SAP SuccessFactors
Service ID: sap-successfactors
SAP SuccessFactors is the global provider of cloud-based Human Experience Management (HXM) software. Our HR application suite integrates onboarding, social business and collaboration tools, a learning management system (LMS), performance management, recruiting software, applicant tracking software, succession planning, talent management, and HR analytics to deliver business strategy alignment, team execution, and maximum people performance to organizations of all sizes across more than 60 industries, in over 200 countries and territories.
At a Glance
- Difficulty
- 🔧ADVANCEDCustom SAML2-Bearer Auth + Multi-Step Admin Setup (OAuth Client Registration + X.509 Certificate)
- Authentication
- OAuth 2.0Custom OAuth 2.0 SAML2-Bearer assertion signed with an X.509 certificate — not a standard OAuth consent flow.
- Webhooks
- Virtual webhooks — polling for hris.employee.* plus ats.applicant.*, ats.application.* and ats.job.* events; SuccessFactors sends no native push.
- Partnership Required
- No(Not required — a consumer connects their existing SuccessFactors instance with credentials from their own tenant.)
- Partnership Application
- SAP PartnerEdge — Build track↗
- Apideck Credentials
- Not available(Not available — each connection uses OAuth client credentials created in the consumer's own SuccessFactors tenant.)
- Costs
- No separate API fee from Apideck. SAP does not publish SuccessFactors API or licensing pricing.
- Sandbox Availability
- Not available(No self-serve sandbox — testing runs against the consumer's own SuccessFactors test instance.)
- Account Type Required
- SuccessFactors instance with OData API access enabled — Employee Central for HRIS, Recruiting for ATS.
- Consumer Access Level
- Admin Center access sufficient to register an OAuth2 Client Application, bind the technical user to it, and upload the X.509 certificate.
- Rate Limits
- Apideck enforces 40 requests/second per connection.
Responsibility matrix
| Task | You (Customer) | Your Consumer | Apideck |
|---|---|---|---|
| Apply for SAP PartnerEdge (for demo or test instances) | ✓ (if needed) | — | Support available |
| Register OAuth Client & Upload X.509 Certificate | — | ✓ (Administrator) | Instructions provided |
| Provide API Server, Company ID, Username, API Key & Private Key | Shares requirements | ✓ | — |
| Authorize Connection (Vault) | Implements Vault | ✓ Enters credentials | Signs SAML assertion, handles tokens |
| Build via Unified API | ✓ | — | Maintains connector |
| Connection Sync | — | — | ✓ Polls via virtual webhooks |
| Monitor Connections | ✓ Via dashboard | ✓ Can revoke the OAuth client | Logs & alerts |
Environments
- Test/Demo
- Development and testing against the consumer's own SuccessFactors test instance (often on the preview release cycle), or against a partner demo instance requested through SAP's Demo Request Tool — a path that requires SAP PartnerEdge membership plus a provisioning account. Credentials are an OAuth client registered in that instance, with its own API server and Company ID.
- Production
- Live HR and recruiting data. Credentials are an OAuth client registered in the production instance — each instance has its own API server, Company ID and registered client, and there is no shared sandbox with generic credentials. Development credentials CANNOT be used with production accounts.
🚨Important to Know About SAP SuccessFactors
- An existing SAP contract usually already includes a test instance, which connects fine — but provisioning a brand-new test or demo tenant requires certified SAP partner status, so an organization not already running SuccessFactors has no path to a first tenant.
- SAP applies tenant-wide soft rate limits with Retry-After responses across OData v2, REST and SOAP as of its 2608 release (effective 17 August 2026); exact thresholds are published only behind an SAP for Me login.
📦
3 supported resources
View field mappings, supported operations, and schema details