Application Security Descriptor File (xs-security.json)
The concept name was not provided (marked as "undefined"), and the supplied source snippets cover several distinct topics — including role collections, token policy configuration, redirect URIs, and principal propagation — without a single unifying concept that can be reliably identified and defined. A precise, source-grounded definition cannot be written without knowing which specific concept is intended.
Tutorials that teach this
- Tutorial Add Scopes and Create Role Collection Mapping
- Tutorial Deploy CAP Java App to SAP Business Technology Platform
- Tutorial Prepare for Production
- Tutorial Add User Authentication to Your Application (SAP HANA Cloud)
- Tutorial Create an Application with Cloud Foundry Python Buildpack
- Tutorial Configure Authentication and Authorization on SAP BTP
- Tutorial Secure a Basic Node.js App with the Authorization and Trust Management Service (XSUAA)
- Tutorial HANA Native, Add User Authentication to Your Application
- Tutorial Add Security to the SAP SuccessFactors Extension
- Tutorial Create an Application with Cloud Foundry Node.js Buildpack
Docs explaining this concept
- Doc 400 Error: Call to /oauth/token Was Not Successful
- Doc Attributes
- Doc Authorization Entities
- Doc Binding Parameters of SAP Authorization and Trust Management Service
- Doc Building Roles and Role Collections for Applications
- Doc Compatible Changes in the Security Descriptor File
- Doc Configuration Options for the SAP Authorization and Trust Management Service
- Doc Configure Token Policy for SAP Authorization and Trust Management Service
Prerequisites
- Concept CAP Integration with Cloud Foundry on SAP BTP The **SAP Cloud Application Programming Model (CAP)** is a framework of languages, libraries, and tools for building enterprise-grade services and applications on [SAP Business Technology Platform](https://help.sap.com/docs/btp/sap-business-technology-platform/00823f91779d4d42aa29a498e0535cdf?locale=en-US&state=PRODUCTION&version=Cloud). Developers use it to define data models, services, and business logic that can be deployed to targets such as SAP HANA Cloud or SAP BTP. CAP supports both Node.js and Java runtimes, and integrates with tools like SAP Business Application Studio and SAP Continuous Integration and Delivery to streamline the full development lifecycle.
- Concept XSUAA Service Instance Configuration (xs-security.json) The concept name is not defined and the provided sources do not contain sufficient information to produce a grounded, accurate definition. No definition can be written without a valid concept name and supporting source content.
- Concept OAuth2 Authentication Redirect The `login` endpoint is a specific route handled by the application router during OAuth2 authentication on SAP Business Technology Platform. A developer uses it to trigger a redirect to the application router as part of the OAuth2 authentication flow, enabling users to authenticate with their applications.
- Concept OAuth2 Redirect URI Configuration The concept name is missing or undefined, and the provided source snippet does not contain enough grounded information to write a meaningful 2–4 sentence prose definition. Please provide a valid concept name and sufficient source material to support the definition.
- Concept CAP Authorization and Access Control The concept name was not provided (marked as "undefined"), and the supplied source snippets do not contain enough specific, attributable detail about a single named concept to produce an accurate, grounded definition. A definition cannot be written without a clearly identified concept and sufficient source content to support it.
- Concept OAuth Redirect URI Restriction The provided sources do not contain enough information to write a grounded definition for an undefined concept. Please provide a valid concept name and relevant source snippets to generate an accurate definition.
- Concept XSUAA Authorization Scopes The concept provided is **undefined** — no specific SAP developer concept was supplied for definition. Based on the available sources, which cover topics such as multitenancy setup on SAP BTP, the application security descriptor file (`xs-security.json`), and securing applications with the [Authorization and Trust Management Service (XSUAA)](https://help.sap.com/docs/btp/sap-business-technology-platform/0a69484539d64567ba17269f6e5ba88d?locale=en-US&state=PRODUCTION&version=Cloud), a meaningful definition cannot be written without a clearly identified concept. Please provide the specific concept name to generate an accurate reference definition.
Concepts that build on this
- Concept Managed Application Router
- Concept SAP SaaS Provisioning Service Instance Creation in Kyma
- Concept Role and Role Collection Management
- Concept Multitenancy with SaaS Provisioning Service
- Concept Scopes and Role Templates in SAP BTP
- Concept Role Collections and Authorization Artifacts
- Concept SAP Authorization and Trust Management (XSUAA) Authentication
- Concept Node.js Application Authentication on SAP BTP
- Concept MTA Project with Application Router Configuration
- Concept UAA (User Account and Authentication) Service
- Concept Cloud Foundry deployment
- Concept xs-security.json Authorization Configuration
- Concept OAuth2 Scopes and Role Templates
- Concept XSUAA Role Collections
- Concept Cloud Foundry application deployment on SAP BTP