All skills
secondsky avatar

/sap-btp-cloud-identity-services

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

SAP Cloud Identity Services for BTP applications: Identity Authentication (IAS), Identity Provisioning (IPS), and Authorization Management (AMS). Use when configuring authentication for BTP apps, setting up OIDC or SAML app registrations, federating corporate identity providers, establishing subaccount trust, provisioning users, writing AMS authorization policies, migrating from XSUAA to IAS-based authentication, or troubleshooting token and trust errors.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-btp-cloud-identity-services

This session only. Nothing lands on disk.

referencestroubleshooting.md

≈2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Troubleshooting — Complete Reference

Source: Monitoring and Troubleshooting, Getting Support, Configure Trust


Trust Configuration Errors

Error: "No trusted identity provider found"

Symptoms: Users see "No trusted identity provider found for the given request" when accessing an application.

Causes:

  1. The application's trust configuration is missing or incomplete
  2. The BTP subaccount has no trust to the IAS tenant
  3. The IAS application doesn't have the correct SP metadata or redirect URIs

Solutions:

  1. In IAS admin console, verify the application exists under Applications & Resources > Applications
  2. Check the trust configuration:
    • For SAML: Verify SP metadata is uploaded correctly
    • For OIDC: Verify redirect URIs match the application callback URL exactly
  3. In BTP cockpit, go to Security > Trust Configuration and verify the IAS tenant is listed
  4. If using the Identity service, rebind the service instance:
    cf unbind-service myapp my-identity
    cf bind-service myapp my-identity
    cf restage myapp

Error: "SAML assertion validation failed"

Symptoms: SAML assertion rejected by the service provider.

Causes:

  1. Clock drift between IAS and the service provider
  2. Assertion expired (default lifetime is short)
  3. Signing certificate mismatch

Solutions:

  1. Verify system clocks are synchronized (NTP)
  2. In IAS admin console, check assertion lifetime settings under the application's SAML configuration
  3. Verify the IAS signing certificate matches what the SP expects:
    • Download IAS signing certificate from Applications & Resources > Tenant Settings > SAML 2.0 Configuration
    • Upload to the service provider's trusted IdP certificates

Token Validation Failures

Error: "Invalid token" or "401 Unauthorized"

Symptoms: Backend service rejects the JWT token.

Diagnosis steps:

  1. Decode the JWT token (use jwt.io or base64 decode the payload)
  2. Check the following claims:
Claim Expected Value Common Issue
iss (issuer) https://<tenant>.accounts.ondemand.com Wrong issuer (XSUAA vs IAS)
aud (audience) The OAuth client ID Client ID mismatch after migration
exp (expiration) Future timestamp Token expired; check clock sync
sub (subject) User identifier Missing or incorrect subject mapping
scope Expected OAuth scopes Scopes not assigned in role collection

Error: "Audience mismatch"

Symptoms: Token aud claim doesn't include the expected client ID.

Causes:

  1. The application uses a different client ID than what's in the token
  2. Migration from XSUAA to Identity service changed the client ID
  3. The token was issued for a different IAS application

Solutions:

  1. Verify the binding credentials:
    cf env myapp
    # Check the clientid in VCAP_SERVICES
  2. Ensure the backend service validates against the correct audience
  3. If using multiple IAS applications, ensure the correct one is configured

Error: "Issuer mismatch"

Symptoms: Token iss claim doesn't match the expected issuer URL.

Causes:

  1. Migration from XSUAA to IAS changed the issuer URL
  2. Wrong IAS tenant is configured
  3. Custom domain configuration changes the issuer

Solutions:

  1. Update the application's expected issuer to match IAS:
    • XSUAA issuer: https://<subdomain>.authentication.<region>.hana.ondemand.com/oauth/token
    • IAS issuer: https://<tenant>.accounts.ondemand.com
  2. During migration, support both issuers during the transition period
  3. Check the Identity service binding credentials for the correct issuer URL

Redirect URI Errors

Error: "Invalid redirect URI" or "redirect_uri_mismatch"

Symptoms: After authentication, users see an error instead of being redirected back to the application.

Causes:

  1. The redirect URI in the IAS application doesn't match the callback URL
  2. Missing trailing slash or different protocol (http vs https)
  3. Port number mismatch

Solutions:

  1. In IAS admin console, go to the application > Trust > Redirect URIs
  2. Add all valid redirect URIs:
    https://myapp.cfapps.eu10.hana.ondemand.com/login/callback
    https://myapp.cfapps.eu10.hana.ondemand.com/
  3. Ensure exact match including protocol, host, path, and trailing slashes
  4. For the Identity service, configure redirect URIs in the service instance config

Missing Role Collections

Error: User has no access despite correct authentication

Symptoms: User authenticates successfully but gets 403 Forbidden on protected resources.

Causes:

  1. Role collections not assigned to the user
  2. Role templates not mapped correctly (XSUAA migration issue)
  3. AMS policies not assigned to the user's group

Solutions:

  1. In BTP cockpit, go to Security > Role Collections
  2. Verify the user has the required role collection assigned
  3. For AMS, check the IAS admin console > Authorization Policies for policy assignments
  4. Check user group membership in the Identity Directory

SAML vs OIDC Pitfalls

SAML-Specific Issues

Issue Solution
Name ID format mismatch Configure the expected format in IAS app > Subject Name Identifier
Assertion consumer URL wrong Update SP metadata or enter ACS URL manually
Attribute statements missing Configure user attributes in IAS app > Assertions
Session timeout too short Adjust in IAS app > Authentication > Session settings

OIDC-Specific Issues

Issue Solution
ID token missing claims Configure scopes in IAS app > Trust > Scopes
Access token too large Reduce claims; use reference tokens instead of JWT
Refresh token not issued Enable refresh tokens in IAS app > Trust
PKCE verification failed Ensure the approuter/client uses the correct code verifier

Provisioning Troubleshooting

Provisioning Job Stuck or Failed

  1. Check job logs in IPS admin console
  2. Verify source/target system connectivity
  3. Check for rate limits (configure ips.max.retry.count)
  4. Review transformation logs for mapping errors
  5. Enable ips.trace.failed.entity.requests for detailed failure logging

Users Not Syncing

  1. Verify the source system filter (ips.sql.condition) isn't too restrictive
  2. Check transformation mappings for required attributes
  3. Ensure the target system's SCIM endpoint is accessible
  4. Verify delta read is supported by the source system

Diagnostic Tools

IAS Admin Console

  • Monitoring > Audit Logs: Authentication events, configuration changes
  • Monitoring > Usage Statistics: Login metrics, application usage
  • Applications > [App] > Authentication: View authentication methods and logs

BTP Cockpit

  • Security > Trust Configuration: Verify IdP trust
  • Security > Role Collections: Verify role assignments
  • Instances and Subscriptions: Verify service bindings

Token Inspection

Decode JWT tokens to verify claims:

# Decode token payload
echo "<token-payload>" | base64 -d | jq .

Key claims to verify:

  • iss, aud, sub, exp, iat
  • scope, xs.user.attributes (XSUAA), user_attributes (IAS)
  • tenant (for multi-tenant apps)

Source: Getting Support

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill is a collection of reference documentation and integration patterns for SAP Cloud Identity Services (IAS, IPS, and AMS) on SAP BTP. It provides technical guidance for OIDC/SAML application registration, XSUAA migration, and authorization policy development without any executable code or malicious patterns.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2026-06-12",
  "documentation_source": "https://help.sap.com/docs/cloud-identity-services",
  "ias_docs": "https://github.com/SAP-docs/btp-cloud-identity-services",
  "integration_guide": "https://help.sap.com/viewer/b95c3d5bab324a3a8409eee5267a5b75/Cloud/en-US/27947dfb325047018603446439050a6b.html",
  "cap_ias_guide": "https://cap.cloud.sap/docs/guides/integration/platform/ias-xsuaa"
}

README badge

README badge for secondsky/sap-skills/sap-btp-cloud-identity-services