Skip to content
Enterprise SaaS and ERP

Enterprise SaaS and ERP

The SaaS and ERP connectors speak each vendor’s REST or OData API directly. They are not equally complete, so each section below says exactly what is built.

Summary

ConnectorType spellingsTestExploreExtraction
SAP (OData)sapNo live probeYes ($metadata)Not yet: row reads are not built
SalesforcesalesforceLive (OAuth token request)YesSOQL query with paging
GuidewireguidewireLive (/rest/apis)YesCloud API resource reads with paging
ServiceNowservicenowLive (Table API request)No catalogue readFixed Table API tables
Dynamics 365d365, dynamics365, dynamicsNo live probeNoNot implemented
HubSpothubspotNo live probeNoNot implemented
SharePointsharepointNo live probeNoNot implemented
Google Workspacegmail, google_sheets, google_docs (fetch only)Not availableNoGmail, Sheets and Docs reads during a fetch

For a type with no live probe, Test returns success: true with live_check_performed: false, which means the configuration was saved and nothing was verified. See Connections and credentials.

All HTTP-based connectors here dial through FACE’s hardened HTTP client. It uses no proxy, applies the address policy, and follows at most 5 redirects, all to the same host. A redirect to a different host is refused, so a credential never travels to a host the connection did not name.

SAP (OData / CSDL)

SAP connections describe an SAP system through SAPConnectionConfig (system_id, client, username, password, host, system_number). Those are RFC and SAP GUI destination parameters. OData discovery is driven by connection properties:

PropertyMeaning
odata_url (also odata_base_url, odata_service_url, service_url, base_url, endpoint, url)The OData service root. http:// is assumed when no scheme is given. The URL must not contain user:pass@.
odata_service_path (also service_path, service)Appended to the service root
sap_client (also sap-client, mandt, client)Sent as the sap-client query parameter
sap_gateway_urlInstead of one service: the Gateway origin, whose OData V2 service catalogue is enumerated

Credentials: username (setting or credential), and password (also api_key, token or secret) from the credential bundle. Internal addresses are allowed by default, because SAP systems usually live on private networks.

  • Explore. One GET of the service’s $metadata, capped at 16 MiB.
    • Entity sets become datasets of kind entityset, qualified by the CSDL namespace.
    • Properties keep their document order and the service’s own type spelling (for example Edm.Decimal(13,3)).
    • Literal units come from Measures.Unit / ISOCurrency, and PII flags from PersonalData.IsPotentiallyPersonal.
    • Validation.AllowedValues becomes a vocabulary (up to 128 values). It is always reported as incomplete, because CSDL does not enforce it.
    • Nullability is reported only where the document states it.
    • No row counts are requested.
  • Test. There is no live probe. Explore is the reachability check.
  • Extraction. Not built yet. A fetch returns an error saying that the OData entity-set reader is not built and that the DDIC path needs the NetWeaver RFC SDK.

Salesforce

Config messageSalesforceConnectionConfig: login_url, client_id
Credentialsusername, password, security_token (appended to the password), client_secret
AuthOAuth 2.0 username–password flow against <login_url>/services/oauth2/token
Propertiessoql (the query a fetch runs), api_version (default v60.0; must match vNN.N), max_records / max_rows, include_deleted (uses queryAll)
Internal addressesRefused by default
  • Test posts the token request to the login host. A success means the credentials were accepted. Discovery and queries then dial the instance_url that the token response names.
  • Extraction runs one SOQL statement, either the query you pass or the connection’s soql property. The connector does not choose objects for you. It follows nextRecordsUrl on the same host only.
    • Rows: default 5,000, at most 50,000.
    • Paging: at most 200 pages within a 3-minute budget.
    • A response that contradicts itself (done with a next page, or not done without one) is refused rather than returned short.
  • Explore reads the org’s version list, then Describe Global, then a describe per object:
    • Up to 200 objects get column detail. The rest are listed without columns, and the reason says how many.
    • Picklists become vocabularies (up to 512 values). A vocabulary is marked complete only when the org flags the picklist as restricted.
    • Lookup targets appear in the declared type as reference(Account).
    • No row counts are requested, to protect your metered API allocation.

Guidewire

Config messageGuidewireConnectionConfig: base_url (the Cloud API root), tenant_id
Credentialsusername and password, sent as HTTP Basic
Propertiesresource (also route, path): the route a fetch reads. max_records / max_rows.
Internal addressesAllowed by default
  • Test calls /rest/apis and requires a non-empty API list.
  • Extraction reads one resource (the query or resource) inside the base_url path. A route that escapes the base path is refused.
    • Page size: 200 by default, 500 maximum.
    • Rows: 5,000 by default, 50,000 maximum.
    • Paging: at most 200 pages within 3 minutes. links.next is followed on the same host only.
    • A 200 response without Guidewire’s data envelope is refused rather than read as empty.
  • Explore enumerates /rest/apis, the per-API OpenAPI documents and the typelists. Typelist vocabularies are marked complete when the codes served match the count the index declares.
  • The connector speaks HTTP Basic, which is what self-managed installations use.

ServiceNow

ServiceNow settings are read from connection properties: systemUrl (the instance URL). The credentials are username and password (HTTP Basic). Internal addresses are refused by default.

  • Extraction reads the Table API tables syslog, sysevent and sys_audit, with an 8 MiB cap per response.
  • Test requests the first of those tables.
  • Explore returns supported=false. The ServiceNow dictionary tables are not read yet.

Dynamics 365, HubSpot, SharePoint

These types resolve and their settings are validated, but no call is made to a live API:

ConnectorConfig message and required settingsExecute returns
Dynamics 365D365ConnectionConfig: base_url, tenant_id, client_idD365 connector for … not yet implemented against a live Dataverse/Graph API (requires MSAL credentials)
HubSpotHubspotConnectionConfig; credential api_keyHubspot connector not yet implemented against a live API (requires OAuth/PAT)
SharePointSharePointConnectionConfig: site_url, tenant_id, client_idSharePoint connector for site … not yet implemented against a live Microsoft Graph API (requires MSAL credentials)

For each of these, Test reports live_check_performed: false and Explore returns supported=false.

Google Workspace

Google Workspace is read only during a fetch, through three connection types. These types are not in the connector registry, so Test reports Unknown connection type for them and Explore is not available.

TypeWhat a fetch readsSettings
gmailUp to 5 messages matching the fetch command as a Gmail query (label:INBOX when the command is fetch)—
google_sheetsOne range of one spreadsheetproperties spreadsheet_id (falls back to the connection name) and range (default A1:Z50)
google_docsThe text of one documentproperty document_id (falls back to the connection name)

Credentials: google_service_account_json. Without it, the instance-wide Google integration configured in Settings is used. The type is matched case-insensitively but otherwise exactly (google_sheets, not Google Sheets).