SAP Authorization and Trust Management (XSUAA) Authentication
The provided sources do not contain sufficient information to define a concept identified as "undefined." The sources cover topics such as multitenant applications, token policy configuration, the HTML5 Application Repository, the User API Service, SAP Java Connector, mTLS access tokens, API access, and signing key rotation — none of which correspond to a concept named "undefined." A accurate definition cannot be grounded solely in these snippets for this concept.
Tutorials that teach this
- Tutorial Create an Application with Cloud Foundry Node.js Buildpack
- Tutorial Create an Application with Cloud Foundry Python Buildpack
- Tutorial Create an Application with SAP Java Buildpack 2
- Tutorial Secure a Basic Node.js App with the Authorization and Trust Management Service (XSUAA)
- Tutorial Prepare for Production
Docs explaining this concept
- Doc Accessing Administration Using APIs of the SAP Authorization and Trust Management Service
- Doc Approuter Application
- Doc Configure Token Policy for SAP Authorization and Trust Management Service
- Doc Configure Trusted Domains for Multi-Environment Subaccounts
- Doc Configure the approuter Application
- Doc Create Role Collections with Predefined Roles
- Doc Get Access to the APIs
- Doc Getting an Access Token for SAP Cloud Management Service APIs
Code samples embodying this
Prerequisites
- Concept OAuth 2.0 Authorization Code Flow The concept name was not provided, and the available source snippets do not contain enough focused, attributable detail to produce a grounded 2–4 sentence prose definition without risking unsupported claims. A valid definition cannot be submitted for an **undefined** concept.
- Concept xs-security.json Authorization Configuration The concept provided is **undefined** and the available source snippets do not converge on a single, clearly named SAP developer concept. A meaningful, grounded definition cannot be written without a specific concept to define.
- Concept OAuth 2.0 Authentication The concept name provided is undefined and the supplied sources do not share a common subject — they cover a Communication Arrangement outbound user entity, Web Access Control in the Cloud Foundry environment, and an augmented reality tutorial — making it impossible to ground a coherent definition in the given material. Please provide a valid concept name and relevant supporting sources so an accurate definition can be written.
- Concept CDS-based Authorization Annotations The concept name is not defined in the provided source snippets, and no factual claims about it can be grounded in the available material. Insufficient source information was provided to produce a reliable definition.
- Concept Application Security Descriptor File (xs-security.json) The concept name was not provided (marked as "undefined"), and the supplied source snippets cover several distinct topics — including role collections, token policy configuration, redirect URIs, and principal propagation — without a single unifying concept that can be reliably identified and defined. A precise, source-grounded definition cannot be written without knowing which specific concept is intended.
- Concept CAP Cloud Deployment The concept name provided is "undefined," which does not correspond to a identifiable SAP developer concept supported by the provided source snippets. The sources reference topics such as Node.js business application development on SAP BTP, CAP services, and deployments to Cloud Foundry and Kyma runtimes, but none of them define or describe a concept called "undefined." A valid concept name is required to produce an accurate definition grounded in the provided sources.
- Concept JWT Token Propagation The concept name is not defined in the provided sources, and no sufficient detail about a specific concept is available to write a grounded definition. Please provide a valid concept name and relevant source snippets so an accurate definition can be written.
- Concept Cloud Foundry application deployment on SAP BTP The concept name is not defined in the provided sources, so a grounded definition cannot be written. The sources cover topics such as the [Cloud Foundry Environment](https://help.sap.com/docs/btp/sap-business-technology-platform/9c7092c7b7ae4d49bc8ae35fdd0e0b18?locale=en-US&state=PRODUCTION&version=Cloud) on SAP BTP and related developer tasks like binding service instances and logging on via the CLI, but none of them define a concept identified as "undefined." Please provide a valid concept name and relevant sources to generate an accurate definition.
- Concept Node.js Development in Cloud Foundry The concept name was not provided (marked as "undefined"), and the supplied source snippets do not contain enough substantive content — only titles and a brief fragment from S1 — to accurately define a specific SAP developer concept. A definition cannot be responsibly written without a valid concept name and sufficient grounding material from the sources.
- Concept CAP Framework (Cloud Application Programming Model) The concept name was not provided, so a precise definition cannot be determined. Based on the available sources, [SAP Business Technology Platform (SAP BTP)](https://help.sap.com/docs/btp/sap-business-technology-platform/c2fec62b49fa43b8bd945c85ecc2e5bd?locale=en-US&state=PRODUCTION&version=Cloud) is a platform on which developers build and run business applications, choosing from development environments, tools, APIs, and [programming models](https://help.sap.com/docs/btp/sap-business-technology-platform/042061da2e964b7eab3c7ec2a5cc7ece?locale=en-US&state=PRODUCTION&version=Cloud) such as ABAP Cloud and the SAP Cloud Application Programming Model (CAP). Developers use it to create full-stack business applications, following best practices to select the approach that best suits their requirements.
Concepts that build on this
- Concept Spring Security Authorization with SAP IAS/AMS
- Concept Approuter Application for Multitenancy
- Concept SaaS Provisioning Subscription Callbacks
- Concept Python Application Security with sap_xssec
- Concept SAP Application Router
- Concept Multitenancy with SaaS Provisioning Service
- Concept Node.js Application Router Package (@sap/approuter)
- Concept Application Router
- Concept UAA (User Account and Authentication) Service
- Concept Application Router (approuter) Configuration