Skip to content
Development
Skill

/sap-btp-connectivity

SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing

From plugin
sap-skills
40440 skills31 agents69 commands8 MCP
Install
$ npx -y skills add secondsky/sap-skills --skill sap-btp-connectivity --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/sap-btp-connectivity

Context preview

The summary Claude sees to decide when to auto-load this skill.

SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing

SKILL.md

sap-btp-connectivity.SKILL.md
name: sap-btp-connectivity
description: "SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing OAuth and principal propagation, deploying connectivity proxies in Kubernetes/Kyma, troubleshooting connectivity errors (405, 407, 503), or configuring multitenancy."
license: GPL-3.0
metadata:
  maintainer: "Eduard Jiglau"
  maintainer_email: "hello@sap-ai-skills.com"
  website: "https://sap-ai-skills.com"
  version: "2.4.1"
  last_verified: "2025-11-27"
  keywords: [SAP BTP, Connectivity, Destination Service, Cloud Connector, Connectivity Proxy, Transparent Proxy, Kyma, Kubernetes, OAuth, Principal Propagation, RFC, LDAP, on-premise, hybrid connectivity, service channels, SOCKS5, reverse proxy, tunnel]

SAP BTP Connectivity Skill

Related Skills

  • **sap-btp-cloud-platform**: Use for platform fundamentals, BTP account setup, and integration patterns
  • **sap-btp-best-practices**: Use for implementation guidance, security best practices, and production deployment
  • **sap-cap-capire**: Use for CAP service connectivity, destination consumption, and secure API access
  • **sap-fiori-tools**: Use for configuring Fiori app destinations and frontend connectivity
  • **sap-abap**: Use when connecting to ABAP systems via RFC or implementing principal propagation

When to Use This Skill

Use this skill when configuring BTP destinations, Cloud Connector, OAuth flows, principal propagation, RFC/LDAP/MAIL/TCP connectivity, Kubernetes/Kyma connectivity proxies, multitenant destination access, or troubleshooting connectivity errors such as 405, 407, 503, and proxy failures.

Table of Contents

1. [Overview](#overview) 2. [Quick Start](#quick-start) 3. [Connectivity Scenarios](#connectivity-scenarios) 4. [Destination Types](#destination-types) 5. [Authentication Configuration](#authentication-configuration) 6. [Cloud Connector Setup](#cloud-connector-setup) 7. [Kubernetes/Kyma Connectivity](#kuberneteskyma-connectivity) 8. [Common Issues & Troubleshooting](#common-issues--troubleshooting) 9. [Security Best Practices](#security-best-practices) 10. [Critical Rules](#critical-rules) 11. [Bundled Resources](#bundled-resources)

---

Overview

SAP BTP Connectivity provides secure access from SAP BTP applications to remote services across cloud, on-premise, and VPC environments.

Core Components

| Component | Purpose | |-----------|---------| | **Destination Service** | Manages connection metadata, authentication, routing | | **Connectivity Service** | Enables Kubernetes workloads via Cloud Connector | | **Cloud Connector** | Reverse proxy for secure on-premise tunneling | | **Connectivity Proxy** | Kubernetes component for on-premise access | | **Transparent Proxy** | Kubernetes component for unified destination access |

**Supported Environments**: Cloud Foundry, ABAP Environment, Kyma **Supported Protocols**: HTTP/HTTPS, RFC, TCP (SOCKS5), LDAP/LDAPS, Mail

---

Quick Start

Create HTTP Destination (Cloud Foundry)

1. Navigate: **Connectivity > Destinations** in BTP Cockpit 2. Select: **Create > From Scratch** 3. Configure:

   Name: my-destination
   Type: HTTP
   URL: https://api.example.com
   ProxyType: Internet
   Authentication: OAuth2ClientCredentials
   clientId: <your-client-id>
   clientSecret: <your-client-secret>
   tokenServiceURL: https://auth.example.com/oauth/token

Set Up Cloud Connector

1. Download from [SAP Tools](https://tools.hana.ondemand.com/#cloud) 2. Access: `https://localhost:8443` 3. Login: `Administrator` / `manage` (change immediately) 4. Add subaccount connection

Access Destination in Application (Node.js)

const { getDestination } = require('@sap-cloud-sdk/connectivity');
const destination = await getDestination({ destinationName: 'my-destination' });

---

Connectivity Scenarios

Cloud-to-Cloud

ProxyType: Internet
Authentication: OAuth2ClientCredentials | OAuth2SAMLBearerAssertion

Cloud-to-On-Premise

ProxyType: OnPremise
Authentication: BasicAuthentication | PrincipalPropagation

Requires Cloud Connector installation in on-premise network.

On-Premise-to-Cloud (Service Channels)

For on-premise systems accessing SAP BTP services via Cloud Connector.

---

Destination Types

| Type | Use Case | ProxyType | Common Authentication | |------|----------|-----------|----------------------| | **HTTP** | REST/OData APIs | Internet/OnPremise | OAuth2, Basic, Certificates | | **RFC** | SAP systems | OnPremise | Basic, PrincipalPropagation | | **LDAP** | Directory services | Internet | Basic, NoAuth | | **MAIL** | Email protocols | Internet | Basic, NoAuth | | **TCP** | Generic TCP | OnPremise | Basic |

**Detailed configuration**: See `references/http-destinations.md`, `references/rfc-destinations.md`, `references/mail-tcp-ldap-destinations.md`

---

Authentication Configuration

OAuth2ClientCredentials (Service-to-Service)

Authentication: OAuth2ClientCredentials
clientId: <client-id>
clientSecret: <client-secret>
tokenServiceURL: https://auth.example.com/oauth/token

OAuth2SAMLBearerAssertion (User Propagation)

Authentication: OAuth2SAMLBearerAssertion
audience: <target-audience>
clientKey: <client-key>
tokenServiceURL: https://auth.example.com/oauth2/token
KeyStoreLocation: <certificate-location>

PrincipalPropagation (On-Premise SSO)

Authentication: PrincipalPropagation
ProxyType: OnPremise

Requires Cloud Connector X.509 certificate generation.

**Complete reference**: `references/authentication-types.md` (all 17+ types)

---

Cloud Connector Setup

Installation

  • **Production**: Windows MSI/Linux RPM packages (service registration)
  • **Development**: Portable archive (manual execution)

Initial Configuration

1. Acces

Read more
Ships withsap-skills

40 SAP development plugins with evidence-tracked verification SAP development plugins for AI coding assistants, with public-source or package-registry verification tracked where available.

Get the whole plugin

Other skills on sap-skills.