# SAP Ariba > SAP Ariba is the procurement and supply-chain collaboration side of SAP: sourcing, contracts, procure-to-pay, supplier management, supplier risk, catalogs, and the SAP Business Network that connects buyers and suppliers. Its API surface is large and enterprise-shaped - 114 REST APIs plus 144 SOAP web services - and almost all of it sits behind an approval gate. Generated by the API Evangelist enrichment pipeline on 2026-08-29 from probed sources. SAP does not publish an llms.txt: https://developer.ariba.com/llms.txt returns HTTP 200 with the portal's Angular HTML shell, not text. This file is generated, not harvested. ## How to call it - Gateway host: https://openapi.ariba.com - Base URL pattern: https://openapi.ariba.com/api/{api-name}/v{n}/{environment} - confirmed examples: /api/bizmonservice/v2/prod, /api/mds/v1/prod, /api/approval, /api/externalDocuments - Every call needs TWO credentials: an `apiKey` header (application key) AND an `Authorization: Bearer` OAuth 2.0 access token (client credentials / two-legged). Tokens expire after 1,440 seconds. - Every call needs a `realm` query parameter naming the customer tenant. It is an authorization boundary: a client id not granted that realm gets a 401. - Credentials are NOT self-serve. Register on the developer portal, an Organization admin requests API access for the application, and SAP Ariba API administration approves it before production credentials exist. ## What is machine-readable, and what is not - The API catalogue IS anonymous: https://api.sap.com/odata/1.0/catalog.svc/ContentEntities.ContentPackages('SAPAribaOpenAPIs')/Artifacts?$format=json returns all 114 REST artifacts with name, version and description. The SOAP sibling package is SAPAribaWebServices (113 artifacts). - The SPECS ARE NOT anonymous. Every artifact download redirects to an SAP ID login. developer.ariba.com serves an Angular shell for every path, including /openapi.json. - SOAP WSDLs are generated per customer realm at https://s1.ariba.com/{Solution}/soap/{partition}/{ServiceName}?wsdl - there is no realm-independent WSDL. - cXML, the procurement interchange standard Ariba authored, IS public: http://xml.cxml.org/current/cXML.dtd ## Runtime semantics an agent needs - Rate limits: window-suffixed headers X-RateLimit-Limit-second/-minute/-hour/-day and X-RateLimit-Remaining-* plus LastCallMade. Exhaustion is 429. There is NO Retry-After and no reset timestamp - compute your own backoff. - Errors: proprietary envelope { "error": { "code", "message" } }. Not RFC 9457. 401 is overloaded (expired token, wrong apiKey, wrong realm, missing scope) - only the expired-token case is worth an automatic retry. - Pagination: four different grammars across the surface (offset/limit + X-Total-Count, $top/$skip/$count, pageLimit 1-50, PageSize/Offset headers). You cannot write one pager for SAP Ariba. - Filtering: RSQL (`rsqlfilter=(document_id==PO37529)`) on the monitoring APIs, OData `$filter` elsewhere. - Deprecation: a deprecated version returns an `X-API-Warn` header naming the active version. Not RFC 8594 Deprecation/Sunset. - Idempotency: NOT documented. Treat every POST as at-most-once and dedupe on your side. Several writes are asynchronous job submissions where re-posting creates a second job. - Reversibility: cancel/undo paths exist (Event Management CANCEL and undo-cancelation, Supplier Data processCancellationRequest, Flow Extension halt/resume, SOAP purchase-order and advance-payment cancels) but SAP publishes NO time window for any of them. Do not assume a reversal will still work. - Async jobs: submit -> poll -> download. Result files expire after 48 hours. ## Documentation - SAP Help Portal, SAP Ariba APIs: https://help.sap.com/docs/ariba-apis - Help for the SAP Ariba Developer Portal: https://help.sap.com/docs/ariba-apis/help-for-sap-ariba-developer-portal/help-for-sap-ariba-developer-portal - Quick start guide for developers: https://help.sap.com/docs/ariba-apis/help-for-sap-ariba-developer-portal/sap-ariba-developer-portal-quick-start-guide-for-developers - Authentication: https://help.sap.com/docs/ARIBA_APIS/b61dd8c7e22c4fe489f191f66b4c48d6/c61ddbd093c1498aae76e42ffaf37e21.html - API gateway and OAuth: https://help.sap.com/docs/ARIBA_APIS/b61dd8c7e22c4fe489f191f66b4c48d6/99ef1f190ff647df8cffd681264c24d0.html - Rate limits: https://help.sap.com/docs/ARIBA_APIS/b61dd8c7e22c4fe489f191f66b4c48d6/962cc344f5e443ffaae9e8aaa15cf34e.html - Versioning and deprecation: https://help.sap.com/docs/ARIBA_APIS/b61dd8c7e22c4fe489f191f66b4c48d6/792a3139e5c04f0cbbcbbd404506bc04.html - Developer portal (login required): https://developer.ariba.com/api/apis - SAP Business Accelerator Hub, SAP Ariba Open APIs: https://api.sap.com/package/SAPAribaOpenAPIs/overview - SOAP web services index: https://help.sap.com/doc/631084d43b6a4216b391ec37ce94733b/cloud/en-US/ws_index.htm ## Standards - cXML (Commerce XML) - authored and maintained by Ariba, the procurement interchange standard for PunchOut, OrderRequest and invoicing. DTD: http://xml.cxml.org/current/cXML.dtd - SCIM 2.0 - the SAP Ariba SCIM API implements /Users and /Groups with the standard `schemas` URN array and add|replace|remove PATCH operations. - OAuth 2.0 client credentials; mutual TLS available. - SOAP 1.1 / WSDL 1.1 for the 144-service web-services layer. ## Optional - Sample code: https://github.com/SAP-samples/ariba-extensibility-samples - SAP BTP procurement data extractor: https://github.com/SAP-samples/btp-procurement-data-extractor - SAP Community, SAP Ariba: https://community.sap.com/ - Vulnerability reporting: https://www.sap.com/report-a-vulnerability (from https://ariba.com/.well-known/security.txt) ## Not published - No OpenAPI or Swagger document served anonymously. - No AsyncAPI document. - No MCP server, hosted or stdio. - No A2A agent card at /.well-known/agent-card.json or /.well-known/agent.json on any Ariba or SAP host. - No first-party client SDK in npm, PyPI, Maven Central, NuGet, RubyGems, crates.io or pkg.go.dev. - No public status page (status.ariba.com does not resolve). - No published API price list; access is an entitlement of an SAP Ariba subscription.