ADO.NET Provider for SAP ByDesign

Build 26.0.9770

SAP IAS SAML Application Configuration

SAP IAS SAML Application Configuration

SAP ByDesign supports the OAuth 2.0 Security Assertion Markup Language (SAML) flow, which requires a signed SAML assertion issued by an external Identity Provider (IdP). This assertion is then exchanged for an access token when making requests to the SAP ByDesign API.

This guide outlines how to configure SAP Identity Authentication Service (IAS) to generate the required SAML assertion using two applications:

  • An OpenID Connect (OIDC) application that handles the OAuth authentication (Authorization Code or Password grant).
  • A SAML 2.0 application that generates the SAML assertion, registered as a Dependency of the OIDC application.

The access token issued by the OIDC application is exchanged for a SAML assertion via the Token Exchange (RFC 8693) flow, targeting the SAML application through its dependency name. The provider then exchanges the assertion for an SAP ByDesign access token.

Note: Existing single-application configurations (a SAML application whose protocol was temporarily switched to OpenID Connect to configure the OAuth settings) continue to work with the Password grant and do not require the Resource property. The two-application setup described here is recommended for all new configurations, and is required for a reliable Authorization Code flow: with a single SAML-protocol application, IAS redirects interactive browser sign-ins to the application's SSO endpoint instead of the OAuth redirect URI, so the provider never receives the authorization code unless the browser already has an active IAS session.

  1. Retrieve the SAP IAS Signing Certificate:
    • On the SAP IAS Admin page, navigate to: Applications & Resources > Tenant Settings > SAML 2.0 Configuration.
    • Under Signing Certificates, click the lens icon to view the active certificate.
    • Copy the entire certificate content under the Certificate Information section, this will be used to validate the SAML assertion signature.
  2. Create an OAuth2 Client App in SAP ByDesign:
    • Navigate to Admin Center > Manage OAuth2 Client Applications.
    • Create a new application using the Register Client Application button.
    • Fill in the Application Name and the Application URL fields to your preferred values.
    • Paste the signing certificate content under the *X.509 Certificate field.
    • After saving, copy the generated API Key, this will be used as the OAuthClientId in your connection configuration.
  3. Create the SAML Application in SAP IAS:
    • In SAP IAS Admin Console, go to: Applications & Resources > Applications > Create.
    • Enter the below properties:
      • Display Name: (custom name)
      • Protocol: SAML 2.0
      • Home URL: Leave empty
      • Parent App: Leave as None
    • Click Create.
    • Go to Trust > Single Sign-On > SAML 2.0 Configuration and configure the following:
      • Set the URL for Principal Propagation to <SAP ByDesign base url>/oauth/token (for example, https://apisalesdemo2.successfactors.eu/oauth/token).
      • Under Subject Name Identifier, choose a value that matches the username of the API user in both SAP IAS and SAP ByDesign.
      • Under Default Name ID Format, select the Unspecified (urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified) option.
      • Under Assertion Attributes, add a new attribute with the name api_key, and set the value to the API Key of the SAP ByDesign OAuth2 client application.
    • This application is never accessed from a browser in this flow. If the configuration requires an SSO endpoint (ACS) value to save, enter any placeholder URL, as it is never invoked.
  4. Create the OIDC Application in SAP IAS:
    • In SAP IAS Admin Console, go to: Applications & Resources > Applications > Create.
    • Enter the below properties:
      • Display Name: (custom name)
      • Protocol: OpenID Connect
      • Home URL: Leave empty
      • Parent App: Leave as None
    • Click Create.
    • Go to Trust > Single Sign-On > OpenID Connect Configuration and configure:
      • Redirect URIs: Add the redirect URI the provider listens on during the Authorization Code flow. The default is http://localhost:33333. This step is not needed for the Password grant.
      • Grant Types: Enable your preferred grants. The provider supports:
        • Authorization Code (with or without PKCE) or Password
        • Token Exchange (RFC 8693): Required to get the SAML assertion.
        • Refresh: Optional, but recommended if you want the provider to automatically refresh the access token.
      • Access Token Format: Leave the default Grant-Type Dependent or select Opaque. The provider explicitly requests an opaque access token, which is required for the token exchange.
    • Configure Client Authentication:
      • Go to Application APIs > Client Authentication.
      • Create a client secret by clicking on the Add button on the Secrets section.
      • Copy the Client ID and Client Secret, as these will be passed in the provider's SSOProperties:
  5. Register the SAML Application as a Dependency of the OIDC Application:
    • On the SAML application, go to Application APIs > Provided APIs and add an API entry (any name, for example, BYD_API). This declares the SAML application as an API provider.
    • On the OIDC application, go to Application APIs > Dependencies and click Add. Enter a Dependency Name (for example, SAML_DEP), select the SAML application as the provider application, and select its provided API.
    • Set the Resource connection property to the dependency resource URN:
      urn:sap:identity:application:provider:name:<DependencyName>
      Replace <DependencyName> with the Dependency Name you entered on the OIDC application (for example, urn:sap:identity:application:provider:name:SAML_DEP).
After completing the configuration steps above, you are ready to set the required connection properties and establish a connection using the provider, as discussed in Establishing a Connection.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770