Resource
The resource URN of the SAP Identity Authentication Service (IAS) dependency application that the requested token is issued for.
Data Type
string
Default Value
""
Remarks
When this property is set, the provider sends its value as the resource parameter of the token request to the IAS token endpoint. IAS uses this value to identify the dependency application that the requested token is issued for.
This property is required when AuthScheme is set to SAPIASOIDCClient. In the SAP IAS OpenID Connect (OIDC) client-credentials flow, IAS uses this value to issue an access token that is scoped to the SAP SuccessFactors sf_technical_access API.
This property is optional when AuthScheme is set to SAPIAS or SAPIASPassword. Set it if your IAS tenant uses a two-application setup, in which a Security Assertion Markup Language (SAML) application is registered as a dependency of the OIDC application that the provider authenticates against. In this setup, the property identifies the SAML dependency application that the exchanged SAML assertion is issued for, and authentication fails without it. If you leave this property empty, the token exchange is unchanged, so single-application setups continue to work.
Provide the resource URN in the following format:
urn:sap:identity:application:provider:name:<DependencyName>
Replace <DependencyName> with the name of the dependency configured on your IAS OIDC application. You can find this name in the SAP IAS administration console: open the OIDC application and navigate to Application APIs > Dependencies. For SAPIASOIDCClient, use the name of the SAP SuccessFactors API dependency; for SAPIAS and SAPIASPassword, use the name of the dependency that references the SAML application.