Skip to content
Item Detail
Deprecation of Basic Authentication for APIs
Deprecated Required Automatically On Impact: High AI Enriched
Description

Access to APIs based on HTTP Basic Authentication will reach end of maintenance on June 2, 2023 and will be deleted on November 20, 2026.See More

Detailed Description

HTTP Basic Authentication for APIs in SAP SuccessFactors HCM suite is being deprecated due to security concerns, as user ID and password are passed over the network in text format. The feature will reach end of maintenance on June 2, 2023 and will be completely deleted on November 20, 2026. SAP encourages migration to more secure authentication methods such as OAuth 2.0 and OpenID Connect (OIDC). An exception exists for Basic Authentication provided as part of the integration add-on 3.0 for SAP ERP HCM and SAP SuccessFactors HCM suite, which will continue to receive maintenance.

Impact Assessment

Organizations using HTTP Basic Authentication to access SAP SuccessFactors APIs must plan migration to OAuth 2.0 or OpenID Connect before the end of maintenance date of June 2, 2023, and complete migration before the deletion date of November 20, 2026. After June 2, 2023, SAP will no longer fix bugs or deliver patches for Basic Authentication, and after November 20, 2026, the feature will no longer be available for productive use. The exception for integration add-on 3.0 for SAP ERP HCM and SuccessFactors HCM suite means some integrations may continue to function, but direct API access using Basic Auth must be migrated.

Test Recommendations
• Test all API integrations currently using HTTP Basic Authentication to identify which ones require migration • Validate OAuth 2.0 authentication implementation for all affected APIs • For instances migrated to SAP Cloud Identity Services, test OpenID Connect (OIDC) authentication as an alternative • Verify that integration add-on 3.0 for SAP ERP HCM continues to function with Basic Authentication where applicable • Conduct end-to-end testing of migrated APIs using new authentication methods before June 2, 2023 end of maintenance date
Product: Platform
Modules: Integration and Extension
Feature: API
Reference: API-14291
Version: 1H 2021; 1H 2022; 1H 2023; 1H 2024; 1H 2025; 1H 2026; 2H 2021; 2H 2022; 2H 2023; 2H 2024; 2H 2025; 2H 2026
Valid as Of: Nov 20, 2026
Latest Revision: Jun 20, 2025
Affected Areas:
API Integration and Extension Authentication OAuth 2.0 OpenID Connect SAP SuccessFactors HCM suite SAP ERP HCM