SAP Knowledge Base Article - Preview

3115516 - Cannot access Custom SAML Assertion Attributes from IdP via sap-approuter-userapi service


  • To authenticate business users of the application at runtime, you use the tenant-aware approuter application and SAP Authorization and Trust Management service (technical name: xsuaa) in SAP BTP. 
  • Furthermore, you defined custom Assertion Attributes in Customer Specific identity Provider (IdP) for example: Employee Number as employee_number and Company as company
  • But from the approuter application/approuter-userapi service, you are not able to access to those defined Assertion Attributes defined in customer specific IdP Anyway. 



  • SAP Business Technology Platform Cloud Foundry Environment
  • SAP Authorization and Trust Management service  (xsuaa)


SAP Business Technology Platform 1.0


JWT, JWT token, Cloud Foundry, CF, xsuaa, custom saml assertion attribute, custom attribute, custom idp , KBA , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP ONE Support launchpad (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.