Windows DSN Configuration
Using the Microsoft ODBC Data Source Administrator
You can use the Microsoft ODBC Data Source Administrator to edit the DSN configuration. Note that the DSN is created during the installation process.
Complete the following steps to edit the DSN configuration:
- Select Start > Search, and enter ODBC Data Sources in the Search box.
- Choose the version of the ODBC Administrator that corresponds to the bitness of your application (32-bit or 64-bit).
- Click the System DSN tab.
- Select the system data source and click Configure.
- Edit the information on the Connection tab and click OK.
Note: For .NET Framework 4.0, the driver distributes Microsoft Visual C++ 2015-2022 Redistributable. For .NET Framework 3.5, the driver distributes Microsoft Visual C++ 2008 Redistributable.
Ensuring Registry Access
The driver stores connection information in the Windows registry. To ensure that the driver can write to the registry, perform either of the following actions:
- Run the calling application as an administrator.
- Connect via a User DSN instead of a System DSN.
Connecting to SAP Gateway
SAP Gateway provides three ways to connect to data:
- To connect to your own local data via the desktop (non-browser connection, referred to below as "basic authentication"), use the CData-supplied embedded OAuth application.
- To connect to shared data over the network (browser connection), use a custom OAuth application.
To access SAP Gateway tables, set the following connection properties:
- URL: The URL of your environment, or the full URL of the service. For example, the full URL might appear as: https://sapes5.sapdevcenter.com/sap/opu/odata/IWBEP/GWSAMPLE_BASIC/. In this example, the environment URL would just be: https://sapes5.sapdevcenter.com. Add any additional properties using the CustomURLParams property.
- Namespace: The appropriate Service Namespace. In the example above, IWBEP is the namespace. It is optional if the full URL to the service is specified.
- Service: The service from which you want to retrieve data. In the URL property example listed above, the service is GWSAMPLE_BASIC. It is not required if the full URL is specified.
- CustomURLParams: Any required additional properties that need to be included with the HTTP request; for example, sap-client=001&sap-language=EN.
Authenticating to SAP Gateway
SAP Gateway supports multiple authentication methods: Basic authentication, OAuth, OAuth PKCE, API Key, and SAP BTP Destination authentication. Use basic authentication to connect with a username and password, OAuth or OAuth PKCE to authenticate via a browser-based authorization flow, API key authentication to connect using an API key, or SAP Business Technology Platform (BTP) Destination authentication to retrieve credentials automatically from a configured SAP BTP Destination Service.
Basic
To enable basic authentication, set the following properties:- AuthScheme: Basic.
- User: The username you use to log in to SAP Gateway.
- Password: The password you use to log in to SAP Gateway.
After you set the above properties are set, you are ready to connect. Use your personal credentials to access your local data.
OAuth
The following subsections provide details about authenticating from a desktop application, the web, or a headless machine. For information about creating a custom OAuth application, see Creating a Custom OAuth Application.
Desktop Applications
To authenticate with the credentials for a custom OAuth application, you must get and refresh the OAuth access token. After you do that, you are ready to connect.Get and Refresh the OAuth Access Token
- OAuthClientId: The client Id assigned when you registered your application.
- OAuthClientSecret: The client secret that was assigned when you registered your application.
- CallbackURL: The redirect URI that was defined when you registered your application.
Log in and grant permissions to the application. When the access token expires, the driver refreshes the access token automatically.
Headless Machines
If you need to authenticate via OAuth with a user account on a headless machine, you must authenticate on another device that has an internet browser. You can do this in either of the following ways:
- Option 1: Obtain the OAuthVerifier value as described in "Obtain and Exchange a Verifier Code" below.
- Option 2: Install the driver on a machine with an internet browser and transfer the OAuth authentication values after you authenticate through the usual browser-based flow, as described in "Transfer OAuth Settings" below.
After you execute either Option 1 or Option 2, configure the driver to automatically refresh the access token on the headless machine.
Option 1: Obtaining and Exchanging a Verifier Code
To obtain a verifier code, you must authenticate at the OAuth authorization URL. Do the following:
- Set the following properties:
- InitiateOAuth: OFF.
- OAuthClientId: The client Id assigned when you registered your application.
- OAuthClientSecret: The client secret assigned when you registered your application.
- Use the appropriate CalllbackURL to call the GetOAuthAuthorizationURL stored procedure.
- Copy the returned URL into a browser and open the page.
- Log in and grant permissions to the driver. You are redirected to the redirect URI.
- Record the code parameter that is appended to the redirect URI. You will use it later, when you set up the OAuthVerifier connection property.
- To exchange the OAuth verifier code for OAuth refresh and access tokens, set the following
connection properties, which provide the OAuth authentication values:
- InitiateOAuth: REFRESH.
- OAuthVerifier: The noted verifier code (the value of the code parameter in the redirect URI).
- OAuthClientId: The client Id in your custom OAuth application settings.
- OAuthClientSecret: The client secret in the custom OAuth application settings.
- OAuthSettingsLocation: Persist the encrypted OAuth authentication values to the specified file.
- Test the connection to generate the OAuth settings file, then re-set the following properties to connect:
- InitiateOAuth: REFRESH.
- OAuthClientId: The client Id assigned when you registered your application.
- OAuthClientSecret: The client secret assigned when you registered your application.
- OAuthSettingsLocation: The file containing the encrypted OAuth authentication values. Make sure this file gives read and write permissions to the driver to enable the automatic refreshing of the access token.
Option 2: Transfer OAuth Settings
Before connecting on a headless machine, you must install and create a connection with the driver on a device that supports an internet browser. Set the connection properties as previously described above, in "Desktop Applications".
After completing the instructions in "Desktop Applications", the resulting authentication values are encrypted and written to the path specified by OAuthSettingsLocation. The default filename is "OAuthSettings.txt".
Test the connection to generate the OAuth settings file, then copy the OAuth settings file to your headless machine.
To connect to data via the headless machine, set the following connection properties:
- InitiateOAuth: REFRESH.
- OAuthClientId: The client Id assigned when you registered your application.
- OAuthClientSecret: The client secret assigned when you registered your application.
- OAuthSettingsLocation: The path to the OAuth settings file you copied from the machine with the browser. To enable automatic refreshing of the access token, ensure that this file gives read and write permissions to the driver.
OAuth PKCE
You can use OAuth authentication with Proof Key for Code Exchange (PKCE), an extension of the standard OAuth 2.0 flow designed for clients that cannot securely store a client secret. PKCE requires a custom OAuth application. For information about creating one, see Creating a Custom OAuth Application.Configure the following connection properties:
- AuthScheme: Set this to OAuthPKCE to authenticate using the OAuth PKCE flow.
- InitiateOAuth: GETANDREFRESH. This setting performs the OAuth authorization flow and automatically refreshes access tokens as needed, eliminating the need to manually complete the OAuth exchange or set the OAuthAccessToken.
- OAuthClientId: The client Id assigned when you registered your custom OAuth application.
- OAuthClientSecret: The client secret assigned when you registered your custom OAuth application. This property is optional. Confidential clients that can securely store a client secret should provide it, while public clients typically do not use one.
The PKCE authentication flow requires a PKCE verifier. Obtain this value by completing the following steps:
- Execute the GetOAuthAuthorizationURL stored procedure. The procedure returns the PKCE verifier in its response.
- Set the PKCEVerifier connection property to the returned value before completing authentication.
API Key
To connect using an API key, set the following properties:
- AuthScheme: Token.
- APIKey: The API key associated with your account.
To obtain an API key, open the Developer Portal and select the Product or Service for which you have published the API. Click Subscribe > Create a new Application, fill in the required information, and create the application. The application key is then displayed. Copy this value into the APIKey connection property.
SAP BTP Destination
To authenticate using SAP BTP Destination Service, you can configure the driver to retrieve authentication details automatically from your SAP BTP destination. This method simplifies authentication by handling token management internally.
To enable authentication via SAP BTP Destination Service, set the following connection properties:
- AuthScheme: SAPBTP.
- InitiateOAuth: GETANDREFRESH.
- OAuthClientId: The client Id associated with your SAP BTP Destination Service. Can be found in the service key of the Destination Service instance under the clientid field.
- OAuthClientSecret: The client secret associated with your SAP BTP Destination Service. Can be found in the service key of the Destination Service instance under the clientsecret field.
- OAuthAccessTokenURL: The URL of the SAP BTP OAuth token endpoint used to obtain an access token for the destination. Can be found in the service key of the Destination Service instance under the url field.
- DestinationName: The name of the SAP BTP destination configured to hold the credentials of the service you want to connect to.
- DestinationURL: The URL of the SAP BTP Destination Service API. Can be found in the service key of the Destination Service instance under the uri field.
After configuring the above properties, the driver handles the authentication flow automatically. You do not need to manage tokens or authentication details manually, making this AuthScheme useful especially for headless machines.
See Creating a SAP Gateway Destination for information on how to create a SAP Gateway Destination.