SourceLace Docs
Open the app

SAP ECC (on-premise)

How to connect an SAP ECC system in your own data centre: SourceLace reads (and, if you allow it, creates or updates) data through your SAP Gateway OData services, as each person's own SAP user, through a small SourceLace Agent that runs inside your network. No SAP passwords are stored anywhere and no inbound firewall rule is needed.

Status: in testing. Built against SAP's documented behaviour for SAP Gateway OData (version 2), client certificates and certificate-to-user mapping, and covered by automated tests against a simulated SAP Gateway; not yet used with a customer's live SAP system. Tell support@sourcelace.com before you start, so we can help with the first connection.

How it works

  1. Your IT team runs the SourceLace Agent, a small program (or Docker container), on a machine inside your network that can reach SAP over HTTPS.
  2. The agent opens one outbound connection to SourceLace over HTTPS (port 443) and keeps it open. SourceLace sends requests over it; nothing connects in to your network.
  3. For each request, the agent maps the asking person to an SAP user (by a rule you choose) and calls SAP Gateway with a client certificate for that user that it signs itself and that lasts a few minutes. Your SAP system trusts the agent's certificate authority and maps each certificate to its SAP user, so SAP applies that person's own authorizations. This is the same pattern as SAP Cloud Connector's principal propagation.
  4. The agent checks every request against its own allowlist first: only the Gateway services you list can be read, and only the entity sets you list under writes can be changed. Deletes, $batch and anything outside your Gateway paths are refused, whatever SourceLace asks.

SourceLace reaches ECC only through SAP Gateway OData services, never through RFC or BAPI calls. If you want SourceLace to use a BAPI's logic, expose it as a Gateway service (for example with transaction SEGW) and add that service to the agent.

The step-by-step guide for your SAP Basis team (installing the agent, making its certificate authority, STRUST, CERTRULE or EXTID_DN, ICM settings and activating services in /IWFND/MAINT_SERVICE) is in SourceLace's repository as docs/SAP_ECC.md; support@sourcelace.com can send it to you.

Create the agent's token (SourceLace admin)

  1. On Manage sources, under On-premise agents, click Add an agent and give it a name, such as Frankfurt DC.
  2. SourceLace shows the agent's token (it starts with sla_) once. Copy it into the agent's token file, or give it to whoever installs the agent through your password manager. SourceLace keeps only a hash of it.
  3. Once the agent runs, the list shows it Online, with the time it was last seen and the services it offers. Revoke stops a token at once and disconnects the agent; make a new one to replace it.

Each organization can have up to 20 agents, for example one per SAP system.

Add the source (SourceLace admin)

On Manage sources → Add a source, choose SAP ECC (on-premise) (ecc).

Option Type Default Example What it is
agent Text (required) agt_0123456789ab The id of the on-premise agent, shown under On-premise agents.
gateway_path Text /sap/opu/odata/sap /sap/opu/odata/sap Where your Gateway services live. The agent must list the same path.

Changes are off unless you turn them on. Name objects as SERVICE/EntitySet, such as ZSALES_ORDER_SRV/SalesOrderSet. A change is only possible when it is allowed in both places: here, and in the agent's own writes list. Records are created or updated one at a time; SourceLace never deletes records in SAP ECC.

Connect (each person)

Each person clicks Connect on Data Sources (or asks their AI app to connect). There is no sign-in page: SourceLace asks the agent which SAP user the person is, and shows it. People the agent cannot map are refused with "You have no SAP user in the SourceLace Agent's configuration".

What people can do

  • search_schema lists the entity sets of the Gateway services the agent offers, read from each service's $metadata as the person.
  • describe_object on SERVICE/EntitySet lists fields, labels, keys and navigation properties.
  • query (language odata) takes SERVICE/EntitySet plus OData options: $filter, $select, $expand, $orderby, $top, $skip, $inlinecount and sap-language. For example ZSALES_ORDER_SRV/SalesOrderSet?$filter=SoldTo eq '1000'&$select=SalesOrder,NetValue&$top=20. Only entity sets can be queried, never function imports.
  • get_record takes a key such as 4711, or a composite key such as SalesOrder='4711',Item='10', and navigation properties as related lists (up to 3).
  • propose_change and apply_change create or update one record, where allowed. SAP Gateway's CSRF token is handled by the agent. When the service sends ETags, SourceLace refuses to apply a change if the record changed after the preview; when it does not, the preview says so.

Security

  • No SAP passwords exist in SourceLace or in the agent. Each certificate names one SAP user and expires within minutes.
  • The certificate authority's private key stays on the agent's machine. SourceLace never has it, so SourceLace alone cannot sign in to SAP as anyone.
  • The agent decides what can be reached, from its own configuration file: SAP's address and client, the Gateway services, the writable entity sets and who is which SAP user. SourceLace cannot change any of it.
  • The agent logs request ids, methods, service names, HTTP status and timings, never row data, query options, tokens or keys.
  • Rows from SAP pass through SourceLace's memory like any other source's and are never stored (How long things are kept).

When something goes wrong

What you see What to do
"Your organization's SourceLace Agent is offline, so SAP cannot be reached right now..." The agent is not running or cannot reach SourceLace over outbound HTTPS. A SourceLace admin sees its state under On-premise agents; your IT team checks the agent's log.
"The SourceLace Agent (...) did not answer within 60 seconds." SAP or the agent was too slow. Try again with fewer rows ($top) or fields ($select).
"You have no SAP user in the SourceLace Agent's configuration: ..." Ask your SAP or IT team to map you: your email domain in the agent's users.domains, or your email in its [users.table].
"The SourceLace Agent for ... refused this request: The Gateway service ... is not in the agent's sap.services list." The agent's allowlist does not include that service. Your IT team can add it.
"SAP did not accept the certificate login for ... (HTTP 401)." SAP does not trust the agent's certificate authority, or cannot map the certificate to a user. Your SAP Basis team checks STRUST and CERTRULE (or EXTID_DN).
"SAP refused this for ... (HTTP 403)..." SAP's own authorization check refused it. Ask your SAP team for the access.
"SAP ECC: the service ... has no entity set ..." Check the name with search_schema. Function imports cannot be queried.
"There is no on-premise agent ... in your organization." The agent option names an agent that does not exist or was revoked. Use an id from On-premise agents.
"SAP ECC: the record changed after the preview." Someone changed the record in SAP meanwhile. Propose the change again to see the current values.