SAP Knowledge Base Article - Public

3790283 - Only users marked as "Is SSO User" are available in the Grant Credentials list when configuring a Trusted Application with the Client Credentials grant type

Symptom

  • After upgrading to SAP CPQ 2608, legacy authentication is no longer supported for the Deploy / Send Changes feature and token-based authentication must be used.
  • When configuring a Trusted Application with the Client Credentials grant type, only users marked as "Is SSO User" are available in the Grant Credentials list.
  • Users that are not marked as "Is SSO User" are not displayed and cannot be selected for Client Credentials grant.

Environment

SAP CPQ

Reproducing the Issue

  1. Log in to the destination environment.
  2. Navigate to Setup > Security > Trusted Applications.
  3. Create a Trusted Application and select the Client Credentials grant type.
  4. Open the Grant Credentials user selection list and observe that only users marked as "Is SSO User" are displayed.

Cause

  • This behavior is by design.
  • The Client Credentials grant flow does not perform password validation or password expiration checks.
  • Therefore, only users marked as "Is SSO User" are available for selection in the Grant Credentials list.

Resolution

  1. Create or designate a dedicated administrative or integration user that is marked as "Is SSO User" and configured for SSO authentication.
  2. Navigate to Setup > Security > Trusted Applications.
  3. Create a Trusted Application using the Client Credentials grant type.
  4. Select the "Is SSO User" account in Grant Credentials.
  5. Save the Trusted Application and use the generated Client ID and Client Secret.
  6. Configure the connected environment for Deploy / Send Changes using the generated credentials.

See Also

Refer to: Deploy / Send Changes – Token-based authentication overview

Refer to: OAuth 2.0 Client Credentials Authentication | SAP Help Portal

Keywords

trusted applications, client credentials, grant credentials list, sso user, non-sso user not listed, token-based authentication, deploy send changes, oauth2, client id client secret, cpq 2608, api authentication, integration user, guided selling deployments, trusted app configuration, sso requirement , KBA , CEC-SAL-CPQ , Sales Cloud CPQ , How To

Product

SAP CPQ 2026