Browse Integrate
Integrate · Agent Tool Integrations

SAP Ariba

Connect SAP Ariba to BotDojo so your agents can work with procurement reporting data and supplier purchase-order data through SAP Ariba native APIs.

6 min read

Connect an approved SAP Ariba application to BotDojo for read-only procurement reports or supplier purchase-order lookups. Each BotDojo SAP Ariba Integration has one API runtime URL. Use separate Integrations and Connections when SAP assigns different runtime URLs or application approvals.

Prepare SAP Ariba

  1. Confirm which API you need:
    • Operational Reporting API for Procurement reads procurement transactions from named reporting view templates. You need the customer realm and approved API access. SAP lists View Management (/viewTemplates) and Synchronous Reporting (/views) as separate Developer Portal discovery pages. Check approval and runtime URL for each; if they differ, configure separate Integrations and Connections and enable only the corresponding tools. See SAP's Procurement Reporting API guide.
    • Purchase Orders Supplier API reads supplier-side order headers (/orders) and line items (/items) from SAP Business Network. The supplier must have an Enterprise account and Developer Portal access; Standard Accounts cannot use the supplier API through the portal. Identify the supplier's own SAP Business Network ID (ANID), which is different from a buyer ANID used as a search filter. See SAP's supplier API setup.
  2. In the SAP Ariba Developer Portal, have a Developer create or open an application for the desired API. Have the Organization Admin request API access and wait for SAP's approval. For the supplier API, select SAP Business Network in the access request and enter the supplier's own ANID in AN-ID; for procurement reporting, select the authorized procurement realm. See SAP's API access request steps. After approval, collect the application key and OAuth client ID; the Organization Admin generates the OAuth secret or Base64-encoded client-and-secret credential. SAP generally limits customers to one application per realm/API combination. See SAP's application setup steps.
  3. On each approved API's discovery page, copy its Runtime URL and OAuth server URL prefix from Environment Details. Use the URL for the API and environment you actually approved. SAP directs Business Network API users to its US Developer Portal data center even when a procurement site is hosted in another region; confirm the correct portal and URLs with your SAP administrator. See the SAP Ariba Developer Portal guide.
  4. For the supplier API, have an authorized supplier account administrator register the approved application's OAuth client ID in SAP Business Network. For an account not yet migrated to SAP Business Network on BTP, use Account Settings → Settings → Account Registration → API Management → API Client ID Configuration → Add, enter the client ID, then save. For a migrated account, follow the BTP-specific instructions linked from SAP's current supplier administration guide; the menu path differs. Confirm the ANID for that same supplier account. SAP's supplier API request specification requires this ANID in X-ARIBA-NETWORK-ID on both order endpoints.

SAP's API-specific terms for Operational Reporting for Procurement and Purchase Orders Supplier state that production use or commercialization of applications containing these APIs requires a written agreement with SAP. For either API, the terms also call for confirming a third-party provider's SAP partner authorization and submitting written consent to SAP before connecting that service for data exchange.

Create the BotDojo Integration

  1. Open Integrations → Agent Tools → SAP Ariba → Connect. Create one Integration for each distinct approved API runtime and credential set you need.
  2. Choose Connection Mode to describe the intended API family: Procurement Reporting or Supplier Network Purchase Orders. The mode does not route API calls or restrict tools; set tool access on the Connection below.
  3. Enter Runtime URL, OAuth Server URL Prefix, Application Key, and either OAuth Client ID plus OAuth Client Secret, or the SAP-generated OAuth Basic Credential. The default token URL is {OAuth Server URL Prefix}/v2/oauth/token; set Token URL only if SAP supplies a different full URL. BotDojo uses Basic client authentication and client_credentials by default; legacy applications can set openapi_2lo. This Integration does not implement SAP's mTLS token flow. See SAP's token request instructions.
  4. For reporting, enter the approved Realm. For supplier orders, enter Supplier ANID (your supplier's own ANID); Realm is not used on supplier requests. BotDojo sends the Supplier ANID only with /orders and /items requests.
  5. Save and run Test Connection. This proves BotDojo can obtain an OAuth token. It does not prove that the application is approved for the selected API, that the realm or supplier ANID is correct, or that a view template exists. Run one read-only tool from the matching API family to validate those details.

Before enabling these tools for agents or exporting the Connection as MCP, confirm with SAP and your organization's contract owner that the intended use has an authorized pathway. SAP API Policy v4.2026a §2.2.2 restricts integration with generative or semiautonomous AI that plans, selects, or executes sequences of API calls except within SAP-endorsed architectures, data services, or expressly intended service-specific pathways. The API-specific requirements above also apply.

Make the tools available to agents

In your BotDojo project, open Context → Connections → Add Connection, find SAP Ariba under Integrations, and select the Integration you just created. Save the Connection, then enable only the tools for its approved API runtime and set each tool's approval policy. Agents use these tools through the Connection; they do not receive the SAP credentials. Follow the Connections guide for visibility, sharing, and access settings. Export as MCP is optional and is for external MCP clients; an in-app agent only needs the Connection.

Use the read-only tools

  • Reporting: With the approved View Management Connection, list or get a view template. With the approved Synchronous Reporting Connection, count or query the published view by name. If SAP assigned the same approved runtime and credentials to both API sets, one Connection can expose all four tools. The synchronous API returns at most 40 records per page and at most 10,000 records per query. Use the returned pageToken for subsequent pages; BotDojo's maxResults only limits how many records from that page reach the agent. At template-definition time, SAP permits either a filter expression based on unique names (for example, UniqueNames) or a FROM/TO date-filter pair spanning no more than 31 days. Separately, its synchronous /views procedure says request filters must specify at least one timespan of 31 days or less. SAP does not reconcile these statements for a unique-name-only template, so confirm that request path with SAP or an authorized tenant before relying on it. Use the template's filter names and pass an appropriate filters object or native filterExpression; for longer date-based reporting, run bounded windows. SAP also rejects API requests that would return records spanning more than one year. See SAP's Operational Reporting API guide and usage limits. BotDojo currently exposes the synchronous read path, not SAP's asynchronous export path.
  • Supplier orders: Use Get Supplier Purchase Orders for headers or Get Supplier Purchase Order Items for line items. Supply at least one filter, such as buyerANID or documentNumber. buyerANID identifies the buyer; it is not the supplier ANID in the connection setting. SAP allows at most 100 rows per $top page; advance $skip to read more. For date filtering, supply a SAP-compatible raw filterExpression with startDate and endDate; SAP limits that range to 31 days. See SAP's supplier filter and paging rules.

SAP's Procurement Reporting guide shows both filter and filters for the count endpoint in different examples. BotDojo currently sends filters; verify that count call against the approved API specification or tenant before relying on it. Supplier convenience filters follow SAP's unquoted examples and accept only simple values (letters, digits, ., _, /, or -); use a tenant-validated filterExpression for complex values. SAP's supplier guide describes $count=true as both count-only and inline, without a response example. BotDojo preserves a numeric count in either form and returns no rows for countOnly, but the exact response shape still needs tenant verification.