API Tokens: Issue, Expire, Revoke — Deep Dive addresses a problem most SAP landscapes know too well: Speed without masking and tokens invites data incidents that erase savings.

Security spans field/row rules in REP, masking rule sets, API tokens and IP lists, rate limits, certificate upload, and trace — Zero Trust applied to integration, not bolted on after go-live.

Sensitive columns never rely on 'trust the integrator' — they rely on platform enforcement.

Capabilities you use in iDataEngine

  • Certificate upload validation
  • API token login and expiry
  • Rate limit per minute/hour
  • IP allow/block lists
  • Authenticated inbound integration endpoint
  • Field-level REP authorization

Recommended workflow

  1. Configure source objects, fields, mappings, or rules using session language and customer/system context.
  2. Enable monitoring alerts and review dashboard KPIs for the first production cycle.
  3. Run Test (iDataView Test, SQL First Row, API Test Service, or AG scan) before scheduling or publishing.
  4. Open the relevant cockpit (iDataView Explorer, SQL Project, API Service Detail, or AccessGuard).

Real-world scenario (2019)

Payroll columns masked in SQL Transfer and omitted from API fieldset — same policy, two channels, one rule set.

Why it matters

A single over-exposed API column can dwarf savings from every low-code win. Field auth, masking, and tokens are how you keep speed without headline risk.

Measured on lead time, defect rate, and audit readiness, the platform pays back in the first production quarter.