Excel Add-In for SAP Gateway

Build 26.0.9770

Establishing a Connection

Configure a Connection Profile

From the CData ribbon, click Get Data and select From SAP Gateway connection/s to launch the CData Query window. To setup a new connection, you will have to click the New SAP Gateway Connection button. Here you can set the connection settings, test the connection, and save the connection profile.

Connecting to SAP Gateway

SAP Gateway provides three ways to connect to data:

  • To connect to your own local data via the desktop (non-browser connection, referred to below as "basic authentication"), use the CData-supplied embedded OAuth application.
  • To connect to shared data over the network (browser connection), use a custom OAuth application.

To access SAP Gateway tables, set the following connection properties:

  • URL: The URL of your environment, or the full URL of the service. For example, the full URL might appear as: https://sapes5.sapdevcenter.com/sap/opu/odata/IWBEP/GWSAMPLE_BASIC/. In this example, the environment URL would just be: https://sapes5.sapdevcenter.com. Add any additional properties using the CustomURLParams property.
  • Namespace: The appropriate Service Namespace. In the example above, IWBEP is the namespace. It is optional if the full URL to the service is specified.
  • Service: The service from which you want to retrieve data. In the URL property example listed above, the service is GWSAMPLE_BASIC. It is not required if the full URL is specified.
  • CustomURLParams: Any required additional properties that need to be included with the HTTP request; for example, sap-client=001&sap-language=EN.

Authenticating to SAP Gateway

SAP Gateway supports multiple authentication methods: Basic authentication, OAuth, OAuth PKCE, API Key, and SAP BTP Destination authentication. Use basic authentication to connect with a username and password, OAuth or OAuth PKCE to authenticate via a browser-based authorization flow, API key authentication to connect using an API key, or SAP Business Technology Platform (BTP) Destination authentication to retrieve credentials automatically from a configured SAP BTP Destination Service.

Basic

To enable basic authentication, set the following properties:

  • AuthScheme: Basic.
  • User: The username you use to log in to SAP Gateway.
  • Password: The password you use to log in to SAP Gateway.

After you set the above properties are set, you are ready to connect. Use your personal credentials to access your local data.

OAuth

The following subsections provide details about authenticating from a desktop application, the web, or a headless machine. For information about creating a custom OAuth application, see Creating a Custom OAuth Application.

Desktop Applications

To authenticate with the credentials for a custom OAuth application, you must get and refresh the OAuth access token. After you do that, you are ready to connect.

Get and Refresh the OAuth Access Token

  • OAuthClientId: The client Id assigned when you registered your application.
  • OAuthClientSecret: The client secret that was assigned when you registered your application.
  • CallbackURL: The redirect URI that was defined when you registered your application.
When you connect, the add-in opens SAP Gateway's OAuth endpoint in your default browser.

Log in and grant permissions to the application. When the access token expires, the add-in refreshes the access token automatically.

OAuth PKCE

You can use OAuth authentication with Proof Key for Code Exchange (PKCE), an extension of the standard OAuth 2.0 flow designed for clients that cannot securely store a client secret. PKCE requires a custom OAuth application. For information about creating one, see Creating a Custom OAuth Application.

Configure the following connection properties:

  • AuthScheme: Set this to OAuthPKCE to authenticate using the OAuth PKCE flow.
  • InitiateOAuth: GETANDREFRESH. This setting performs the OAuth authorization flow and automatically refreshes access tokens as needed, eliminating the need to manually complete the OAuth exchange or set the OAuthAccessToken.
  • OAuthClientId: The client Id assigned when you registered your custom OAuth application.
  • OAuthClientSecret: The client secret assigned when you registered your custom OAuth application. This property is optional. Confidential clients that can securely store a client secret should provide it, while public clients typically do not use one.

The PKCE authentication flow requires a PKCE verifier. Obtain this value by completing the following steps:

  • Execute the GetOAuthAuthorizationURL stored procedure. The procedure returns the PKCE verifier in its response.
  • Set the PKCEVerifier connection property to the returned value before completing authentication.

API Key

To connect using an API key, set the following properties:

To obtain an API key, open the Developer Portal and select the Product or Service for which you have published the API. Click Subscribe > Create a new Application, fill in the required information, and create the application. The application key is then displayed. Copy this value into the APIKey connection property.

SAP BTP Destination

To authenticate using SAP BTP Destination Service, you can configure the add-in to retrieve authentication details automatically from your SAP BTP destination. This method simplifies authentication by handling token management internally.

To enable authentication via SAP BTP Destination Service, set the following connection properties:

  • AuthScheme: SAPBTP.
  • InitiateOAuth: GETANDREFRESH.
  • OAuthClientId: The client Id associated with your SAP BTP Destination Service. Can be found in the service key of the Destination Service instance under the clientid field.
  • OAuthClientSecret: The client secret associated with your SAP BTP Destination Service. Can be found in the service key of the Destination Service instance under the clientsecret field.
  • OAuthAccessTokenURL: The URL of the SAP BTP OAuth token endpoint used to obtain an access token for the destination. Can be found in the service key of the Destination Service instance under the url field.
  • DestinationName: The name of the SAP BTP destination configured to hold the credentials of the service you want to connect to.
  • DestinationURL: The URL of the SAP BTP Destination Service API. Can be found in the service key of the Destination Service instance under the uri field.

After configuring the above properties, the add-in handles the authentication flow automatically. You do not need to manage tokens or authentication details manually, making this AuthScheme useful especially for headless machines.

See Creating a SAP Gateway Destination for information on how to create a SAP Gateway Destination.

Connection Properties

The Connection properties describe the various options that can be used to establish a connection.

Managing Connections

After successfully authenticating to SAP Gateway you will be able to customize the data you are importing. To learn more about this, see Managing Connections.

See Also

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770