/sap-btp-connectivity
SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing
$ npx -y skills add secondsky/sap-skills --skill sap-btp-connectivity --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/sap-btp-connectivity
Context preview
The summary Claude sees to decide when to auto-load this skill.
SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing
SKILL.md
sap-btp-connectivity.SKILL.mdname: sap-btp-connectivity
description: "SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing OAuth and principal propagation, deploying connectivity proxies in Kubernetes/Kyma, troubleshooting connectivity errors (405, 407, 503), or configuring multitenancy."
license: GPL-3.0
metadata:
maintainer: "Eduard Jiglau"
maintainer_email: "hello@sap-ai-skills.com"
website: "https://sap-ai-skills.com"
version: "2.4.1"
last_verified: "2025-11-27"
keywords: [SAP BTP, Connectivity, Destination Service, Cloud Connector, Connectivity Proxy, Transparent Proxy, Kyma, Kubernetes, OAuth, Principal Propagation, RFC, LDAP, on-premise, hybrid connectivity, service channels, SOCKS5, reverse proxy, tunnel]
SAP BTP Connectivity Skill
Related Skills
- **sap-btp-cloud-platform**: Use for platform fundamentals, BTP account setup, and integration patterns
- **sap-btp-best-practices**: Use for implementation guidance, security best practices, and production deployment
- **sap-cap-capire**: Use for CAP service connectivity, destination consumption, and secure API access
- **sap-fiori-tools**: Use for configuring Fiori app destinations and frontend connectivity
- **sap-abap**: Use when connecting to ABAP systems via RFC or implementing principal propagation
When to Use This Skill
Use this skill when configuring BTP destinations, Cloud Connector, OAuth flows, principal propagation, RFC/LDAP/MAIL/TCP connectivity, Kubernetes/Kyma connectivity proxies, multitenant destination access, or troubleshooting connectivity errors such as 405, 407, 503, and proxy failures.
Table of Contents
1. [Overview](#overview) 2. [Quick Start](#quick-start) 3. [Connectivity Scenarios](#connectivity-scenarios) 4. [Destination Types](#destination-types) 5. [Authentication Configuration](#authentication-configuration) 6. [Cloud Connector Setup](#cloud-connector-setup) 7. [Kubernetes/Kyma Connectivity](#kuberneteskyma-connectivity) 8. [Common Issues & Troubleshooting](#common-issues--troubleshooting) 9. [Security Best Practices](#security-best-practices) 10. [Critical Rules](#critical-rules) 11. [Bundled Resources](#bundled-resources)
---
Overview
SAP BTP Connectivity provides secure access from SAP BTP applications to remote services across cloud, on-premise, and VPC environments.
Core Components
| Component | Purpose | |-----------|---------| | **Destination Service** | Manages connection metadata, authentication, routing | | **Connectivity Service** | Enables Kubernetes workloads via Cloud Connector | | **Cloud Connector** | Reverse proxy for secure on-premise tunneling | | **Connectivity Proxy** | Kubernetes component for on-premise access | | **Transparent Proxy** | Kubernetes component for unified destination access |
**Supported Environments**: Cloud Foundry, ABAP Environment, Kyma **Supported Protocols**: HTTP/HTTPS, RFC, TCP (SOCKS5), LDAP/LDAPS, Mail
---
Quick Start
Create HTTP Destination (Cloud Foundry)
1. Navigate: **Connectivity > Destinations** in BTP Cockpit 2. Select: **Create > From Scratch** 3. Configure:
Name: my-destination
Type: HTTP
URL: https://api.example.com
ProxyType: Internet
Authentication: OAuth2ClientCredentials
clientId: <your-client-id>
clientSecret: <your-client-secret>
tokenServiceURL: https://auth.example.com/oauth/token
Set Up Cloud Connector
1. Download from [SAP Tools](https://tools.hana.ondemand.com/#cloud) 2. Access: `https://localhost:8443` 3. Login: `Administrator` / `manage` (change immediately) 4. Add subaccount connection
Access Destination in Application (Node.js)
const { getDestination } = require('@sap-cloud-sdk/connectivity');
const destination = await getDestination({ destinationName: 'my-destination' });---
Connectivity Scenarios
Cloud-to-Cloud
ProxyType: Internet
Authentication: OAuth2ClientCredentials | OAuth2SAMLBearerAssertion
Cloud-to-On-Premise
ProxyType: OnPremise
Authentication: BasicAuthentication | PrincipalPropagation
Requires Cloud Connector installation in on-premise network.
On-Premise-to-Cloud (Service Channels)
For on-premise systems accessing SAP BTP services via Cloud Connector.
---
Destination Types
| Type | Use Case | ProxyType | Common Authentication | |------|----------|-----------|----------------------| | **HTTP** | REST/OData APIs | Internet/OnPremise | OAuth2, Basic, Certificates | | **RFC** | SAP systems | OnPremise | Basic, PrincipalPropagation | | **LDAP** | Directory services | Internet | Basic, NoAuth | | **MAIL** | Email protocols | Internet | Basic, NoAuth | | **TCP** | Generic TCP | OnPremise | Basic |
**Detailed configuration**: See `references/http-destinations.md`, `references/rfc-destinations.md`, `references/mail-tcp-ldap-destinations.md`
---
Authentication Configuration
OAuth2ClientCredentials (Service-to-Service)
Authentication: OAuth2ClientCredentials
clientId: <client-id>
clientSecret: <client-secret>
tokenServiceURL: https://auth.example.com/oauth/token
OAuth2SAMLBearerAssertion (User Propagation)
Authentication: OAuth2SAMLBearerAssertion
audience: <target-audience>
clientKey: <client-key>
tokenServiceURL: https://auth.example.com/oauth2/token
KeyStoreLocation: <certificate-location>
PrincipalPropagation (On-Premise SSO)
Authentication: PrincipalPropagation
ProxyType: OnPremise
Requires Cloud Connector X.509 certificate generation.
**Complete reference**: `references/authentication-types.md` (all 17+ types)
---
Cloud Connector Setup
Installation
- **Production**: Windows MSI/Linux RPM packages (service registration)
- **Development**: Portable archive (manual execution)
Initial Configuration
1. Acces
Read more
name: sap-btp-connectivity description: "SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing OAuth and principal propagation, deploying connectivity proxies in Kubernetes/Kyma, troubleshooting connectivity errors (405, 407, 503), or configuring multitenancy." license: GPL-3.0 metadata: maintainer: "Eduard Jiglau" maintainer_email: "hello@sap-ai-skills.com" website: "https://sap-ai-skills.com" version: "2.4.1" last_verified: "2025-11-27" keywords: [SAP BTP, Connectivity, Destination Service, Cloud Connector, Connectivity Proxy, Transparent Proxy, Kyma, Kubernetes, OAuth, Principal Propagation, RFC, LDAP, on-premise, hybrid connectivity, service channels, SOCKS5, reverse proxy, tunnel]
SAP BTP Connectivity Skill
Related Skills
- **sap-btp-cloud-platform**: Use for platform fundamentals, BTP account setup, and integration patterns
- **sap-btp-best-practices**: Use for implementation guidance, security best practices, and production deployment
- **sap-cap-capire**: Use for CAP service connectivity, destination consumption, and secure API access
- **sap-fiori-tools**: Use for configuring Fiori app destinations and frontend connectivity
- **sap-abap**: Use when connecting to ABAP systems via RFC or implementing principal propagation
When to Use This Skill
Use this skill when configuring BTP destinations, Cloud Connector, OAuth flows, principal propagation, RFC/LDAP/MAIL/TCP connectivity, Kubernetes/Kyma connectivity proxies, multitenant destination access, or troubleshooting connectivity errors such as 405, 407, 503, and proxy failures.
Table of Contents
1. [Overview](#overview) 2. [Quick Start](#quick-start) 3. [Connectivity Scenarios](#connectivity-scenarios) 4. [Destination Types](#destination-types) 5. [Authentication Configuration](#authentication-configuration) 6. [Cloud Connector Setup](#cloud-connector-setup) 7. [Kubernetes/Kyma Connectivity](#kuberneteskyma-connectivity) 8. [Common Issues & Troubleshooting](#common-issues--troubleshooting) 9. [Security Best Practices](#security-best-practices) 10. [Critical Rules](#critical-rules) 11. [Bundled Resources](#bundled-resources)
---
Overview
SAP BTP Connectivity provides secure access from SAP BTP applications to remote services across cloud, on-premise, and VPC environments.
Core Components
| Component | Purpose | |-----------|---------| | **Destination Service** | Manages connection metadata, authentication, routing | | **Connectivity Service** | Enables Kubernetes workloads via Cloud Connector | | **Cloud Connector** | Reverse proxy for secure on-premise tunneling | | **Connectivity Proxy** | Kubernetes component for on-premise access | | **Transparent Proxy** | Kubernetes component for unified destination access |
**Supported Environments**: Cloud Foundry, ABAP Environment, Kyma **Supported Protocols**: HTTP/HTTPS, RFC, TCP (SOCKS5), LDAP/LDAPS, Mail
---
Quick Start
Create HTTP Destination (Cloud Foundry)
1. Navigate: **Connectivity > Destinations** in BTP Cockpit 2. Select: **Create > From Scratch** 3. Configure:
Name: my-destination Type: HTTP URL: https://api.example.com ProxyType: Internet Authentication: OAuth2ClientCredentials clientId: <your-client-id> clientSecret: <your-client-secret> tokenServiceURL: https://auth.example.com/oauth/token
Set Up Cloud Connector
1. Download from [SAP Tools](https://tools.hana.ondemand.com/#cloud) 2. Access: `https://localhost:8443` 3. Login: `Administrator` / `manage` (change immediately) 4. Add subaccount connection
Access Destination in Application (Node.js)
const { getDestination } = require('@sap-cloud-sdk/connectivity');
const destination = await getDestination({ destinationName: 'my-destination' });---
Connectivity Scenarios
Cloud-to-Cloud
ProxyType: Internet Authentication: OAuth2ClientCredentials | OAuth2SAMLBearerAssertion
Cloud-to-On-Premise
ProxyType: OnPremise Authentication: BasicAuthentication | PrincipalPropagation
Requires Cloud Connector installation in on-premise network.
On-Premise-to-Cloud (Service Channels)
For on-premise systems accessing SAP BTP services via Cloud Connector.
---
Destination Types
| Type | Use Case | ProxyType | Common Authentication | |------|----------|-----------|----------------------| | **HTTP** | REST/OData APIs | Internet/OnPremise | OAuth2, Basic, Certificates | | **RFC** | SAP systems | OnPremise | Basic, PrincipalPropagation | | **LDAP** | Directory services | Internet | Basic, NoAuth | | **MAIL** | Email protocols | Internet | Basic, NoAuth | | **TCP** | Generic TCP | OnPremise | Basic |
**Detailed configuration**: See `references/http-destinations.md`, `references/rfc-destinations.md`, `references/mail-tcp-ldap-destinations.md`
---
Authentication Configuration
OAuth2ClientCredentials (Service-to-Service)
Authentication: OAuth2ClientCredentials clientId: <client-id> clientSecret: <client-secret> tokenServiceURL: https://auth.example.com/oauth/token
OAuth2SAMLBearerAssertion (User Propagation)
Authentication: OAuth2SAMLBearerAssertion audience: <target-audience> clientKey: <client-key> tokenServiceURL: https://auth.example.com/oauth2/token KeyStoreLocation: <certificate-location>
PrincipalPropagation (On-Premise SSO)
Authentication: PrincipalPropagation ProxyType: OnPremise
Requires Cloud Connector X.509 certificate generation.
**Complete reference**: `references/authentication-types.md` (all 17+ types)
---
Cloud Connector Setup
Installation
- **Production**: Windows MSI/Linux RPM packages (service registration)
- **Development**: Portable archive (manual execution)
Initial Configuration
1. Acces
40 SAP development plugins with evidence-tracked verification SAP development plugins for AI coding assistants, with public-source or package-registry verification tracked where available.
Repo: secondsky/sap-skills
Other skills on sap-skills.
- /sap-abap-cds
Comprehensive SAP ABAP CDS (Core Data Services) reference for data modeling, view development, and semantic enrichment. Use when creating CDS views or view entities, defining data models with annotations, working with associations and cardinality, implementing input parameters,
Open skill - /sap-abap
Comprehensive ABAP development skill for SAP systems. Use when writing ABAP code, working with internal tables, structures, ABAP SQL, object-oriented programming, RAP (RESTful Application Programming Model), CDS views, EML statements, ABAP Cloud development, string processing,
Open skill - /sap-ai-core
Guides development with SAP AI Core and SAP AI Launchpad for enterprise AI/ML workloads on SAP BTP. Use when: deploying generative AI models, building orchestration workflows with templating/filtering/grounding, implementing RAG with vector databases, managing ML training
Open skill - /sap-api-policy
Evidence-based assessment of whether an SAP API/interface usage scenario aligns with the SAP API Policy (v.4.2026a). Use whenever someone asks whether a way of calling SAP is allowed/compliant — e.g. Published API vs internal/private/"confidential" API status, "Documented Use",
Open skill - /sap-api-style
This skill provides comprehensive guidance for documenting SAP APIs following the SAP API Style Guide standards. It should be used when creating or reviewing API documentation for REST, OData, Java, JavaScript, .NET, or C/C++ APIs. The skill covers naming conventions,
Open skill - /sap-browser-automation
Use when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO reuse, isolated Edge profiles, deterministic target selection, screenshots, or browser bootstrap
Open skill

