SAP Knowledge Base Article - Preview

3592653 - Troubleshooting 401 Errors for Inbound Calls to Cloud Integration iFlow Endpoints

Symptom

The purpose of this KBA is to break down the various authentication methods which might be used when calling iFlow endpoints on cloud integration tenant, and advise how to troubleshoot and resolve any issues involving a 401 'Authentication Failed' error message for such calls.
As the required configuration can differ for each scenario depending on whether the Cloud Integration tenant is hosted on Cloud Foundry or NEO, each type of authentication scenario has a dedicated section for each, where necessary. 

Topic Covered:

  • 1. Basic Authentication
        1.a Applicable for Cloud Integration tenants hosted on both NEO and Cloud Foundry (CF)
        1.b NEO only
        1.c Cloud Foundry only

  • 2. Client Certificate Authentication
        2.a Cloud Integration tenants hosted on NEO
        2.b Cloud Integration tenants hosted on Cloud Foundry

  • 3. OAuth Client Credentials Grant
        3.a Cloud Integration tenants hosted on NEO
        3.b Cloud Integration tenants hosted on Cloud Foundry

  • 4. A note about 401 error when calling Cloud Integration APIs


Read more...

Environment

  • SAP Cloud Integration
  • SAP Integration Suite

Product

Cloud Integration all versions ; SAP Integration Suite all versions

Keywords

CPI, SCPI, HCI, Cloud Integration, Integration Suite, 401, CPI Endpoint, iFlow endpoint, iFlow, integration flow, inbound communication, authentication, Basic Authentication, client certificate authentication, OAuth Client Credentials grant, sender adapter, adapter endpoint, CPI endpoint, 401 Authentication Failed, client certificate, HTTP Access logs, S-User ID, user credentials, SAP Load Balancer, NEO, Cloud Foundry, CF, technical S-User ID, Universal ID, UID, XSUAA could not authenticate user, password_locked, user ID, password, client ID, secret, clientID, The client certificate is not configured in a service key of a Process Integration Runtime service instance, SSL Client PSE parameter, Identity provider, Service Instance, Service Key, Certificate-to-user mapping, X.509 client certificate, certificate chain, root certificate, client, server, certificate authority, SAP Global Trust List, CA, Service Plan, Grant type, client credentials, integration-flow, external certificate, PEM-encoded format, Neither client certificate nor Authorization header found. Returning no auth type, access token , KBA , LOD-HCI-PI-CON-SOAP , SOAP Adapter , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.