Agent skill

Sap Btp Connectivity

by secondsky in secondsky/sap-skills

SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes.

GPL-3.0Auto-check passedDevOps & Cloud

Install Sap Btp Connectivity

skills CLI
$ npx skills add secondsky/sap-skills --skill sap-btp-connectivity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/sap-skills sap-btp-connectivity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/sap-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/sap-btp-connectivity/skills/sap-btp-connectivity .claude/skills/sap-btp-connectivity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sap-btp-connectivity
GitHub stars
462
Token cost
~2.8k tokens
SKILL.md length
801 words
Files
21 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
GPL-3.0

At a glance

SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes.

  • Works in 11 steps: Overview → Quick Start → Connectivity Scenarios → …
  • Configuring destinations (HTTP
  • SKILL.md covers Related Skills, When to Use This Skill, Table of Contents and Overview, plus 7 more sections
  • Calls helm

What it does

Sap Btp Connectivity is an agent skill from secondsky/sap-skills. SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing OAuth and principal propagation, deploying connectivity proxies in Kubernetes/Kyma, troubleshooting connectivity errors (405, 407, 503), or configuring multitenancy.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including reference files (for example `README.md`, `agents/openai.yaml` and `references/advanced-configuration.md`).

It sits in DevOps & Cloud, covering Container orchestration and OAuth and OpenID Connect. It works with SAP and Kubernetes. The repository describes itself as: Production-ready plugins for SAP development with AI coding assistants — BTP, CAP, Fiori, ABAP, HANA, Analytics Cloud, Datasphere, and more. The licence is GPL-3.0.

When your agent uses it

  • Configuring destinations (HTTP
  • Setting up cloud-to-on-premise connectivity
  • Implementing OAuth and principal propagation
  • Deploying connectivity proxies in Kubernetes/Kyma

Example prompts

  • “/sap-btp-connectivity”

Requirements

  • Node.js
  • Docker

Workflow steps

11 steps, taken from the first numbered list in SKILL.md.

  1. Overview
  2. Quick Start
  3. Connectivity Scenarios
  4. Destination Types
  5. Authentication Configuration
  6. Cloud Connector Setup
  7. Kubernetes/Kyma Connectivity
  8. Common Issues & Troubleshooting
  9. Security Best Practices
  10. Critical Rules
  11. Bundled Resources

What it can do on your machine

Read from SKILL.md and the folder at commit 652a861. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • helm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • help.sap.com
    • github.com
    • api.sap.com
    • tools.hana.ondemand.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sap Btp Connectivity loads about 2.8k tokens when it runs, and up to ~38k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 801 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~38k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/sap-skills at commit 652a861, republished under its GPL-3.0 licence (© secondsky). 801 words, ~2,809 tokens.

Download SKILL.mdSave it as .claude/skills/sap-btp-connectivity/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
sap-btp-connectivity
description
SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Use when configuring destinations (HTTP, RFC, LDAP, MAIL, TCP), setting up cloud-to-on-premise connectivity, implementing OAuth and principal propagation, deploying connectivity proxies in Kubernetes/Kyma, troubleshooting connectivity errors (405, 407, 503), or configuring multitenancy.
license
GPL-3.0
metadata.maintainer
Eduard Jiglau
metadata.maintainer_email
hello@sap-ai-skills.com
metadata.website
https://sap-ai-skills.com
metadata.version
2.4.1
metadata.last_verified
2025-11-27
metadata.keywords
SAP BTP, Connectivity, Destination Service, Cloud Connector, Connectivity Proxy, Transparent Proxy, Kyma, Kubernetes, OAuth, Principal Propagation, RFC, LDAP…

SAP BTP Connectivity Skill

  • sap-btp-cloud-platform: Use for platform fundamentals, BTP account setup, and integration patterns
  • sap-btp-best-practices: Use for implementation guidance, security best practices, and production deployment
  • sap-cap-capire: Use for CAP service connectivity, destination consumption, and secure API access
  • sap-fiori-tools: Use for configuring Fiori app destinations and frontend connectivity
  • sap-abap: Use when connecting to ABAP systems via RFC or implementing principal propagation

When to Use This Skill

Use this skill when configuring BTP destinations, Cloud Connector, OAuth flows, principal propagation, RFC/LDAP/MAIL/TCP connectivity, Kubernetes/Kyma connectivity proxies, multitenant destination access, or troubleshooting connectivity errors such as 405, 407, 503, and proxy failures.

Table of Contents

  1. Overview
  2. Quick Start
  3. Connectivity Scenarios
  4. Destination Types
  5. Authentication Configuration
  6. Cloud Connector Setup
  7. Kubernetes/Kyma Connectivity
  8. Common Issues & Troubleshooting
  9. Security Best Practices
  10. Critical Rules
  11. Bundled Resources

Overview

SAP BTP Connectivity provides secure access from SAP BTP applications to remote services across cloud, on-premise, and VPC environments.

Core Components
ComponentPurpose
Destination ServiceManages connection metadata, authentication, routing
Connectivity ServiceEnables Kubernetes workloads via Cloud Connector
Cloud ConnectorReverse proxy for secure on-premise tunneling
Connectivity ProxyKubernetes component for on-premise access
Transparent ProxyKubernetes component for unified destination access

Supported Environments: Cloud Foundry, ABAP Environment, Kyma
Supported Protocols: HTTP/HTTPS, RFC, TCP (SOCKS5), LDAP/LDAPS, Mail


Quick Start

Create HTTP Destination (Cloud Foundry)
  1. Navigate: Connectivity > Destinations in BTP Cockpit
  2. Select: Create > From Scratch
  3. Configure:
    Name: my-destination
    Type: HTTP
    URL: https://api.example.com
    ProxyType: Internet
    Authentication: OAuth2ClientCredentials
    clientId: <your-client-id>
    clientSecret: <your-client-secret>
    tokenServiceURL: https://auth.example.com/oauth/token
Set Up Cloud Connector
  1. Download from SAP Tools
  2. Access: https://localhost:8443
  3. Login: Administrator / manage (change immediately)
  4. Add subaccount connection
Access Destination in Application (Node.js)
javascript
const { getDestination } = require('@sap-cloud-sdk/connectivity');
const destination = await getDestination({ destinationName: 'my-destination' });

Connectivity Scenarios

Cloud-to-Cloud
ProxyType: Internet
Authentication: OAuth2ClientCredentials | OAuth2SAMLBearerAssertion
Cloud-to-On-Premise
ProxyType: OnPremise
Authentication: BasicAuthentication | PrincipalPropagation

Requires Cloud Connector installation in on-premise network.

On-Premise-to-Cloud (Service Channels)

For on-premise systems accessing SAP BTP services via Cloud Connector.


Destination Types

TypeUse CaseProxyTypeCommon Authentication
HTTPREST/OData APIsInternet/OnPremiseOAuth2, Basic, Certificates
RFCSAP systemsOnPremiseBasic, PrincipalPropagation
LDAPDirectory servicesInternetBasic, NoAuth
MAILEmail protocolsInternetBasic, NoAuth
TCPGeneric TCPOnPremiseBasic

Detailed configuration: See references/http-destinations.md, references/rfc-destinations.md, references/mail-tcp-ldap-destinations.md


Authentication Configuration

OAuth2ClientCredentials (Service-to-Service)
Authentication: OAuth2ClientCredentials
clientId: <client-id>
clientSecret: <client-secret>
tokenServiceURL: https://auth.example.com/oauth/token
OAuth2SAMLBearerAssertion (User Propagation)
Authentication: OAuth2SAMLBearerAssertion
audience: <target-audience>
clientKey: <client-key>
tokenServiceURL: https://auth.example.com/oauth2/token
KeyStoreLocation: <certificate-location>
PrincipalPropagation (On-Premise SSO)
Authentication: PrincipalPropagation
ProxyType: OnPremise

Requires Cloud Connector X.509 certificate generation.

Complete reference: references/authentication-types.md (all 17+ types)


Cloud Connector Setup

Installation
  • Production: Windows MSI/Linux RPM packages (service registration)
  • Development: Portable archive (manual execution)
Initial Configuration
  1. Access UI: https://<hostname>:8443
  2. Login: Administrator / manage
  3. Change password immediately
  4. Select mode: Master or Shadow
  5. Add subaccount connection
Access Control

Configure on-premise resource access:

  • Backend Types: ABAP System, SAP Gateway, Non-SAP System, SAP HANA
  • HTTP Access Control: System mapping + resource paths + policies
High Availability
  • Master-Shadow: Primary + backup with synchronized config
  • Requirements: Stable network, separate machines, identical versions

Complete guide: references/cloud-connector.md


Kubernetes/Kyma Connectivity

Connectivity Proxy

Enables Kubernetes workloads to access on-premise systems.

Installation:

bash
helm install connectivity-proxy \
  oci://registry-1.docker.io/sapse/connectivity-proxy \
  --version <version> --namespace <namespace> -f values.yaml
Transparent Proxy

Exposes BTP destinations as Kubernetes Services.

Installation:

bash
helm install transparent-proxy \
  oci://registry-1.docker.io/sapse/transparent-proxy \
  --version <version> --namespace <namespace> -f values.yaml

Usage: Create Destination Custom Resource, access as Kubernetes Service.

Complete configuration: references/kubernetes-connectivity.md


Common Issues & Troubleshooting

Show full SKILL.md (329 more words)Show less
HTTP Error Codes
CodeCauseSolution
400Malformed requestCheck request syntax
401Authentication failureVerify credentials/tokens
405HTTPS instead of HTTPUse http:// with port 20003
407Missing authorizationAdd Proxy-Authorization: Bearer <token>
503Cloud Connector offlineCheck CC connection and Location ID
Cloud Connector Issues

Cannot connect to subaccount:

  • Verify region host URL
  • Check firewall allows outbound HTTPS
  • Verify subaccount credentials

Access denied to resource:

  • Check access control configuration
  • Verify virtual host mapping
  • Check resource path policy

Complete troubleshooting: references/troubleshooting.md


Security Best Practices

Cloud Connector
  • Deploy in DMZ under IT control
  • Change default password immediately
  • Configure LDAP for user management
  • Enable audit logging (All level for production)
  • Deploy high availability (master + shadow)
Destinations
  • Use OAuth over basic authentication
  • Store credentials in Destination Service, not code
  • Enable TLS for all connections
  • Use mTLS for enhanced security

Critical Rules

Always Do
  • Change Cloud Connector default password immediately
  • Use HTTPS for all external connections
  • Configure access control before exposing resources
  • Enable audit logging in production
  • Cache tokens and destinations appropriately
Never Do
  • Expose Cloud Connector UI to internet
  • Store credentials in application code
  • Skip access control configuration
  • Modify Cloud Connector Tomcat config files
  • Run multiple master instances (split-brain)

Bundled Resources

Configuration References
  • references/http-destinations.md - Complete HTTP destination properties
  • references/rfc-destinations.md - RFC destination properties and pooling
  • references/mail-tcp-ldap-destinations.md - Mail, TCP, LDAP configuration
  • references/authentication-types.md - All 17+ authentication configurations
Setup & Configuration
  • references/cloud-connector.md - Cloud Connector setup and configuration
  • references/kubernetes-connectivity.md - Connectivity Proxy and Transparent Proxy
  • references/destination-service-api.md - REST API reference
Advanced Topics
  • references/advanced-configuration.md - MTA, config.json, chaining, ZTIS
  • references/identity-propagation-scenarios.md - ABAP, NetWeaver Java, custom IDP
  • references/operational-guides.md - Network zones, solution management
  • references/connectivity-alternatives-and-config.md - Reverse proxy, user roles, RFC config
Development & SDK
  • references/java-sdk-development.md - Java APIs, JCo, SAP Cloud SDK
  • references/mail-protocols.md - SMTP, IMAP, POP3 configuration
Templates
  • templates/destination-http-oauth.json - HTTP destination with OAuth template
  • templates/destination-onpremise.json - On-premise destination template
  • templates/connectivity-proxy-values.yaml - Helm values for Connectivity Proxy
  • templates/transparent-proxy-values.yaml - Helm values for Transparent Proxy


Last Updated: 2025-11-27
Next Review: 2026-02-27
Source: https://github.com/SAP-docs/btp-connectivity (383 files, 352+ analyzed)

© secondsky, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (references) in plugins/sap-btp-connectivity/skills/sap-btp-connectivity of secondsky/sap-skills.

  • SKILL.md
  • README.md
  • agents/openai.yaml
  • references/advanced-configuration.md
  • references/authentication-types.md
  • references/cloud-connector.md
  • references/connectivity-alternatives-and-config.md
  • references/destination-service-api.md
  • references/http-destinations.md
  • references/identity-propagation-scenarios.md
  • references/java-sdk-development.md
  • references/kubernetes-connectivity.md
  • references/mail-protocols.md
  • references/mail-tcp-ldap-destinations.md
  • references/operational-guides.md
  • references/rfc-destinations.md
  • references/troubleshooting.md
  • templates/connectivity-proxy-values.yaml
  • … and 3 more

Open the folder on GitHubat commit 652a861

Compare with similar skills

Sap Btp Connectivity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sap Btp Connectivity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sap Btp Connectivity this skillsecondsky/sap-skills462—~2.8kAutomated safety check: PassGPL-3.0
Entra Agent Idmicrosoft/skills3.1k1 repos~2.3kAutomated safety check: PassMIT
Ksaildevantler-tech/ksail165—~1.1kAutomated safety check: PassCustom licence
Implementing Image Provenance Verification With Cosignmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: NotesApache-2.0
Implementing Rbac Hardening For Kubernetesmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k1 repos~3.1kAutomated safety check: PassCustom licence

Similar skills

  • Entra Agent Id

    microsoft/skills

    Official

    Microsoft Entra Agent ID (preview) for creating OAuth2-capable AI agent identities via Microsoft Graph beta API.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    DevOps & CloudAuto-check passed
  • Ksail

    devantler-tech/ksail

    Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.

    165 GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Implementing Image Provenance Verification With Cosign

    mukul975/Anthropic-Cybersecurity-Skills

    Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Implementing Rbac Hardening For Kubernetes

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed
  • NGINX Ingress Policy CRD Guide

    nginx/kubernetes-ingress

    Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.

    5.1k GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from secondsky/sap-skills

All 41 skills in this repo
  • Sap Rpt1

    secondsky/sap-skills

    SAP-RPT-1-OSS local tabular prediction workflows for FI/CO prototype datasets.

    462 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check: notes
  • Dependency Upgrade

    secondsky/sap-skills

    Secure dependency upgrades with supply chain protection, cooldowns, and staged rollout.

    462 GitHub stars~4.8k tokensUpdated 3 days ago
    Auto-check: warnings
  • Sap Abap

    secondsky/sap-skills

    Comprehensive ABAP development skill for SAP systems. An agent skill from secondsky/sap-skills.

    462 GitHub stars~3.9k tokensUpdated 3 days ago
    Auto-check passed
  • Sap Dependency Security

    secondsky/sap-skills

    SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection.

    462 GitHub stars~5.9k tokensUpdated 3 days ago
    Auto-check: warnings
  • Sap Abap Cds

    secondsky/sap-skills

    Comprehensive SAP ABAP CDS (Core Data Services) reference for data modeling, view development, and semantic enrichment.

    462 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • Sap AI Core

    secondsky/sap-skills

    Guides development with SAP AI Core and SAP AI Launchpad for enterprise AI/ML workloads on SAP BTP.

    462 GitHub stars~3.3k tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about Sap Btp Connectivity

What does Sap Btp Connectivity do?

SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes. Sap Btp Connectivity is an agent skill from secondsky/sap-skills. SAP BTP Connectivity skill covering Destination Service, Connectivity Service, Cloud Connector, Connectivity Proxy, and Transparent Proxy for Kubernetes.

When should I use Sap Btp Connectivity?

Sap Btp Connectivity fits situations like: configuring destinations (HTTP; setting up cloud-to-on-premise connectivity; implementing OAuth and principal propagation; deploying connectivity proxies in Kubernetes/Kyma.

How do I install Sap Btp Connectivity in Claude Code?

Run `npx skills add secondsky/sap-skills --skill sap-btp-connectivity -a claude-code`. Or copy the skill folder (plugins/sap-btp-connectivity/skills/sap-btp-connectivity in secondsky/sap-skills) into .claude/skills/sap-btp-connectivity in your project. Claude Code loads it when a task matches its description.

How do I install Sap Btp Connectivity in Codex?

Run `npx skills add secondsky/sap-skills --skill sap-btp-connectivity -a codex`. Or copy the skill folder (plugins/sap-btp-connectivity/skills/sap-btp-connectivity in secondsky/sap-skills) into .agents/skills/sap-btp-connectivity in your project. Codex loads it when a task matches its description.

Can I use Sap Btp Connectivity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/sap-skills --skill sap-btp-connectivity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sap-btp-connectivity, .gemini/skills/sap-btp-connectivity, .github/skills/sap-btp-connectivity and .opencode/skills/sap-btp-connectivity in your project.

What does Sap Btp Connectivity need to run?

Going by SKILL.md and its folder, Sap Btp Connectivity needs the command-line tools its instructions call (helm). Our summary lists: Node.js; Docker.

Does Sap Btp Connectivity access the network?

SKILL.md names 4 domains. As links in the text: help.sap.com, github.com, api.sap.com and tools.hana.ondemand.com. This is read from the text; nothing was executed.

Is Sap Btp Connectivity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sap Btp Connectivity use?

Sap Btp Connectivity is published under the GPL-3.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sap Btp Connectivity use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 35k tokens, read only when the agent opens those files.

What are the alternatives to Sap Btp Connectivity?

Skills that share tags, products or a category with Sap Btp Connectivity: Entra Agent Id (microsoft/skills, 3.1k stars), Ksail (devantler-tech/ksail, 165 stars), Implementing Image Provenance Verification With Cosign (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Rbac Hardening For Kubernetes (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sap Btp Connectivity?

secondsky (a GitHub user) maintains it in secondsky/sap-skills, which has 462 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: secondsky/sap-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.