIs do not use an API Factory policy.

Method Path Phase Purpose

GET

/sap/bc/http/neptune/dxp/system/runtime/systeminfo

Ingestion

System information and presence check

POST

/sap/bc/http/neptune/dxp/core/api/list

Ingestion

List customer Hub APIs

GET

/sap/bc/http/neptune/dxp/api/{apiPath}/swagger.json

Ingestion

OpenAPI specification for a Hub API

(any)

/sap/bc/http/neptune/dxp/api/…​

Runtime

Execute Hub operations

Troubleshooting

Symptom Probable cause Corrective action

HTTP 401 during ingestion

Remote-system proxy authentication missing or invalid

Correct the proxy authentication assignment on the remote system.

HTTP 401 during request execution

SAP data source authentication missing or invalid

Assign role-based authentication on the SAP data source Authentication tab.

OAS_NOT_ALLOWED, EXECUTE_NOT_ALLOWED, NO_ENTITY_SETS_EVAL_POSITIVE, or an unrestricted API engine / policy message

API Factory policy missing, or entity sets not granted for function-module search

Assign a policy to the SAP user for the relevant proxy authentication, grant the required entity sets, or enable Visible to all / Unrestricted API Engine as appropriate.

HTTP 403 on /neptune/api/dynamic/…​, or ICF_SUBNODE_NOT_ALLOWED

dynamic ICF node inactive or not permitted

Activate dynamic in transaction SICF.

SOURCE_SYSTEM_NOT_ALLOWED

Calling source system not permitted

Add the Neptune DXP - Open Edition source system in the API Factory configuration.

Ingestion succeeds; every BAPI or function-module call fails with policy errors

Execute not authorized for the runtime identity (policy permits OpenAPI or metadata only, or was assigned only to the ingestion identity)

Extend the policy for the SAP data source runtime identity on the same dynamic libraries.

Ingestion or execution fails with SAP authorization / AUTHORITY-CHECK messages after HTTP success

ABAP authorization missing on the artifact

Grant the required SAP authorizations to the ingestion or runtime identity. Neptune DXP cannot bypass these checks.

HTTP 403 or empty catalog for OData only

Gateway or OData service authorization

Verify OData service activation and authorizations for the authenticated user.

Integration Hub does not appear

Connector transport missing or ICF inactive

Install the Integration Hub transport and activate /sap/bc/http/neptune/dxp.

Discovery lists an API Designer API; execution fails

Policy or ABAP authorization on that customer API

Review the policies defined on the API in the API Designer and the runtime identity’s SAP authorizations.

Neptune DXP - Open Edition maps common API Factory failures to diagnostic messages in the user interface and logs, so initial analysis does not require inspecting a raw exception payload.