plugins/sap-cloud-sdk-ai-python/skills/sap-cloud-sdk-ai-python/SKILL.md
Integrates the SAP Cloud SDK for AI for Python (sap-ai-sdk-gen, formerly generative-ai-hub-sdk) into Python applications. Use when building Python apps with SAP AI Core, Generative AI Hub, or the Orchestration Service: chat completion, embeddings, streaming, LangChain integration, templating, content filtering, data masking, and document grounding. Supports OpenAI GPT models, Llama, Gemini, Amazon Nova, and other foundation models via SAP BTP.
npx skillsauth add secondsky/sap-skills sap-cloud-sdk-ai-pythonInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Package rename: The PyPI package
generative-ai-hub-sdkis deprecated (v4.12.4 is the last release). Its successor issap-ai-sdk-gen(currently v6.10.0 per public PyPI registry evidence from 2026-06-15). Code and tutorials referencinggenerative-ai-hub-sdkshould migrate tosap-ai-sdk-gen; the import name remainsgen_ai_hub.
The official Python SDK for SAP Generative AI Hub and Orchestration Service. It wraps the native SDKs of model providers (OpenAI, Amazon Bedrock, Google GenAI) and offers a harmonised LangChain integration and a full Orchestration client — all routed through SAP AI Core with unified authentication. Package freshness is registry-verified; AI Core runtime behavior and exact model availability still require target-tenant validation.
If your task involves working inside Databricks (notebooks, Unity Catalog, Spark, SAP Databricks in SAP Business Data Cloud), consider installing the Databricks agent skills plugin. Ask whether you would like help installing it — never install unprompted.
Use this skill when:
gen_ai_hub Python package (installed as sap-ai-sdk-gen)generative-ai-hub-sdk to sap-ai-sdk-genfrom gen_ai_hub.proxy.native.openai import chat
messages = [
{"role": "system", "content": "You are a helpful assistant."},
{"role": "user", "content": "What is SAP BTP?"}
]
response = chat.completions.create(
model_name="gpt-4o-mini",
messages=messages
)
print(response.choices[0].message.content)
from gen_ai_hub.orchestration_v2 import (
OrchestrationConfig, OrchestrationService,
ModuleConfig, PromptTemplatingModuleConfig,
Template, UserMessage, LLMModelDetails
)
config = OrchestrationConfig(
modules=ModuleConfig(
prompt_templating=PromptTemplatingModuleConfig(
prompt=Template(
template=[UserMessage(role="user", content="{{?question}}")]
),
model=LLMModelDetails(name="gpt-4o-mini")
)
)
)
service = OrchestrationService(config=config)
response = service.run(placeholder_values={"question": "What is SAP?"})
print(response.final_result.choices[0].message.content)
# All providers + LangChain support
pip install "sap-ai-sdk-gen[all]"
# Default (OpenAI only, no LangChain)
pip install sap-ai-sdk-gen
# Specific providers (without LangChain)
pip install "sap-ai-sdk-gen[google, amazon]"
The SDK reads credentials via AICoreV2Client.from_env(), which resolves
credentials in this order:
GenAIHubProxyClient(...)AICORE_CLIENT_ID, AICORE_CLIENT_SECRET,
AICORE_AUTH_URL, AICORE_BASE_URL, AICORE_RESOURCE_GROUP$AICORE_HOME/config.json (or path set by AICORE_CONFIG);
use AICORE_PROFILE to select a named profileexport AICORE_CLIENT_ID="sb-..."
export AICORE_CLIENT_SECRET="..."
export AICORE_AUTH_URL="https://<tenant>.authentication.sap.hana.ondemand.com/oauth/token"
export AICORE_BASE_URL="https://api.ai.prod.eu-central-1.aws.ml.hana.ondemand.com/v2"
export AICORE_RESOURCE_GROUP="default"
# ~/.aicore/config.json
{
"AICORE_CLIENT_ID": "sb-...",
"AICORE_CLIENT_SECRET": "...",
"AICORE_AUTH_URL": "https://<tenant>.authentication.sap.hana.ondemand.com/oauth/token",
"AICORE_BASE_URL": "https://api.ai.prod.eu-central-1.aws.ml.hana.ondemand.com/v2",
"AICORE_RESOURCE_GROUP": "default"
}
For detailed auth setup and troubleshooting, see references/getting-started-auth.md.
| Module | Import Path | Purpose |
|--------|-------------|---------|
| Proxy (native clients) | gen_ai_hub.proxy.native.* | Direct model access per provider |
| LangChain integration | gen_ai_hub.proxy.langchain | init_llm, init_embedding_model, ChatOpenAI, etc. |
| Orchestration | gen_ai_hub.orchestration_v2 | Templating, filtering, masking, grounding |
| Document Grounding | gen_ai_hub.document_grounding | Pipeline, Vector, Retrieval APIs |
| Prompt Registry | gen_ai_hub.prompt_registry | Template management and config storage |
| Evaluations | gen_ai_hub.evaluations | Model evaluation runs and metrics |
| SAP RPT-1 | gen_ai_hub.proxy.native.sap | Tabular prediction (classification, regression) |
| Provider | Import | Key Classes |
|----------|--------|-------------|
| OpenAI | gen_ai_hub.proxy.native.openai | OpenAI, completions, chat, embeddings, responses |
| Amazon Bedrock | gen_ai_hub.proxy.native.amazon | Session, ClientWrapper |
| Google GenAI | gen_ai_hub.proxy.native.google_genai | Client |
| SAP RPT-1 | gen_ai_hub.proxy.native.sap | RPTClient, RPTRequest |
The Generative AI Hub catalog includes models from multiple providers. Check SAP's model catalog and the target tenant catalog for the authoritative model IDs. Example families:
| Provider | Example Families | |----------|------------------| | OpenAI | GPT-family chat, multimodal, reasoning, and embedding models | | Anthropic (via Bedrock) | Claude-family models | | Amazon | Nova/Titan-family models | | Google | Gemini-family models | | Mistral | Mistral-family models | | SAP | RPT-family tabular prediction models where enabled |
from gen_ai_hub.proxy.native.openai import OpenAI
client = OpenAI()
response = client.chat.completions.create(
model="gpt-4o-mini",
messages=[{"role": "user", "content": "Explain CAP in one paragraph."}]
)
print(response.choices[0].message.content)
from gen_ai_hub.proxy.native.openai import OpenAI
client = OpenAI()
stream = client.chat.completions.create(
model="gpt-4o-mini",
messages=[{"role": "user", "content": "Explain SAP CAP."}],
stream=True
)
for chunk in stream:
if chunk.choices[0].delta.content:
print(chunk.choices[0].delta.content, end="")
from gen_ai_hub.proxy.native.openai import embeddings
response = embeddings.create(
input="Every decoding is another encoding.",
model_name="text-embedding-3-small"
)
print(response.data[0].embedding)
from gen_ai_hub.proxy.langchain import init_llm, init_embedding_model
llm = init_llm("gpt-4o-mini", max_tokens=300)
result = llm.invoke("What is SAP BTP?")
print(result.content)
embeddings = init_embedding_model("text-embedding-3-small")
vector = embeddings.embed_query("SAP Business Technology Platform")
from gen_ai_hub.orchestration_v2 import (
OrchestrationConfig, OrchestrationService,
ModuleConfig, PromptTemplatingModuleConfig,
Template, UserMessage, LLMModelDetails,
FilteringModuleConfig, InputFiltering, OutputFiltering,
AzureContentSafetyInput, AzureContentSafetyOutput, AzureThreshold
)
config = OrchestrationConfig(
modules=ModuleConfig(
prompt_templating=PromptTemplatingModuleConfig(
prompt=Template(template=[UserMessage(role="user", content="{{?question}}")]),
model=LLMModelDetails(name="gpt-4o-mini")
),
filtering=FilteringModuleConfig(
input=InputFiltering(filters=[
AzureContentSafetyInput(hate=AzureThreshold.ALLOW_SAFE, violence=AzureThreshold.ALLOW_SAFE)
]),
output=OutputFiltering(filters=[
AzureContentSafetyOutput(hate=AzureThreshold.ALLOW_SAFE, violence=AzureThreshold.ALLOW_SAFE)
])
)
)
)
service = OrchestrationService(config=config)
response = service.run(placeholder_values={"question": "Explain SAP."})
from gen_ai_hub.orchestration_v2 import (
OrchestrationConfig, OrchestrationService,
ModuleConfig, PromptTemplatingModuleConfig,
Template, UserMessage, LLMModelDetails,
MaskingModuleConfig, MaskingProviderConfig,
DPIStandardEntity, MaskingMethod, DataMaskingProviderName
)
config = OrchestrationConfig(
modules=ModuleConfig(
prompt_templating=PromptTemplatingModuleConfig(
prompt=Template(template=[UserMessage(role="user", content="{{?text}}")]),
model=LLMModelDetails(name="gpt-4o-mini")
),
masking=MaskingModuleConfig(
masking_providers=[
MaskingProviderConfig(
type=DataMaskingProviderName.SAP_DATA_PRIVACY_INTEGRATION,
method=MaskingMethod.ANONYMIZATION,
entities=[
DPIStandardEntity(type="profile-email"),
DPIStandardEntity(type="profile-person")
]
)
]
)
)
)
service = OrchestrationService(config=config)
response = service.run(placeholder_values={"text": "Contact [email protected] for details."})
from gen_ai_hub.orchestration_v2 import (
OrchestrationConfig, OrchestrationService,
ModuleConfig, PromptTemplatingModuleConfig,
Template, UserMessage, LLMModelDetails,
GroundingModuleConfig, DocumentGroundingConfig,
DocumentGroundingFilter, DocumentGroundingPlaceholders,
GroundingSearchConfig, DataRepositoryType, GroundingType
)
config = OrchestrationConfig(
modules=ModuleConfig(
prompt_templating=PromptTemplatingModuleConfig(
prompt=Template(template=[UserMessage(role="user", content="{{?question}}")]),
model=LLMModelDetails(name="gpt-4o-mini")
),
grounding=GroundingModuleConfig(
type=GroundingType.DOCUMENT_GROUNDING_SERVICE,
config=DocumentGroundingConfig(
placeholders=DocumentGroundingPlaceholders(
input=["{{?question}}"],
output="{{?context}}"
),
filters=[
DocumentGroundingFilter(
id="my-vector-repo-id",
data_repository_type=DataRepositoryType.VECTOR,
search_config=GroundingSearchConfig(max_chunk_count=5)
)
]
)
)
)
)
service = OrchestrationService(config=config)
response = service.run(placeholder_values={"question": "What is the refund policy?"})
| Error | Cause | Solution |
|-------|-------|----------|
| No credentials found in any source | Missing AI Core service key/env vars | Set all AICORE_* environment variables or create a config file profile |
| No deployment found | Model not deployed in AI Core | Deploy the model in your resource group, or use deployment_id directly |
| AICORE_RESOURCE_GROUP not set | Missing resource group | Set AICORE_RESOURCE_GROUP env var or pass resource_group to the client |
| ModuleNotFoundError: No module named 'gen_ai_hub' | Wrong package installed | Install sap-ai-sdk-gen (not generative-ai-hub-sdk) |
| Import from generative_ai_hub_sdk fails | Using deprecated package name | The package was renamed; import from gen_ai_hub (installed via sap-ai-sdk-gen) |
| ValidationError on proxy client init | Incomplete credentials | Verify all four required env vars: AICORE_CLIENT_ID, AICORE_CLIENT_SECRET, AICORE_AUTH_URL, AICORE_BASE_URL |
references/getting-started-auth.md - Installation, authentication, and config setupreferences/native-clients-guide.md - Native client usage for OpenAI, Amazon, Google, and SAP RPT-1references/orchestration-guide.md - Orchestration service: templating, filtering, masking, grounding, embeddingsreferences/langchain-guide.md - LangChain integration: LLM/embedding init, chains, structured outputsreferences/troubleshooting.md - Common errors, version compatibility, migration from generative-ai-hub-sdkKeep this skill updated using these sources:
tools
Use when automating SAP BW query inspection, InfoProvider metadata reads (characteristics, key figures), metadata-verified specification review, unsaved draft preparation, or human-confirmed query draft population through Eclipse or HANA Studio with BW Modeling Tools.
tools
Use when an agent must inspect or operate an authenticated SAP web UI through an in-app Browser, Microsoft Edge CDP, or an existing Playwright client, especially when SAP SSO reuse, isolated Edge profiles, deterministic target selection, screenshots, or browser bootstrap recovery is required.
tools
Evidence-based assessment of whether an SAP API/interface usage scenario aligns with the SAP API Policy (v.4.2026a). Use whenever someone asks whether a way of calling SAP is allowed/compliant — e.g. Published API vs internal/private/"confidential" API status, "Documented Use", whether a third-party tool / iPaaS / middleware / RPA bot / AI agent / MCP server may call SAP APIs, agentic or generative-AI access to SAP, bulk data extraction or replication into a lake/warehouse, custom Z/Y OData or RFC/BAPI wrappers and Clean Core, ADT/developer-tooling boundaries, ODP-RFC and other "not permitted" interfaces, partner Integration Certification, or RISE integration remediation. Trigger even when the policy is not named, e.g. "are we allowed to…", "is it compliant to…", "can we connect X to SAP…", "will this break under the new API policy". Produces a sourced technical assessment with a confidence level — explicitly NOT legal advice and NOT a final SAP compliance decision.
development
SAP-RPT-1-OSS local tabular prediction workflows for FI/CO prototype datasets. Use when preparing SAP finance CSV exports for classification or regression experiments with source-verified setup, leakage checks, and governance review.