Enterprise SaaS and ERP
The SaaS and ERP connectors speak each vendor’s REST or OData API directly. They are not equally complete, so each section below says exactly what is built.
Summary
| Connector | Type spellings | Test | Explore | Extraction |
|---|---|---|---|---|
| SAP (OData) | sap | No live probe | Yes ($metadata) | Not yet: row reads are not built |
| Salesforce | salesforce | Live (OAuth token request) | Yes | SOQL query with paging |
| Guidewire | guidewire | Live (/rest/apis) | Yes | Cloud API resource reads with paging |
| ServiceNow | servicenow | Live (Table API request) | No catalogue read | Fixed Table API tables |
| Dynamics 365 | d365, dynamics365, dynamics | No live probe | No | Not implemented |
| HubSpot | hubspot | No live probe | No | Not implemented |
| SharePoint | sharepoint | No live probe | No | Not implemented |
| Google Workspace | gmail, google_sheets, google_docs (fetch only) | Not available | No | Gmail, Sheets and Docs reads during a fetch |
For a type with no live probe, Test returns success: true with
live_check_performed: false, which means the configuration was saved and
nothing was verified. See Connections and credentials.
All HTTP-based connectors here dial through FACE’s hardened HTTP client. It uses no proxy, applies the address policy, and follows at most 5 redirects, all to the same host. A redirect to a different host is refused, so a credential never travels to a host the connection did not name.
SAP (OData / CSDL)
SAP connections describe an SAP system through SAPConnectionConfig (system_id,
client, username, password, host, system_number). Those are RFC and SAP
GUI destination parameters. OData discovery is driven by connection
properties:
| Property | Meaning |
|---|---|
odata_url (also odata_base_url, odata_service_url, service_url, base_url, endpoint, url) | The OData service root. http:// is assumed when no scheme is given. The URL must not contain user:pass@. |
odata_service_path (also service_path, service) | Appended to the service root |
sap_client (also sap-client, mandt, client) | Sent as the sap-client query parameter |
sap_gateway_url | Instead of one service: the Gateway origin, whose OData V2 service catalogue is enumerated |
Credentials: username (setting or credential), and password (also api_key,
token or secret) from the credential bundle. Internal addresses are allowed by
default, because SAP systems usually live on private networks.
- Explore. One
GETof the service’s$metadata, capped at 16 MiB.- Entity sets become datasets of kind
entityset, qualified by the CSDL namespace. - Properties keep their document order and the service’s own type spelling
(for example
Edm.Decimal(13,3)). - Literal units come from
Measures.Unit/ISOCurrency, and PII flags fromPersonalData.IsPotentiallyPersonal. Validation.AllowedValuesbecomes a vocabulary (up to 128 values). It is always reported as incomplete, because CSDL does not enforce it.- Nullability is reported only where the document states it.
- No row counts are requested.
- Entity sets become datasets of kind
- Test. There is no live probe. Explore is the reachability check.
- Extraction. Not built yet. A fetch returns an error saying that the OData entity-set reader is not built and that the DDIC path needs the NetWeaver RFC SDK.
Salesforce
| Config message | SalesforceConnectionConfig: login_url, client_id |
| Credentials | username, password, security_token (appended to the password), client_secret |
| Auth | OAuth 2.0 username–password flow against <login_url>/services/oauth2/token |
| Properties | soql (the query a fetch runs), api_version (default v60.0; must match vNN.N), max_records / max_rows, include_deleted (uses queryAll) |
| Internal addresses | Refused by default |
- Test posts the token request to the login host. A success means the
credentials were accepted. Discovery and queries then dial the
instance_urlthat the token response names. - Extraction runs one SOQL statement, either the query you pass or the
connection’s
soqlproperty. The connector does not choose objects for you. It followsnextRecordsUrlon the same host only.- Rows: default 5,000, at most 50,000.
- Paging: at most 200 pages within a 3-minute budget.
- A response that contradicts itself (
donewith a next page, or not done without one) is refused rather than returned short.
- Explore reads the org’s version list, then Describe Global, then a
describe per object:
- Up to 200 objects get column detail. The rest are listed without columns, and the reason says how many.
- Picklists become vocabularies (up to 512 values). A vocabulary is marked complete only when the org flags the picklist as restricted.
- Lookup targets appear in the declared type as
reference(Account). - No row counts are requested, to protect your metered API allocation.
Guidewire
| Config message | GuidewireConnectionConfig: base_url (the Cloud API root), tenant_id |
| Credentials | username and password, sent as HTTP Basic |
| Properties | resource (also route, path): the route a fetch reads. max_records / max_rows. |
| Internal addresses | Allowed by default |
- Test calls
/rest/apisand requires a non-empty API list. - Extraction reads one resource (the query or
resource) inside thebase_urlpath. A route that escapes the base path is refused.- Page size: 200 by default, 500 maximum.
- Rows: 5,000 by default, 50,000 maximum.
- Paging: at most 200 pages within 3 minutes.
links.nextis followed on the same host only. - A 200 response without Guidewire’s
dataenvelope is refused rather than read as empty.
- Explore enumerates
/rest/apis, the per-API OpenAPI documents and the typelists. Typelist vocabularies are marked complete when the codes served match the count the index declares. - The connector speaks HTTP Basic, which is what self-managed installations use.
ServiceNow
ServiceNow settings are read from connection properties: systemUrl (the
instance URL). The credentials are username and password (HTTP Basic).
Internal addresses are refused by default.
- Extraction reads the Table API tables
syslog,syseventandsys_audit, with an 8 MiB cap per response. - Test requests the first of those tables.
- Explore returns
supported=false. The ServiceNow dictionary tables are not read yet.
Dynamics 365, HubSpot, SharePoint
These types resolve and their settings are validated, but no call is made to a live API:
| Connector | Config message and required settings | Execute returns |
|---|---|---|
| Dynamics 365 | D365ConnectionConfig: base_url, tenant_id, client_id | D365 connector for … not yet implemented against a live Dataverse/Graph API (requires MSAL credentials) |
| HubSpot | HubspotConnectionConfig; credential api_key | Hubspot connector not yet implemented against a live API (requires OAuth/PAT) |
| SharePoint | SharePointConnectionConfig: site_url, tenant_id, client_id | SharePoint connector for site … not yet implemented against a live Microsoft Graph API (requires MSAL credentials) |
For each of these, Test reports live_check_performed: false and Explore returns
supported=false.
Google Workspace
Google Workspace is read only during a fetch, through three connection types.
These types are not in the connector registry, so Test reports
Unknown connection type for them and Explore is not available.
| Type | What a fetch reads | Settings |
|---|---|---|
gmail | Up to 5 messages matching the fetch command as a Gmail query (label:INBOX when the command is fetch) | — |
google_sheets | One range of one spreadsheet | properties spreadsheet_id (falls back to the connection name) and range (default A1:Z50) |
google_docs | The text of one document | property document_id (falls back to the connection name) |
Credentials: google_service_account_json. Without it, the instance-wide Google
integration configured in Settings is used. The type is matched case-insensitively but otherwise exactly
(google_sheets, not Google Sheets).