SAP Knowledge Base Article - Preview

3115516 - Cannot access custom attributes from IdP via sap-approuter-userapi service

Symptom

  • To authenticate business users of the application at runtime, you use the tenant-aware Application Router application and SAP Authorization and Trust Management service (xsuaa) in SAP BTP. 
  • Furthermore, you defined custom Assertion Attributes in Customer Specific Identity Provider (IdP) for example: Employee Number as employee_number and Company as company.
  • But from the approuter application/approuter-userapi service, you are not able to access to those defined Assertion Attributes defined in customer specific IdP. 


Read more...

Environment

  • SAP Business Technology Platform, Cloud Foundry Environment
  • SAP Authorization and Trust Management service 
  • SAP Application Router

Product

SAP BTP, Neo environment 1.0

Keywords

JWT, JWT token, Cloud Foundry, CF, xsuaa, custom saml assertion attribute, custom attribute, custom idp , KBA , BC-CP-APR , SAP BTP Application Router , BC-CP-CF-SEC-IAM , UAA, Authentication, Authorization, Trust Mgmnt , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.