SAP Business ByDesign OAuth Scopes
SAP Business ByDesign publishes 1 OAuth 2.0 scope via the clientCredentials and saml2Bearer flows. Scopes are the fine-grained permissions an application requests at authorization time to act against the SAP Business ByDesign API on a user’s behalf.
Tokens are issued from https://{tenant}.bydesign.cloud.sap/sap/bc/sec/oauth2/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
OAuth endpoints
https://{tenant}.bydesign.cloud.sap/sap/bc/sec/oauth2/token
clientCredentialssaml2Bearer
Scopes (1)
| Scope | Description | Flows |
|---|---|---|
| UIWC:CC_HOME | Home work center scope. SAP's official guidance states selecting scope ID UIWC:CC_HOME "is sufficient for most use cases"; effective access to OData services is determined by the work centers assigned to the OAuth client and the propagated business user's authorizations. |
📄 Provider scope reference: https://github.com/SAP-samples/partner-reference-application/blob/main/Tutorials/35b-Multi-Tenancy-Provisioning-Connect-ByD.md
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.