You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SAP云身份服务中基于Issuer信任的令牌交换失败问题

SAP试用租户中基于Issuer信任的令牌交换场景支持问题及示例请求

问题概述

在SAP试用租户中遵循令牌交换文档,尝试通过「Configure Trust by Issuer」实现外部身份提供商(Entra ID)到SAP的令牌交换,流程失败,需确认该机器对机器(M2M)场景是否受支持。

操作流程及报错详情

1. 从Entra ID获取访问令牌

// @name loginEntraId
POST {{entraAuthorityUri}}/oauth2/v2.0/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials
&client_id={{entraIdClientId}}
&client_secret={{entraIdClientSecret}}
&scope={{entraIdClientId}}/.default

2. 向SAP发起令牌交换请求

@entratoken = {{loginEntraId.response.body.$.access_token}}

// @name loginSAP
POST {{SAPDomain}}:443/oauth2/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded

grant_type=urn:ietf:params:oauth:grant-type:token-exchange
&subject_token={{entratoken}}
&subject_token_type=urn:ietf:params:oauth:token-type:access_token
&requested_token_type=urn:ietf:params:oauth:token-type:access_token
&client_id={{SAPClientId}}
&client_secret={{SAPClientSecret}}
&resource=urn:sap:identity:application:provider:name:{{SAPApplicationDependency}}
&scope=openid

3. SAP返回错误响应

{
  "error": "invalid_client",
  "error_description": "Missing session for token."
}

该报错表明SAP无法识别无会话状态的M2M令牌交换流程(未使用交互式OpenID流程)。

4. 排查日志信息

state="aborted", action="login", objectType="thing", objectId="ba97661d-d9a0-4bbb-9243-8c6a20c8edce", message="No public client access allowed", appId="00b057c2-f564-4572-8f80-9b32d59e653e", category="audit.authentication", duration="12 ms", serviceProvider="test2", workflow="restApi", error="invalid_client"

已尝试的无效解决方法

  • 在SAP应用中开启Enable Public Client Flows,问题仍未解决
  • 常规client_credentials流程可正常运行,但不属于令牌交换场景,请求示例如下:
// @name loginSAP
POST {{SAPDomain}}:443/oauth2/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials
&client_id={{SAPClientId}}
&client_secret={{SAPClientSecret}}
&resource=urn:sap:identity:application:provider:name:{{SAPApplicationDependency}}

反向流程对比

将SAP令牌交换为Entra ID令牌的反向流程可正常执行,且Entra ID侧的令牌交换请求无需携带client_secret(仅基于Issuer信任即可),但SAP文档明确要求外部到SAP的令牌交换请求必须携带client_secret。

请求

恳请提供一个可行的外部身份提供商到SAP的基础令牌交换示例。


内容的提问来源于stack exchange,提问作者r3verse

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.11 22:13:12