API Tokens: Issue, Expire, Revoke — Deep Dive addresses a problem most SAP landscapes know too well: Speed without masking and tokens invites data incidents that erase savings.

Masking preview and audit trails show what left the building; API Assign Users limits Basic Auth callers to named accounts.

Security spans field/row rules in REP, masking rule sets, API tokens and IP lists, rate limits, certificate upload, and trace — Zero Trust applied to integration, not bolted on after go-live.

Capabilities you use in iDataEngine

  • IP allow/block lists
  • Authenticated inbound integration endpoint
  • Field-level REP authorization
  • Masking rule sets import/export
  • Masking audit trail
  • API token login and expiry

Recommended workflow

  1. Save and capture the generated URL, job ID, or snapshot reference in your change record.
  2. Open the relevant cockpit (iDataView Explorer, SQL Project, API Service Detail, or AccessGuard).
  3. Configure source objects, fields, mappings, or rules using session language and customer/system context.
  4. Enable monitoring alerts and review dashboard KPIs for the first production cycle.

Real-world scenario (2024)

Payroll columns masked in SQL Transfer and omitted from API fieldset — same policy, two channels, one rule set.

Why it matters

A single over-exposed API column can dwarf savings from every low-code win. Field auth, masking, and tokens are how you keep speed without headline risk.

Your next step is a controlled pilot: Test in cockpit, save with evidence, then extend to the next channel without redesign.