Connect Tenants
A tenant is a connection to one SAP Integration Suite, Cloud Integration (CPI) tenant: a hostname and a credential. You can define as many as you like, for example development, test and production, and switch between them in the top bar.
Defining a tenant needs the admin role. Every user can then use it.
Create a service key
Section titled “Create a service key”Companion reads your tenant through the Cloud Integration OData API. It needs an API client: a service instance of Process Integration Runtime with plan api, and a service key for that instance.
Please refer to:
- SAP Help: OAuth with client credentials grant for API clients
- this blog post: Integration Suite: accessing Cloud Integration runtime
For the instance, choose the grant type client_credentials and these roles:
{ "grant-types": ["client_credentials"], "redirect-uris": [], "roles": [ "AuthGroup_Administrator", "AuthGroup_BusinessExpert", "AuthGroup_IntegrationDeveloper", "AuthGroup_TenantPartnerDirectoryConfigurator" ]}These groups cover every tool, now and as tools are added. If your security team wants the key to hold only what is used, Tenant Permissions lists which tool reads which API with which role, and the smallest set.
Companion only reads. It deploys nothing to the tenant and changes nothing in your flows.
Add the tenant
Section titled “Add the tenant”- Open
Tenantsand add a tenant. - Paste the JSON of the service key. It is read in your browser; only the client ID, the client secret, the token URL and the hostname are saved. The form fills in the hostname and suggests a tenant key.
- Check the tenant key. It is the short name of this tenant in Companion, for example
devorprod-eu: lower-case letters, digits and hyphens, at most 32 characters. It cannot be changed later. - Optionally add a description and the environment. Production tenants are highlighted in lists.
- Click Test connection. Companion requests a token and makes one call to the message log API, and tells you which of the two steps failed if one does.
- Save.
You can also enter the client ID, client secret and token URL by hand, or use basic authentication with a technical user.
Neo tenants
Section titled “Neo tenants”Companion also works with Cloud Integration tenants in the Neo environment. Neo has no service key to paste, so the values are entered by hand.
- Create an OAuth client in the Neo cockpit. SAP Help describes the steps: Setting up OAuth inbound authentication with client credentials grant for API clients. Give the client the Neo roles listed on Tenant Permissions.
- When adding the tenant, type the hostname of the tenant, the client ID, the client secret and the token URL of the OAuth client into the form instead of pasting a service key.
- Test the connection and save, as for a Cloud Foundry tenant.
About stored credentials
Section titled “About stored credentials”- The client secret is encrypted in the database and is never shown again. When you edit a tenant, leave the secret empty to keep the stored one.
- A stored secret is only sent to the host it was saved for. Pointing an existing credential at another hostname needs an administrator, and changing its type or token URL needs the secret typed in again.
- Deleting a tenant also deletes its credential when no other tenant uses it.
After connecting
Section titled “After connecting”Syncing is off for a new tenant until you switch it on:
- Message Logs → Settings turns on log sync and sets how long logs are kept. See Message Logs.
- Artifacts → Settings turns on the scheduled artifact sync. See Artifacts.
The tools that read the tenant live, such as Certificate Expiry or Partner Directory, work right away.