ADO.NET Provider for SAP SuccessFactors

Build 26.0.9770

SAP IAS SAML Application Configuration

SAP IAS SAML Application Configuration

SAP SuccessFactors supports the OAuth 2.0 Security Assertion Markup Language (SAML) flow, which requires a signed SAML assertion issued by an external Identity Provider (IdP). This assertion is then exchanged for an access token when making requests to the SAP SuccessFactors API.

This guide outlines how to configure SAP Identity Authentication Service (IAS) to generate the required SAML assertion using two applications:

  • An OpenID Connect (OIDC) application that handles the OAuth authentication (Authorization Code or Password grant).
  • A SAML 2.0 application that generates the SAML assertion, registered as a Dependency of the OIDC application.

The access token issued by the OIDC application is exchanged for a SAML assertion via the Token Exchange (RFC 8693) flow, targeting the SAML application through its dependency name. The provider then exchanges the assertion for an SAP SuccessFactors access token.

Note: Existing single-application configurations (a SAML application whose protocol was temporarily switched to OpenID Connect to configure the OAuth settings) continue to work with the Password grant and do not require the Resource property. The two-application setup described here is recommended for all new configurations, and is required for a reliable Authorization Code flow: with a single SAML-protocol application, IAS redirects interactive browser sign-ins to the application's SSO endpoint instead of the OAuth redirect URI, so the provider never receives the authorization code unless the browser already has an active IAS session.

  1. Retrieve the SAP IAS Signing Certificate:
    • On the SAP IAS Admin page, navigate to: Applications & Resources > Tenant Settings > Single Sign-On > SAML 2.0 Configuration.
    • Under Signing Certificates, click the lens icon to view the active certificate.
    • Copy the entire certificate content under the Certificate Information section. This will be used later to validate the SAML assertion signature.
  2. Create an OAuth2 Client App in SAP SuccessFactors:
    • From the SAP SuccessFactors homepage, in the user menu (the button with your user icon, found in the top-right corner), click Admin Center.
    • In the Tools > Search Tools box, search for "Manage OAuth2 Client Applications" and click the result of the same name.
    • Create a new application using the Register Client Application button.
    • Set Application Name to your preferred name and set Application URL to a unique URL (this can be any URL not used by your other OAuth apps, since it is used as an identifier for the application rather than a redirect URL).
    • In the *X.509 Certificate field, paste the value you copied from "Certificate Information".
    • Click Register. You are redirected back to the app list. Your new app is now part of the list.
    • Click View on the row containing the newly generated application, then copy the value from the API Key field. Save this value for use in the OAuthClientId connection property.
  3. Create the SAML Application in SAP IAS:
    • In SAP IAS Admin Console, go to: Applications & Resources > Applications. Then, in the Applications sidebar, click Create. You may need to expand the browser window to see the sidebar and Create button.
    • Enter the below properties:
      • Display Name: Set your preferred display name for the SAML application
      • Protocol Type: SAML 2.0
      • Home URL: Leave empty
      • Parent App: Leave as None
    • Click Create.
    • Go to Trust > Single Sign-On > SAML 2.0 Configuration and configure the following:
      • Set the URL for Principal Propagation to <SAP SuccessFactors base url>/oauth/token (for example, https://apisalesdemo2.successfactors.eu/oauth/token).
      • Under Subject Name Identifier, choose a value that matches the username of the API user in both SAP IAS and SAP SuccessFactors.
      • Under Default Name ID Format, select the Unspecified (urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified) option.
      • Under Assertion Attributes, add a new attribute with the name api_key, and set the value to the API Key of the SAP SuccessFactors OAuth2 client application.
    • This application is never accessed from a browser in this flow. If the configuration requires an SSO endpoint (ACS) value to save, enter any placeholder URL, as it is never invoked.
  4. Create the OIDC Application in SAP IAS:
    • In SAP IAS Admin Console, go to: Applications & Resources > Applications. Then, in the Applications sidebar, click Create.
    • Enter the below properties:
      • Display Name: Set your preferred display name for the OIDC application
      • Protocol Type: OpenID Connect
      • Home URL: Leave empty
      • Parent App: Leave as None
    • Click Create.
    • Go to Trust > Single Sign-On > OpenID Connect Configuration and configure:
      • Redirect URIs: Add the redirect URI the provider listens on during the Authorization Code flow. The default is http://localhost:33333. This step is not needed for the Password grant.
      • Grant Types: Enable your preferred grants. The provider supports:
        • Authorization Code (with or without PKCE) or Password
        • Token Exchange (RFC 8693): Required to get the SAML assertion.
        • Refresh: Optional, but recommended if you want the provider to automatically refresh the access token.
      • Access Token Format: Leave the default Grant-Type Dependent or select Opaque. The provider explicitly requests an opaque access token, which is required for the token exchange.
    • Configure Client Authentication:
      • Go to Application APIs > Client Authentication.
      • Create a client secret by clicking on the Add button on the Secrets section.
      • Copy the Client ID and Client Secret, as these will be passed in the provider's SSOProperties:
  5. Register the SAML Application as a Dependency of the OIDC Application:
    • On the SAML application, go to Application APIs > Provided APIs and add an API entry (any name, for example, SF_API). This declares the SAML application as an API provider.
    • On the OIDC application, go to Application APIs > Dependencies and click Add. Enter a Dependency Name (for example, SAML_DEP), select the SAML application as the provider application, and select its provided API.
    • Set the Resource connection property to the dependency resource URN:
      urn:sap:identity:application:provider:name:<DependencyName>
      Replace <DependencyName> with the Dependency Name you entered on the OIDC application (for example, urn:sap:identity:application:provider:name:SAML_DEP).
After completing the configuration steps above, you are ready to set the required connection properties and establish a connection using the provider, as discussed in Establishing a Connection.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770