Skip to content

Connect Tenants

A tenant is a connection to one SAP Integration Suite, Cloud Integration (CPI) tenant: a hostname and a credential. You can define as many as you like, for example development, test and production, and switch between them in the top bar.

Defining a tenant needs the admin role. Every user can then use it.

Companion reads your tenant through the Cloud Integration OData API. It needs an API client: a service instance of Process Integration Runtime with plan api, and a service key for that instance.

Please refer to:

For the instance, choose the grant type client_credentials and these roles:

{
"grant-types": ["client_credentials"],
"redirect-uris": [],
"roles": [
"AuthGroup_Administrator",
"AuthGroup_BusinessExpert",
"AuthGroup_IntegrationDeveloper",
"AuthGroup_TenantPartnerDirectoryConfigurator"
]
}

These groups cover every tool, now and as tools are added. If your security team wants the key to hold only what is used, Tenant Permissions lists which tool reads which API with which role, and the smallest set.

Companion only reads. It deploys nothing to the tenant and changes nothing in your flows.

  1. Open Tenants and add a tenant.
  2. Paste the JSON of the service key. It is read in your browser; only the client ID, the client secret, the token URL and the hostname are saved. The form fills in the hostname and suggests a tenant key.
  3. Check the tenant key. It is the short name of this tenant in Companion, for example dev or prod-eu: lower-case letters, digits and hyphens, at most 32 characters. It cannot be changed later.
  4. Optionally add a description and the environment. Production tenants are highlighted in lists.
  5. Click Test connection. Companion requests a token and makes one call to the message log API, and tells you which of the two steps failed if one does.
  6. Save.

You can also enter the client ID, client secret and token URL by hand, or use basic authentication with a technical user.

Companion also works with Cloud Integration tenants in the Neo environment. Neo has no service key to paste, so the values are entered by hand.

  1. Create an OAuth client in the Neo cockpit. SAP Help describes the steps: Setting up OAuth inbound authentication with client credentials grant for API clients. Give the client the Neo roles listed on Tenant Permissions.
  2. When adding the tenant, type the hostname of the tenant, the client ID, the client secret and the token URL of the OAuth client into the form instead of pasting a service key.
  3. Test the connection and save, as for a Cloud Foundry tenant.
  • The client secret is encrypted in the database and is never shown again. When you edit a tenant, leave the secret empty to keep the stored one.
  • A stored secret is only sent to the host it was saved for. Pointing an existing credential at another hostname needs an administrator, and changing its type or token URL needs the secret typed in again.
  • Deleting a tenant also deletes its credential when no other tenant uses it.

Syncing is off for a new tenant until you switch it on:

  • Message Logs → Settings turns on log sync and sets how long logs are kept. See Message Logs.
  • Artifacts → Settings turns on the scheduled artifact sync. See Artifacts.

The tools that read the tenant live, such as Certificate Expiry or Partner Directory, work right away.