API Tokens: Issue, Expire, Revoke — Deep Dive addresses a problem most SAP landscapes know too well: Speed without masking and tokens invites data incidents that erase savings.
Masking preview and audit trails show what left the building; API Assign Users limits Basic Auth callers to named accounts.
Security spans field/row rules in REP, masking rule sets, API tokens and IP lists, rate limits, certificate upload, and trace — Zero Trust applied to integration, not bolted on after go-live.
Capabilities you use in iDataEngine
- IP allow/block lists
- Authenticated inbound integration endpoint
- Field-level REP authorization
- Masking rule sets import/export
- Masking audit trail
- API token login and expiry
Recommended workflow
- Save and capture the generated URL, job ID, or snapshot reference in your change record.
- Open the relevant cockpit (iDataView Explorer, SQL Project, API Service Detail, or AccessGuard).
- Configure source objects, fields, mappings, or rules using session language and customer/system context.
- Enable monitoring alerts and review dashboard KPIs for the first production cycle.
Real-world scenario (2024)
Payroll columns masked in SQL Transfer and omitted from API fieldset — same policy, two channels, one rule set.
Why it matters
A single over-exposed API column can dwarf savings from every low-code win. Field auth, masking, and tokens are how you keep speed without headline risk.
Your next step is a controlled pilot: Test in cockpit, save with evidence, then extend to the next channel without redesign.