Agent skill

Sap Btp Cias

by secondsky in secondsky/sap-skills

SAP BTP Cloud Integration Automation Service (CIAS) skill for guided integration workflows.

GPL-3.0Auto-check passedBackend & APIs

Install Sap Btp Cias

skills CLI
$ npx skills add secondsky/sap-skills --skill sap-btp-cias -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/sap-skills sap-btp-cias --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/sap-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/sap-btp-cias/skills/sap-btp-cias .claude/skills/sap-btp-cias && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sap-btp-cias
GitHub stars
462
Token cost
~3.2k tokens
SKILL.md length
1,279 words
Files
12 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
GPL-3.0

At a glance

SAP BTP Cloud Integration Automation Service (CIAS) skill for guided integration workflows.

  • Works in 6 steps: Subscribe to CIAS (Standard Plan) → Assign Roles to Users → Plan Integration Scenario → …
  • : setting up CIAS subscriptions
  • SKILL.md covers Related Skills, When to Use This Skill, Table of Contents and Quick Reference, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sap Btp Cias is an agent skill from secondsky/sap-skills. SAP BTP Cloud Integration Automation Service (CIAS) skill for guided integration workflows. Use when: setting up CIAS subscriptions, configuring destinations, assigning roles (CIASIntegrationAdministrator, CIASIntegrationExpert, CIASIntegrationMonitor), planning integration scenarios, working with My Inbox tasks, monitoring scenario execution, troubleshooting CIAS errors, creating OAuth2 instances, configuring identity providers for CIAS, understanding CIAS security architecture, or integrating SAP products…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including reference files (for example `README.md`, `agents/openai.yaml` and `references/integration-scenarios.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect and Email management. It works with SAP. The repository describes itself as: Production-ready plugins for SAP development with AI coding assistants — BTP, CAP, Fiori, ABAP, HANA, Analytics Cloud, Datasphere, and more. The licence is GPL-3.0.

When your agent uses it

  • : setting up CIAS subscriptions
  • Configuring destinations
  • Assigning roles (CIASIntegrationAdministrator
  • CIASIntegrationExpert

Example prompts

  • “/sap-btp-cias”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Subscribe to CIAS (Standard Plan)
  2. Assign Roles to Users
  3. Plan Integration Scenario
  4. Work with Tasks (My Inbox)
  5. Create Destination for Automation
  6. Monitor Scenario Execution

What it can do on your machine

Read from SKILL.md and the folder at commit 652a861. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • help.sap.com
    • github.com
    • maintenanceplanner.cfapps.eu10.hana.ondemand.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sap Btp Cias loads about 3.2k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 146 tokens; SKILL.md has 1,279 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~146
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/sap-skills at commit 652a861, republished under its GPL-3.0 licence (© secondsky). 1,279 words, ~3,227 tokens.

Download SKILL.mdSave it as .claude/skills/sap-btp-cias/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
sap-btp-cias
description
SAP BTP Cloud Integration Automation Service (CIAS) skill for guided integration workflows. Use when: setting up CIAS subscriptions, configuring destinations, assigning roles (CIASIntegrationAdministrator, CIASIntegrationExpert, CIASIntegrationMonitor), planning integration scenarios, working with My Inbox tasks, monitoring scenario execution, troubleshooting CIAS errors, creating OAuth2 instances, configuring identity providers for CIAS, understanding CIAS security architecture, or integrating SAP products (S/4HANA, SuccessFactors, BTP services, SAP Build, IBP).
license
GPL-3.0
metadata.maintainer
Eduard Jiglau
metadata.maintainer_email
hello@sap-ai-skills.com
metadata.website
https://sap-ai-skills.com
metadata.version
2.4.1
metadata.last_verified
2025-11-27
metadata.sap_product
Cloud Integration Automation Service
metadata.source_docs
https://github.com/SAP-docs/btp-cloud-integration-automation-service

SAP BTP Cloud Integration Automation Service (CIAS)

Cloud Integration Automation Service provides guided workflows to integrate SAP cloud solutions with on-premise and other SAP cloud solutions. It offers both manual task instructions and automated configuration capabilities.

  • sap-btp-cloud-platform: Use for subaccount, subscription, entitlement, and role collection setup
  • sap-btp-connectivity: Use for destinations, OAuth2 service instances, and Cloud Connector dependencies
  • sap-btp-integration-suite: Use when CIAS scenarios produce or depend on Integration Suite artifacts
  • sap-btp-cloud-identity-services: Use for identity-provider and trust configuration that affects CIAS access

When to Use This Skill

Use this skill when subscribing to CIAS, assigning CIAS role collections, planning guided integration scenarios, working My Inbox tasks, monitoring scenario execution, configuring OAuth2 API access, or troubleshooting CIAS workflow/task failures.

Table of Contents

Quick Reference

Service Plans
PlanTypePurpose
StandardApplicationUI access for scenario planning, task monitoring, integration management
OAuth2ServiceAPI access for programmatic operations (required for ABAP automation)
Role Collections
RoleCollectionCapabilities
Integration AdministratorCIASIntegrationAdministratorFull access: Plan for Integration, My Inbox, Monitoring; terminate scenarios
Integration ExpertCIASIntegrationExpertMy Inbox access; work on assigned tasks
Integration MonitorCIASIntegrationMonitorRead-only access to Scenario Execution Monitoring
Supported Regions

AWS: EU10 (Frankfurt), EU11 (Frankfurt EU Access), US10 (Virginia), AP10 (Sydney), JP10 (Tokyo), CA10 (Montreal) Azure: EU20 (Netherlands), CN20 (China North 3) Alibaba: CN40 (Shanghai)

Core Workflows

1. Subscribe to CIAS (Standard Plan)
  1. Navigate to SAP BTP Cockpit → Global Account → Subaccount
  2. Go to Services → Service Marketplace
  3. Filter by "Cloud Integration Automation Service"
  4. Click tile → Create → Select Standard plan
  5. Confirm creation
  6. Access via Instances and Subscriptions → "Go to Application" icon
2. Assign Roles to Users
  1. Navigate to Security → Role Collections in subaccount
  2. Select role collection (e.g., CIASIntegrationAdministrator)
  3. Click Edit → Users tab
  4. Add users by email ID or login user ID
  5. Save changes

Multiple users can be assigned per role using comma-separated user IDs.

3. Plan Integration Scenario
  1. Access CIAS application from Instances and Subscriptions
  2. Open Plan for Integration tile
  3. Browse available solutions in Solutions tab
  4. Select scenario and scenario option
  5. Choose systems for integration (by customer number)
  6. Specify:
    • Target subaccount for workflow
    • SAP BTP Workflow Users (must have subaccount access)
    • Transaction name for monitoring
  7. Confirm workflow generation
  8. Access tasks in My Inbox tile
4. Work with Tasks (My Inbox)
  1. Open My Inbox tile (requires Administrator or Expert role)
  2. Click Claim to lock task for your user
  3. Follow instructions in Task Instructions tab
  4. For automation tasks: Configure parameters → Click Execute Step
  5. Click Task Completed when done
  6. Click Refresh to display next task
  7. Repeat until viewing Execution Summary
5. Create Destination for Automation
  1. In My Inbox → Confirm System Components task
  2. Click Create Destination link
  3. Configure:
    • Name: Valid identifier
    • Description: Purpose description
    • URL: Target system host URL
    • Authentication: Method + credentials
    • Type: HTTP (default)
  4. Save configuration

Always use HTTPS for secure communication.

6. Monitor Scenario Execution
  1. Open Scenario Execution Monitoring tile (requires Administrator or Monitor role)
  2. Filter workflows by status: Running, Completed, Canceled
  3. View tabs: Task Details, Targets, Roles and Users, Scope, Support Information
  4. Use Terminate Execution to remove scenarios permanently
  5. Access Logs tab for automation execution details

Service Limitations

  • Maximum 15 active workflows per subaccount
  • No self-service data deletion (submit ticket to component BC-INS-CIT-RT)
  • Logs retained for 90 days
  • OAuth2 certificate maximum validity: 1 year
  • Execution scope cannot be changed after confirmation
  • Destination cannot be changed if already used in automation task
  • Supported browsers: Google Chrome, Microsoft Edge (Chromium), Mozilla Firefox, Apple Safari (macOS)

Security Architecture

CIAS comprises six core components:

  1. Runtime: Backbone framework rendering integration tasks
  2. Planning: UI for planning integration scenarios
  3. Inbox: UI for end-user task access
  4. Monitoring: UI for scenario implementation monitoring
  5. Managed System: System configured during integration
  6. Automation Runtime: Calls configuration APIs of managed systems

Security features:

  • Role-based access via SAP BTP authorization framework
  • XSRF protection for backend connectivity calls
  • Identity provider integration (SAML assertion Name ID attribute supported)
  • Credentials stored in Credential Store service (inaccessible to external parties)

Common Error Patterns

Empty Destination Dropdown

Symptom: Destination dropdown shows no options during task execution.

Cause: No destinations exist matching the tenant's Host Base URL.

Solution:

  1. Create destination manually following Destination Creation steps
  2. Ensure destination URL matches tenant Host Base URL exactly
  3. Refresh the dropdown after creation
Show full SKILL.md (522 more words)Show less
Workflow Conflict Lock

Symptom: Cannot proceed with task; execution lock activated.

Cause: Multiple integration workflows exist with identical system components.

Solutions:

  • Proceed: Continue without resolving (manual resolution later)
  • Terminate: End selected conflicting instances
  • Terminate Current Instance: Stop active workflow only
  • Cancel: Halt operation entirely
Application Access Denied After IdP Change

Symptom: Users cannot access CIAS application after identity provider change.

Cause: Users not managed by newly configured identity provider.

Solution:

  1. Add users to new identity provider
  2. Reassign role collections in subaccount Security settings
  3. Verify user IDs exist in configured IdP
Task Marked as Reserved

Symptom: Cannot claim task; shows "Reserved" status.

Cause: Another assigned user has already claimed the task.

Solution: Coordinate with team; only one user can work on claimed task at a time.

Support Channels

Issue TypeComponentAction
General CIAS supportBC-INS-CIT-RTCreate support ticket
Manual task instructionsCheck Support Information tabSubmit incident to listed component
Data deletion requestBC-INS-CIT-RTInclude email ID and subaccount name
Service availabilityConsumer accountCheck Service Availability feature

OAuth2 API Access

For programmatic access (required for ABAP automation):

  1. Navigate to subaccount → Services → Service Marketplace
  2. Select Cloud Integration Automation Service → Create
  3. Choose OAuth2 plan
  4. Select runtime: "Other" or "Cloud Foundry"
  5. Provide instance name → Create
Create Service Key (for API calls)

With mTLS (Certificate):

json
{
  "xsuaa": {
    "credential-type": "x509",
    "x509": {
      "key-length": 2048,
      "validity": 365,
      "validity-type": "DAYS"
    }
  }
}

Without Certificate: Create with name only.

Use generated client ID and client secret to create OAuth JWT token for API authentication.

Data Protection

  • Email IDs and subaccount names stored in service database
  • System/tenant selection data preserved for workflow execution
  • Logs do not store user-related personal data
  • Audit logs follow SAP BTP Audit Log retention policy
  • Sensitive data stored in Credential Store service

Glossary

TermDefinition
Personal DataAny information relating to identified/identifiable natural person
Sensitive Personal DataRacial/ethnic origin, political opinions, religious beliefs, genetic/biometric data
Residence PeriodTime between business end and end-of-purpose when data remains accessible
Retention PeriodTime from last business activity through data deletion
BlockingRestricting access to data whose primary business purpose has ended

Task UI Controls Quick Reference

Automation Task Controls
ControlFunction
RefreshUpdate automation statuses
Expand AllShow all parameter panels
Collapse AllHide all parameter panels
Show/Hide Read-Only ParametersToggle read-only visibility
Save ParametersPreserve current values
LogsView execution records
InformationParameter descriptions
Execute StepRun automation (async)
Error Recovery

After automation failure:

  • Only Failed Automations - Retry failed steps only
  • All Automations - Retry entire sequence

Bundled Resources

Reference Files
  1. references/setup-guide.md - Complete subscription, OAuth2, and destination configuration procedures
  2. references/security-guide.md - Security architecture, identity provider configuration, and role management
  3. references/integration-scenarios.md - Full list of 100+ supported integration scenarios with codes (1M1, 22K, 4A1, etc.)
  4. references/troubleshooting.md - Detailed error resolution procedures and common issues
  5. references/maintenance-planner.md - Maintenance Planner integration guide and workflow invocation
  6. references/task-ui-guide.md - Complete task UI controls, tabs, behaviors, and automation steps
  7. references/whats-new.md - Complete release notes from 2021-2025 with feature updates
Template Files
  1. templates/destination-config.md - Destination configuration templates by target system type
  2. templates/role-assignment.md - Role assignment procedures and checklists for different scenarios

Documentation Sources

Primary:

Related:

© secondsky, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (references) in plugins/sap-btp-cias/skills/sap-btp-cias of secondsky/sap-skills.

  • SKILL.md
  • README.md
  • agents/openai.yaml
  • references/integration-scenarios.md
  • references/maintenance-planner.md
  • references/security-guide.md
  • references/setup-guide.md
  • references/task-ui-guide.md
  • references/troubleshooting.md
  • references/whats-new.md
  • templates/destination-config.md
  • templates/role-assignment.md

Open the folder on GitHubat commit 652a861

Compare with similar skills

Sap Btp Cias next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sap Btp Cias compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sap Btp Cias this skillsecondsky/sap-skills462—~3.2kAutomated safety check: PassGPL-3.0
Google WorkspaceRedWoodOG/Hermes-Desktop177—~2.1kAutomated safety check: PassMIT
E2a Setuptokencanopy/e2a193—~820Automated safety check: PassApache-2.0
Detecting Email Account Compromisemukul975/Anthropic-Cybersecurity-Skills34k—~823Automated safety check: PassApache-2.0
Google Workspaceericrisco/rsc-harness180—~3.2kAutomated safety check: PassMIT
GCP Workspace Pivotwgpsec/AboutSecurity1.8k—~2.9kAutomated safety check: PassNone

Similar skills

  • Google Workspace

    RedWoodOG/Hermes-Desktop

    Gmail, Calendar, Drive, Contacts, Sheets, and Docs integration via Python.

    177 GitHub stars~2.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • E2a Setup

    tokencanopy/e2a

    A skill your agent uses when a user wants to connect or authorize the e2a MCP server, select or create an agent inbox, verify first-run readiness, or set up a custom email domain.

    193 GitHub stars~820 tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Google Workspace

    ericrisco/rsc-harness

    A skill your agent uses when server-side code reads or writes Gmail, Drive, Calendar, or Sheets with a GCP service account and no human in the OAuth loop: picking the auth mode (app-owned vs…

    180 GitHub stars~3.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • GCP Workspace Pivot

    wgpsec/AboutSecurity

    GCP 到 Google Workspace 的穿越攻击方法论。当已获取 GCP Service Account 或 Project 权限并发现目标组织使用 Google Workspace、需要从云平台穿越到企业邮件/文档/管理控制台、或发现 Domain-Wide Delegation 配置时使用。覆盖 Domain-Wide Delegation 滥用、OAuth…

    1.8k GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Pp Workspace Admin

    mvanhorn/printing-press-library

    GAT-style Google Workspace auditing as an agent-native CLI: sync Directory, Drive, Gmail, Reports, and Alert Center into a local store, then run offline cross-API audits, offboarding, and OAuth-app…

    2.1k GitHub stars~11k tokensUpdated today
    Backend & APIsAuto-check: notes

More from secondsky/sap-skills

All 41 skills in this repo
  • Sap Rpt1

    secondsky/sap-skills

    SAP-RPT-1-OSS local tabular prediction workflows for FI/CO prototype datasets.

    462 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check: notes
  • Dependency Upgrade

    secondsky/sap-skills

    Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout.

    462 GitHub stars~4.8k tokensUpdated 4 days ago
    Auto-check: warnings
  • Sap Abap

    secondsky/sap-skills

    Comprehensive ABAP development skill for SAP systems. An agent skill from secondsky/sap-skills.

    462 GitHub stars~3.9k tokensUpdated 4 days ago
    Auto-check passed
  • Sap Dependency Security

    secondsky/sap-skills

    SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection.

    462 GitHub stars~5.9k tokensUpdated 4 days ago
    Auto-check: warnings
  • Sap Abap Cds

    secondsky/sap-skills

    Comprehensive SAP ABAP CDS (Core Data Services) reference for data modeling, view development, and semantic enrichment.

    462 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Sap AI Core

    secondsky/sap-skills

    Guides development with SAP AI Core and SAP AI Launchpad for enterprise AI/ML workloads on SAP BTP.

    462 GitHub stars~3.3k tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about Sap Btp Cias

What does Sap Btp Cias do?

SAP BTP Cloud Integration Automation Service (CIAS) skill for guided integration workflows. Sap Btp Cias is an agent skill from secondsky/sap-skills. SAP BTP Cloud Integration Automation Service (CIAS) skill for guided integration workflows.

When should I use Sap Btp Cias?

Sap Btp Cias fits situations like: : setting up CIAS subscriptions; configuring destinations; assigning roles (CIASIntegrationAdministrator; CIASIntegrationExpert.

How do I install Sap Btp Cias in Claude Code?

Run `npx skills add secondsky/sap-skills --skill sap-btp-cias -a claude-code`. Or copy the skill folder (plugins/sap-btp-cias/skills/sap-btp-cias in secondsky/sap-skills) into .claude/skills/sap-btp-cias in your project. Claude Code loads it when a task matches its description.

How do I install Sap Btp Cias in Codex?

Run `npx skills add secondsky/sap-skills --skill sap-btp-cias -a codex`. Or copy the skill folder (plugins/sap-btp-cias/skills/sap-btp-cias in secondsky/sap-skills) into .agents/skills/sap-btp-cias in your project. Codex loads it when a task matches its description.

Can I use Sap Btp Cias in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/sap-skills --skill sap-btp-cias -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sap-btp-cias, .gemini/skills/sap-btp-cias, .github/skills/sap-btp-cias and .opencode/skills/sap-btp-cias in your project.

What does Sap Btp Cias need to run?

SKILL.md names no scripts, command-line tools or credentials: Sap Btp Cias is instructions for the agent only.

Does Sap Btp Cias access the network?

SKILL.md names 3 domains. As links in the text: help.sap.com, github.com and maintenanceplanner.cfapps.eu10.hana.ondemand.com. This is read from the text; nothing was executed.

Is Sap Btp Cias safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sap Btp Cias use?

Sap Btp Cias is published under the GPL-3.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sap Btp Cias use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to Sap Btp Cias?

Skills that share tags, products or a category with Sap Btp Cias: Google Workspace (RedWoodOG/Hermes-Desktop, 177 stars), E2a Setup (tokencanopy/e2a, 193 stars), Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Google Workspace (ericrisco/rsc-harness, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sap Btp Cias?

secondsky (a GitHub user) maintains it in secondsky/sap-skills, which has 462 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: secondsky/sap-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.