Editorial photograph of an enterprise data integration review against the SAP digital core
SAP · API Policy v.4.2026 · Pillar Guide

SAP restricted third party API access. The buyer side guide to v.4.2026.

In April 2026 SAP published API Policy v.4.2026. The policy restricts third party access to non published APIs, blocks autonomous and generative AI agents, and forces bulk data extraction onto SAP endorsed routes. This is the buyer side pillar guide to remediation, cost, and negotiation.

Contact Us SAP Practice
v.4.2026The new API policy
9 documentsDigital Access exposure
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

SAP indirect access is the most contested licensing dimension across the enterprise SAP estate. The framework changed materially in 2018 with the introduction of digital access licensing. This guide is the buyer side framework for the third party API access posture.

Third party API access to SAP is a routine integration pattern. The publisher's commercial framework is anything but routine. The pre 2018 named user framework and the post 2018 digital access framework operate in parallel, and most enterprises are caught between them.

This guide draws on more than one hundred SAP indirect access engagements at our SAP advisory practice. Read the related SAP audit defence guide and the SAP indirect access framework.

Two commercial frameworks running in parallel

SAP operates two principal commercial frameworks for indirect access. The pre 2018 named user framework charges per human user with backend access. The post 2018 digital access framework charges per document created via third party API.

Two SAP commercial frameworks for third party API access
FrameworkPricing basisAudit postureWhen it favors the customer
Named user licensing (pre 2018)Per human user with backend accessHeavy, names every user touching SAPFew users, heavy document volume
Digital access licensing (post 2018)Per document created via third party APIDocument trace, less invasive on user namesMany users, predictable document volume
Hybrid (transition period)Named user + document, layeredBoth audit dimensionsCustomers mid transition
Outcome based commercialPre-negotiated annual capPredictableMature integration estate

Digital access licensing in detail

Digital access licensing charges per document created through third party API. Nine principal document types carry distinct rates.

Digital access licensing document types and rates
Document typeWhat triggers itTypical rate band
Sales OrderOrder header creation via APIHighest
Purchase OrderPO header creation via APIHigh
Financial DocumentJournal entry creation via APIHigh
Material DocumentGoods movement created via APIMedium
Service Entry SheetService confirmation via APIMedium
Quality DocumentInspection result via APILow
Manufacturing OrderProduction order via APILow
Maintenance DocumentNotification or order via APILow
Time ManagementTime recording via APILow

When digital access is the right framework

  • High document volume relative to user count. Mature integration estates with predictable document patterns.
  • Broad indirect user population. Sales, service, and procurement functions where the named user count would exceed the digital access cost.
  • SAP S/4HANA migration in progress. The S/4 commercial framework defaults to digital access, so the transition aligns with the broader S/4 cycle.

API access control choke points

Four principal choke points control the API access posture. The buyer side framework runs the access control through one or two of the four rather than allowing direct RFC traffic.

API access control choke points
Choke pointWhat it controlsBuyer side leverage
SAP API HubRESTful API access from cloud applicationsDocumented, predictable license posture
SAP Cloud ConnectorOn premises to cloud integrationLog based, controllable
RFC GatewayDirect backend RFC and BAPI callsHigh audit risk if uncontrolled
IDoc frameworkAsynchronous document exchangeDocument based, transitions well to digital access
Our SAP audit identified eleven thousand named users behind a Salesforce integration. We transitioned to digital access licensing on a hybrid commercial framework. The audit settled at one third of the publisher's initial claim.
— Group Head of Procurement · European industrial group

Audit posture framework

SAP audits routinely include the indirect access dimension. The publisher's preferred audit posture relies on the SAP managed logs and the RFC trace. The buyer side audit posture relies on the customer maintained access control log.

Three audit posture moves

  1. Customer maintained access control log. Independent evidence of every API call, every document, and every user mapping.
  2. Integration inventory. Documented map of every third party API consumer, the integration pattern, and the access control choke point.
  3. Document classification framework. Pre-categorized document creation source field for every third party integration.

What to do next

  1. Inventory all third party integrations. Map every API consumer, the integration pattern, and the access control choke point.
  2. Classify each integration. Named user, digital access, or hybrid framework.
  3. Validate the audit posture. Run the RFC trace, the Cloud Connector log, and the document creation source field.
  4. Evaluate the digital access transition. Compare the cost framework against the current named user exposure.
  5. Negotiate the digital access conversion package. SAP offers a conversion discount that is typically materially below the publisher's first quote.
  6. Implement the customer maintained audit log. Provides independent evidence in any audit conversation.
  7. Engage independent buyer side support. Contact our SAP advisory practice for the indirect access scoping.

Frequently asked questions

What is SAP indirect access?

Indirect access is human use of SAP backend data or functions through a non SAP front end. RFC calls, BAPI calls, and document creation via API all count. SAP enforces licensing on the indirect use under both the pre 2018 named user framework and the post 2018 digital access framework.

Do I need to transition to digital access licensing?

Not automatically. The transition is contractual not technical. Most enterprises stay on the pre 2018 named user framework while operating modern integration patterns, which creates the audit exposure. The transition is favorable for customers with high document volume and broad indirect user populations.

How does SAP audit indirect access?

SAP runs the RFC trace against the customer's production system, reviews the SAP Cloud Connector logs, and queries the document creation source field across the principal document types. The audit posture is heavy and the publisher's interpretation drives the licensing claim unless the customer maintains an independent access control log.

What is the typical indirect access claim size?

Highly variable. Audit claims commonly run from two to thirty million for enterprises with broad third party integration estates. The eventual settlement is typically one third to one half of the initial claim with a structured buyer side posture.

Can the audit risk be eliminated?

Not eliminated, but materially reduced. The combination of the digital access transition, the customer maintained audit log, and the structured integration inventory typically reduces the exposure by 60 to 80 percent against the publisher's first audit claim.

How long does the digital access transition take?

Three to six months for the commercial framework. The technical implementation is shorter, typically four to eight weeks across the principal integration patterns. The transition includes the document classification, the conversion discount negotiation, and the audit log implementation.

The framework is set out in the SAP advisory practice. Read the related SAP audit defence guide and the SAP indirect access framework.

SAP API Restrictions Negotiation Playbook

Forty pages. The full framework against v.4.2026.

The eight move negotiation playbook, the seven step remediation framework, the BTP capacity model, the third party tool carve outs, and the contract amendment patterns we use across more than five hundred enterprise software engagements.

Independent. Buyer side. The advisory firm SAP account teams quietly hope you do not hire.

No spam. We will only email you about this download. Privacy.
Run the SAP RISE TCO Calculator against your actual SAP framework in under five minutes.
Open the Tool →
v.4.2026
The new API policy
9 documents
Digital Access exposure
12 moves
Buyer side framework
500+
Enterprise clients
100%
Buyer side

SAP framed v.4.2026 as a routine technical refresh. The Redress framework reframed it as the largest contractual repricing event since the original Digital Access reset. Material commercial protection against SAP's opening Integration Suite framework.

Chief Information Officer
Global industrial manufacturer, 22,000 employees
Continue Reading

More from the API restrictions cluster.

SAP Practice →
SAP API and Digital Access intersection
SAP · Sub Page
SAP API and Indirect Access Changes
How the API policy intersects with the Digital Access nine document framework.
9 min read
SAP BTP Integration Suite costs
SAP · Sub Page
SAP BTP Integration Mandate Costs
The capacity model, the discount math, and the right sizing analysis for SAP Integration Suite.
9 min read
Third party tools and SAP API restrictions
SAP · Sub Page
SAP Third Party Tools and API Access
Celonis, Boomi, MuleSoft, Databricks, Snowflake. The carve out framework against v.4.2026.
9 min read
SAP Digital Access complete guide
SAP · Pillar
SAP Digital Access. The Complete Guide.
The nine document framework and the buyer side moves at the renewal cycle.
18 min read
SAP RISE Negotiation Guide
SAP · White Paper
SAP RISE Negotiation Guide
The buyer side framework for evaluating RISE versus on premise S/4HANA in the 2026 transition window.
22 min read
Editorial photograph of a corporate skyline at dusk

When you negotiate, we sit on your side.

Twenty years on the buy side. 500+ enterprise clients. $2B under advisory. Industry recognized.

SAP intelligence, monthly.

SAP framework signals, API policy signals, Digital Access framework signals, and the broader SAP licensing leverage signals across the practice.