Symptom
You need to validate that OAuth 2.0 authentication is working correctly in your SuccessFactors tenant before configuring it in the client system (e.g., CPI, Boomi, ECP, third-party).
The OAuth 2.0 SAML Bearer Assertion flow is shared across all SuccessFactors API protocols. The steps below use an API testing tool (e.g., Postman) to isolate and validate the authentication independently from the client system.
If OAuth works in the API testing tool but fails in the client system, the issue is in the client system's configuration — not in the SuccessFactors OAuth setup.
OAuth Authentication flow schema
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Read more...
Environment
SAP SuccessFactors HCM Suite
- OData V2/V4
- SFAPI (CompoundEmployee)
- REST API
- SCIM API
Product
Keywords
odata, api, oauth, authentication, token, bearer, access_token, assertion, client_id, grant_type, assertion, saml, OAuth, OAuth 2.0, SAML, SAML assertion, access token, bearer token, Postman, API testing, OData, SFAPI, SCIM, client_id, company_id, grant_type, X.509, certificate, Manage OAuth2 Client Applications, API Key, /oauth/token, /oauth/validate, authentication, token expired, SAML2 bearer, integration, CPI, Boomi , KBA , LOD-SF-INT-ODATA-OAU , ODATA OAUTH Authentication , How To
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview