This page contains instructions for setting up the OAuth 2.0 server in SAP and setting up the OAuth 2.0 client in Foundry.
SYSTEM user/PALANTIR/OAUTH_CLIENT should be assigned to the Foundry technical user and any end users wishing to write back to SAP from Foundry/PALANTIR/CONTENT_FUNCTION_ALL should be assigned to end user/sap/public/bc node to be activated (for OAuth 2.0 configuration)
/sap/bc/sec/oauth2*/default_host/sap/bc/webdynpro/sap/oauth2_authoritySOAUTH2 transaction.https://<FOUNDRY_DOMAIN>/workspace/oauth2-clients/callback./PALANTIR/SRV_0001 and a description such as Palantir Foundry writeback using SAP functions.~CHECK_CSRF_TOKEN and value 0 (zero)./IWFND/MAINT_SERVICE transaction./PALANTIR/SRV_0001LOCAL/PALANTIR/SRVODATA_SRV1This follows the general approach outlined in Configure outbound applications but has been tailored specifically to SAP systems.
Choose the setup that matches your SAP connection:
Allow Foundry to act on your behalf in SAP?.<SAP_DOMAIN> with your SAP hostname and <SAP_PORT> with its HTTPS port:https://<SAP_DOMAIN>:<SAP_PORT>/sap/bc/sec/oauth2/authorize
https://<SAP_DOMAIN>:<SAP_PORT>/sap/bc/sec/oauth2/token

/PALANTIR/SRV_0001.For more details on outbound application configuration options, see Configure outbound applications.
User-attributed writeback through SAP Data Accelerator is in the beta phase of development and may not be available on your enrollment. This includes the get token and refresh token webhooks, outbound application setup, and BAPI writeback described below. Functionality may change during active development.
To enable user-attributed writeback through SAP Data Accelerator, create two webhooks on your SAP ERP source: a get token webhook and a refresh token webhook. Then, select both webhooks in an outbound application. These webhooks use the source's authentication and SAP Data Accelerator connection settings to exchange and refresh tokens.
Before you begin, complete the SAP OAuth 2.0 server setup and configure your SAP ERP source to use SAP Data Accelerator. You also need permission to manage outbound applications.
When creating the get token webhook and the refresh token webhook, turn off Function configuration. If this setting is enabled, the webhooks are published as functions and cannot be used in outbound applications.
Use Insert example for each webhook after selecting its Task type. It automatically fills the task body template and creates the input and output parameters, including their types and mappings to response fields. Use the parameter tables below to check the generated configuration.

For both webhooks, leave Outbound application set to Not selected under Request configuration > Authorization. They use the SAP source's authentication to obtain and refresh tokens for the outbound application. Selecting that application here would create a circular dependency.
For both webhooks, leave Webhook safety set to the default Write API.
Follow the instructions below to create two webhooks on the same SAP ERP source:
Get OAuth Token, and turn off Function configuration.sap-erp-oauth2-token-webhook-task in Request configuration,Refresh OAuth Token.sap-erp-oauth2-refresh-webhook-task.The get token webhook expects the following input parameters:
| Input parameter | Type | Required |
|---|---|---|
client_id | String | Yes |
redirect_uri | String | Yes |
authorization_code | String | Yes |
code_verifier | Optional string | Required when Enable PKCE is turned on in the outbound application. |
The generated task body maps these inputs as follows:
Copied!1 2 3 4 5 6{ "client_id": {{json client_id}}, "redirect_uri": {{json redirect_uri}}, "authorization_code": {{json authorization_code}}, "code_verifier": {{json code_verifier}} }
The refresh token webhook expects the following input parameters:
| Input parameter | Type | Required |
|---|---|---|
client_id | String | Yes |
refresh_token | String | Yes |
The generated task body maps these inputs as follows:
Copied!1 2 3 4{ "client_id": {{json client_id}}, "refresh_token": {{json refresh_token}} }
Foundry supplies these input values during authorization and token refresh. Keep the parameter references in the task bodies so each request receives the appropriate values.
Insert example also creates the following output parameters for both webhooks. In Responses, verify that each variable has its own output parameter with the specified name, type, and response key. If configuring a webhook manually, create one output parameter for each row and map it to the matching response key as outlined in the table below:
| Output parameter | Type | Response key |
|---|---|---|
access_token | String | access_token |
scope | String | scope |
token_type | Optional string | token_type |
expires_in | Optional string | expires_in |
refresh_token | Optional string | refresh_token |
The following example shows the configured inputs and output mappings for the get token webhook:

The refresh token webhook uses the same output mappings with its two input parameters:

Follow the instructions below to use the two saved webhooks to configure the OAuth 2.0 connection:
Allow Foundry to act on your behalf in SAP?.sap-erp-oauth2-token-webhook-task and Refresh token webhook to the webhook using sap-erp-oauth2-refresh-webhook-task.https://<SAP_DOMAIN>/sap/bc/sec/oauth2/authorize. Use an SAP URL that users can reach from their browsers. This interactive authorization step requires access from the user's computer even though token exchange and refresh use SAP Data Accelerator./PALANTIR/SRV_0001 under Scopes.
On the same SAP ERP source, create or edit the webhook that invokes your BAPI. For this BAPI webhook, select the saved application under Request configuration > Authorization > Outbound application. When a user runs the writeback workflow, Foundry prompts them to authorize access to SAP if they do not already have a valid token. The writeback then uses that user's SAP authorization, and the refresh token webhook obtains a new access token when needed.
The REST API webhook configuration described below is in the legacy phase of development and no additional development is expected. For new configurations, choose the matching connection setup under Setting up the OAuth 2.0 client in Foundry. For more information on the legacy approach, see (Legacy) Custom webhook-based OAuth 2.0 handshakes.
Previously, configuring OAuth 2.0 for SAP required creating a dedicated REST API source with webhooks to handle the token and refresh flows manually. If your existing SAP integration uses this approach, it will continue to work.
Ensure that the SAP source URL is using HTTPS, or webhooks will fail when using an OAuth flow.


Webhooks published as functions cannot be used in legacy custom webhook-based OAuth 2.0 outbound applications. When creating your token and refresh webhooks, ensure function publishing is disabled.
On the overview page of the new REST API source, select Create webhook.
Give the webhook a name (such as SAP OAuth2 authorization code flow webhook). Ensure that Function Configuration is toggled off.
Advance to the Request configuration step.
Under Calls, select POST as the request type and enter sap/bc/sec/oauth2/token as the path.
Under Query Params, sap-client might have to be set if the client used is not the default client.

redirect_uriclient_idauthorization_code
grant_type → authorization_coderedirect_uri → Mapped to the redirect_uri input parameter (see below for how to do this)client_id → Mapped to the client_id input parametercode → Mapped to the authorization_code input parameter

access_tokentoken_typeexpires_inrefresh_tokenscopeThis is an example for creating access_token. All output parameters should follow this pattern.

SAP OAuth2 refresh flow webhook). Ensure that Function Configuration is toggled off.sap/bc/sec/oauth2/token ) should be used.sap-client as a Query Param if needed.Content-Type → application/x-www-form-urlencoded
client_idrefresh_tokengrant_type → refresh_tokenclient_id → Mapped to the client_id input parameterrefresh_token → Mapped to the refresh_token input parameter

access_tokentoken_typeexpires_inrefresh_tokenscopehttps://<SAP_DOMAIN>/sap/bc/sec/oauth2/authorize
/PALANTIR/SRV_0001.