Coupa
Connect Coupa to BotDojo so your agents can look up procurement records through Coupa's native Core API.
Connect Coupa to BotDojo so agents can look up procurement records through Coupa's native Core API. This provider exposes read-only invoice, purchase-order, and supplier tools.
Create a Coupa OAuth Client
Ask a Coupa administrator to create an OAuth 2.0 / OpenID Connect client in the Coupa instance that BotDojo will access:
- Go to Setup → Integrations → OAuth2/OpenID Connect Clients and select Create.
- Select Client Credentials as the grant type. This is the system-to-system flow; it does not use a Coupa user's login or a redirect URL.
- Set Client Purpose to the category that accurately describes this use. Coupa's current choices include Customer/Internal Admin, Third-Party Software Provider, and App Marketplace Application Partner. If the tenant classifies BotDojo as a third-party software provider, enter BotDojo as the provider name. The Coupa administrator should confirm the tenant's classification before saving; see Coupa's OAuth 2.0 and OIDC client settings.
- Use the tenant's Scope management page at
https://<your-coupa-instance>/oauth2/scopesto check which scopes grant the required API permissions. Select only read scopes for the records the agent should access. - In the client's data access restrictions, assign Account Groups to limit transactional records such as invoices and purchase orders, and Business Groups to limit master data such as suppliers, where those groupings apply. Read scopes grant endpoint permissions; they do not limit the records returned. Coupa says clients without group restrictions have unrestricted access to those data sets, so confirm broad tenant-wide access is intended before leaving both restrictions empty.
- Optionally configure Coupa's IP allowlist for the OAuth client if you have the approved BotDojo egress IP addresses or ranges for this deployment. Requests from other IP addresses will be rejected.
- Save the client. Record its Identifier, Secret, and OIDC Scopes securely.
For the built-in tools, the least-privilege example is:
core.invoice.read core.purchase_order.read core.supplier.read
Use the actual scope strings and permissions shown in the tenant's scope-management page. Coupa scopes are tenant-configured permissions; do not add write scopes for these read-only tools. Coupa documents the OAuth client flow and these example read scopes in Set Up an OpenID Connect Client and OpenID Connect Clients. The parent OAuth 2.0 and OIDC page documents the data access restrictions and IP allowlisting described above.
Collect these values for BotDojo:
| BotDojo field | Coupa value |
|---|---|
| Instance URL | The tenant HTTPS origin, such as https://example.coupahost.com. Do not include /api, /oauth2/token, or another path. |
| OAuth Client ID | The client Identifier. |
| OAuth Client Secret | The client Secret. Treat it as a credential. |
| Scopes | The client's OIDC Scopes, entered as a space-separated string with no commas. For example: core.invoice.read core.purchase_order.read core.supplier.read. |
| Token URL (optional) | Leave blank to use https://<instance-url>/oauth2/token, or enter the tenant's exact OAuth token URL. |
| OAuth Grant Type (optional) | client_credentials; this is also the default. |
Connect in BotDojo
- In the project, open Context → Connections and select Add Connection.
- Search the Integrations sources and select Coupa. Select an existing Coupa Integration if one is already configured; otherwise, BotDojo opens Coupa's Integration setup before continuing to the Connection.
- Enter the collected Instance URL, OAuth Client ID, OAuth Client Secret, and exact space-separated Scopes. Leave Token URL blank unless the tenant uses a different endpoint. Keep the grant type as
client_credentials. - When setting up a new Integration, select Test Connection to check that the current credentials can obtain an OAuth access token, then select Connect to save the Integration and continue creating the Connection. Test Connection makes a fresh token request, so it checks the current client ID, secret, and scopes even when a cached token exists. If you chose an existing Integration, select it and finish creating the Connection.
- Review the discovered tools in the Connection. Enable only the tools needed and set their approval behavior. Run a small list or get call against a known record the Coupa client is allowed to read.
See the canonical BotDojo Connections guide for Connection access, tool permissions, and sharing settings.
The Test Connection check validates fresh OAuth token acquisition only. It does not call invoice, purchase-order, or supplier endpoints and cannot prove that the selected scopes, account-group/business-group restrictions, or tenant data permissions allow a particular API read. Confirm access by running the relevant Coupa tool after connecting.
What This Integration Supports
Supported tools:
- list invoices
- get invoice
- list purchase orders
- get purchase order
- list suppliers
- get supplier
List tools support a bounded limit, offset, date filters, selected convenience filters, and a raw query object for exact Coupa query parameters such as updated_at[gt_or_eq], supplier[id], or name[contains].
Coupa allows at most 50 records per Core API GET. BotDojo caps every list request and its normalized result at 50, even if a larger limit is supplied. Each call returns one page; it does not automatically fetch the next page. Use the caller-controlled offset to continue: for example, request limit: 50, offset: 0, then limit: 50, offset: 50, then offset: 100. Advance by the number returned on a full page and stop when a page contains fewer records than requested. Coupa documents this limit and offset pattern in Querying Options.
Use Coupa tools inside BotDojo
Use the saved Connection in a workspace agent or flow. Enable only the Coupa tools it needs, set each tool's approval behavior, and give the agent or runtime identity access to that Connection. In-app use goes through the Connection and its policy; the agent does not receive the Coupa OAuth secret directly. The BotDojo Connections guide explains access and tool settings.
Expose the Connection to an external MCP client
To make the Coupa tools available outside BotDojo:
- Open the Coupa Connection and enable Export as MCP.
- Save the Connection, then select Get URL & Token in its settings.
- Configure the external MCP client with the provided MCP server URL and BotDojo token. Store the token in the client's secret store.
The external client receives the Connection's enabled tools and remains subject to BotDojo's Connection access and approval controls. Do not provide it the Coupa OAuth client secret or access token. See Export a Connection as MCP for the full procedure.
Notes
- After Coupa issues a token, BotDojo waits at least five seconds before the first API request using that token, as Coupa recommends. The issue time is retained with the cached token so another BotDojo worker honors the remaining wait. BotDojo refreshes a token at the earlier of 20 hours after its recorded issue time or five minutes before the
expires_inexpiry. Legacy cached tokens without a recorded issue time retain the expiry-based refresh behavior until BotDojo next issues a token. - Coupa API keys are deprecated for Core API integrations; use OAuth2 / OpenID Connect clients instead.