Home  /  Research Videos  /  SAP
SAP · 5:35 · Buyer-side briefing

SAP's API Policy and the SuccessFactors 429: Read the Headers Before January

SAP's API Policy 4/2026 restricts you to published APIs, introduces fair use throttling and routes agentic AI through SAP's own pathways. SuccessFactors put numbers on it: 600 requests a minute per tenant, soft limits live since August 17, hard 429s from November 13 and January 1, 2027. What breaks under hard mode, the commercial proposal that follows, and how to keep the policy out of SAP's quarter end.

Share

The presenters in this briefing are AI generated avatars. The research, figures, and guidance are real, produced by Redress Compliance analysts from our consulting engagements and market network.

Transcript

Full narration of the briefing. Click a section heading to jump the player to that moment.

A policy, not an amendment 0:00

In April SAP published version four of its API Policy, and in August SuccessFactors became the first application to put numbers on it. The policy does three things: it restricts you to published APIs used for their documented purpose, it introduces fair use limits with throttling, and it confines agentic and generative AI access to SAP's own pathways. It is a governance document, not a contract amendment, so it reaches integration teams first and procurement last. I am Tom, Claire is with me, and this briefing is what the limits are, when they bite, and how to keep the policy off SAP's timetable.

What the policy does 0:46

Four provisions matter. Published APIs only: interfaces on the Business Accelerator Hub are usable, undocumented ones are out of policy now. Documented purpose only: section two point two point two prohibits large scale extraction outside endorsed pathways. Agentic AI through SAP's door: the same section prohibits API use by generative systems that plan and execute sequences of calls, except through SAP endorsed architectures.

And enforcement: SAP may throttle, suspend or terminate access, and names proxies and gateways as circumvention. The FAQ says it changes no license grant, no export right and no data ownership. The gap between that assurance and the policy text is where the risk lives.

SuccessFactors soft and hard limits 1:36

SuccessFactors replaced guidance with published limits in the 2608 release on August seventeenth. Soft limits are live for every existing customer: requests still run, but every response carries rate limit headers. Hard limits, where excess requests are rejected with a 429, apply to all new public APIs from November thirteenth and to every new tenant from January first, 2027. The headline number is six hundred requests per minute across the whole tenant, every connector combined.

Underneath it, twenty five per minute on metadata, batch and upsert, seventy five on the SOAP SFAPI. No date is announced for moving existing tenants to hard mode. Assume 2027.

Fair use is a percentile 2:21

How were the numbers set? SAP's CTO described it at Sapphire: take the workload distribution across all customers of an application and set fair use at the ninety ninth percentile. That protects the median customer and exposes the largest, most integrated estates, the ones with a payroll feed to lose. Soft mode means the request executes and a warning header comes back; nothing is logged unless you log it.

Hard mode means a 429 with a Retry After header and an integration that fails until it backs off. The RateLimit Policy header on every response tells you the policy, quota, window and mode. It is a free audit, running right now, on your tenant.

Where the exposure sits 3:04

Picture hard mode on a large estate. At shift change the identity provider, the time system and the payroll connector all poll Employee Central in the same window, the tenant crosses six hundred a minute, and you get random 429s across unrelated interfaces: provisioning fails, payroll reruns by hand. A connector that refetches metadata on every call hits twenty five a minute within seconds. A recruiting partner polling candidate records breaks the limit, and the 429 lands on your tenant.

A copilot with service credentials is out of policy regardless of volume. Then the proposal arrives: Integration Suite, Business Data Cloud, Joule, and a services engagement to rebuild it all.

The sequence 3:53

The response is a sequence. Inventory every integration that calls SuccessFactors, S/4HANA or Ariba, by endpoint, frequency and owner, and classify each as documented, used off purpose, undocumented, or agentic. The last two are policy exposure today. Read the headers now: log them for thirty days, aggregate by endpoint and hour, and find what would fail under hard mode before SAP's account team finds it for you.

Fix the design: cache metadata, size batches properly, replace polling with events, spread scheduled jobs across the hour. Most breaches are design defects that cost nothing once they are visible. And push the limit onto partners: every vendor connected to your tenant consumes your quota, so require each to remediate at its own cost.

The move 4:43

The move from this briefing: separate policy from contract. The policy is not an amendment; your license grant and your export rights are unchanged, so read anything that incorporates it by reference before signing. If your workload legitimately exceeds fair use, get a tenant level exception into the order form with a term. Evaluate Business Data Cloud, Integration Suite and Joule as products, on your timeline, never as the cure for a 429 at quarter end.

And put API terms on the renewal agenda: published limits for your tenant and a written statement that access to your own data carries no charge. The full research note is free to download under this video, at redresscompliance dot com slash newsletter slash september.

Negotiating a SAP renewal this year?

Redress Compliance works on contingency: our fee is 25 percent of what we save you. Nothing saved, nothing paid. Independent, buyer side only, never vendor funded. Want Redress to contact you? Reach out and we respond the same day.

Talk to a SAP negotiator
Browse all 192 research videos