plugins/sap-btp-cloud-platform/skills/sap-btp-cloud-platform/SKILL.md
Comprehensive SAP Business Technology Platform (BTP) reference for cloud development, deployment, and operations. Use when setting up BTP accounts, working with Cloud Foundry environment, deploying to Kyma (Kubernetes, serverless), developing in ABAP environment (RAP, CDS), managing entitlements and quotas, configuring identity providers (XSUAA), using btp CLI or CF CLI, deploying multi-target applications (MTA), setting up connectivity (destinations, Cloud Connector), implementing CI/CD pipelines, extending SAP solutions, or troubleshooting BTP services. Covers all three runtime environments.
npx skillsauth add secondsky/sap-skills sap-btp-cloud-platformInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when setting up or operating SAP BTP accounts, directories, subaccounts, Cloud Foundry, Kyma, ABAP Environment, entitlements, quotas, role collections, CLI tooling, MTA deployments, connectivity, CI/CD, extensions, or platform troubleshooting.
btp and cf CLI examples in Tools for repeatable setup.sap-cap-capire, sap-fiori-tools, sap-btp-connectivity, or sap-btp-service-manager.Comprehensive reference for SAP Business Technology Platform covering all runtime environments, account management, security, and operations.
Documentation Source: https://github.com/SAP-docs/sap-btp-cloud-platform SAP Help Portal: https://help.sap.com/docs/btp SAP Discovery Center: https://discovery-center.cloud.sap/
SAP BTP integrates five technology portfolios: Application Development, Process Automation, Integration, Data & Analytics, and AI. Provides suite qualities: SAP Fiori UX, Cloud Identity Services, Master Data Integration, embedded analytics, SAP Task Center, and SAP Cloud ALM.
Global Account → Directory (optional) → Subaccount (region-specific)
↓ CF: Org → Spaces
↓ Kyma: Cluster → Namespaces
↓ ABAP: System instance
SAP BTP offers four runtime environments at the subaccount level:
Open PaaS with polyglot support. Features: multiple buildpacks (Java, Node.js, Python, Go, PHP), spaces for separation, auto-scaling, SAP HANA integration.
cf login -a https://api.cf.<region>.hana.ondemand.com
cf push my-app
cf bind-service my-app my-service-instance
Structure: Subaccount → Org (1:1) → Spaces
Managed Kubernetes runtime based on open-source Kyma.
Cloud ABAP development with RAP, CDS, SAP Fiori integration, ADT, 1:1 SAP HANA database per system. Use Cases: Extend S/4HANA Cloud, build new cloud applications, transform ABAP custom code
Status: Sunsetting December 31, 2028. Recommendation: Migrate to CF/Kyma.
Access all eligible services with flexible usage. Flavors: SAP BTPEA, CPEA, Pay-As-You-Go. Benefits: Switch services on/off, access current and future services.
Fixed cost for selected services, pay irrespective of consumption. Additional services require contract modification.
Best Practice: Use consumption-based for pilots, subscription for stable workloads.
Global Account → Directory (reserves) → Subaccount (consumes) → CF Space (optional)
| Provider | Examples | |----------|----------| | SAP | eu10, us10, ap10 | | AWS | eu10, us10, ap10, ap11, ap12 | | Azure | eu20, us20, ap20, jp20 | | Google Cloud | us30, in30 | | Alibaba Cloud | cn40 |
Multi-AZ deployment for high availability:
| Type | Description | Example | |------|-------------|---------| | Platform Users | Manage BTP infrastructure | Developers, administrators | | Business Users | Use deployed applications | End users, customers |
| Provider | Use Case | |----------|----------| | SAP ID Service | Default, SAP community users | | SAP Cloud Identity Services | Recommended for production | | Corporate IdP | Via Identity Authentication proxy |
Identity Provider
↓
SAP BTP (Shadow Users)
↓
Role Collections
↓
Application/Service Access
# btp CLI
btp login --url https://cpcli.cf.<region>.hana.ondemand.com
btp list accounts/subaccount
btp create accounts/subaccount --display-name "Dev"
btp assign security/role-collection "Subaccount Administrator" --to-user [email protected]
# CF CLI
cf login -a https://api.cf.<region>.hana.ondemand.com
cf target -o my-org -s my-space
cf push my-app
cf bind-service my-app my-service
# kubectl
kubectl get pods -n my-namespace
kubectl apply -f deployment.yaml
kubectl logs -f deployment/my-app
Recommended: Corporate IdP → SAP Cloud Identity Services → SAP BTP
XSUAA provides OAuth 2.0 authorization, role-based access control, and application security descriptors (xs-security.json).
Connect to remote systems without hardcoding URLs. Key authentication methods:
NoAuthentication (public APIs)OAuth2ClientCredentials (service-to-service)OAuth2SAMLBearerAssertion (user propagation)PrincipalPropagation (on-premise with Cloud Connector)Secure tunnel for on-premise connectivity with no inbound firewall ports, fine-grained access control, RFC/HTTP support, and principal propagation.
Package multiple modules for deployment. Core structure includes modules (app types: nodejs, html5) and resources (services like hana).
Single entry point providing static content serving, user authentication, URL rewriting, and request forwarding to microservices.
Managed service supporting Cloud Foundry apps (Fiori, CAP), SAP Fiori for ABAP Platform, and SAP Integration Suite artifacts.
Build loosely coupled extensions: SAP Solution → APIs & Events → SAP BTP Extension → Custom Business Logic
For detailed guidance, see the 13 reference files:
references/glossary.md - Complete terminology (40+ terms)references/cloud-foundry.md - CF development and administrationreferences/kyma.md - Kyma runtime and Kubernetes patternsreferences/abap.md - ABAP environment, RAP, CDSreferences/security.md - Authentication, authorization, identityreferences/connectivity.md - Destinations, Cloud Connectorreferences/development.md - Development patterns, MTA, Application Routerreferences/administration.md - Account management, btp CLIreferences/operations.md - Monitoring, alerting, loggingreferences/extensions.md - SAP solution extensions, formationsreferences/tools.md - CLI references, development toolsreferences/troubleshooting.md - Common issues and solutionsreferences/regions-endpoints.md - Region-specific API endpointsLast Verified: 2025-11-27
tools
Use when automating SAP BW query inspection, InfoProvider metadata reads (characteristics, key figures), metadata-verified specification review, unsaved draft preparation, or human-confirmed query draft population through Eclipse or HANA Studio with BW Modeling Tools.
tools
Use when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO reuse, isolated Edge profiles, deterministic target selection, screenshots, or browser bootstrap recovery is required.
tools
Evidence-based assessment of whether an SAP API/interface usage scenario aligns with the SAP API Policy (v.4.2026a). Use whenever someone asks whether a way of calling SAP is allowed/compliant — e.g. Published API vs internal/private/"confidential" API status, "Documented Use", whether a third-party tool / iPaaS / middleware / RPA bot / AI agent / MCP server may call SAP APIs, agentic or generative-AI access to SAP, bulk data extraction or replication into a lake/warehouse, custom Z/Y OData or RFC/BAPI wrappers and Clean Core, ADT/developer-tooling boundaries, ODP-RFC and other "not permitted" interfaces, partner Integration Certification, or RISE integration remediation. Trigger even when the policy is not named, e.g. "are we allowed to…", "is it compliant to…", "can we connect X to SAP…", "will this break under the new API policy". Produces a sourced technical assessment with a confidence level — explicitly NOT legal advice and NOT a final SAP compliance decision.
development
SAP-RPT-1-OSS local tabular prediction workflows for FI/CO prototype datasets. Use when preparing SAP finance CSV exports for classification or regression experiments with source-verified setup, leakage checks, and governance review.