SAP Home Learn Build Integrate Model Operate Extend with AI ConnectTutorial navigator Knowledge Graph API Devtoberfest Developer Advocates App Space

Manage my Account SAP Devs YouTube ↗ Learnings ↗ Community ↗ Provide Feedback ↗
Logout
โคข Open full site

Enhance ISLM Connectivity to SAP AI Core with mTLS

Enable certificate-based authentication for Intelligent Scenario Lifecycle Management (ISLM) to communicate with SAP AI Core.

Overview

🎓 intermediate 25 min. SAP S 4hanaIntermediateArtificial IntelligenceSAP Ai Core

You will learn

  • โœ”Generate and manage client certificates in SAP BTP
  • โœ”Enable certificate-based authentication and extend the SAP AI Core integration with mTLS
  • โœ”Update the ISLM reuse connection in SAP S/4HANA to use mTLS
Daniel Funkert D Daniel Funkert April 28, 2026
Created by April 28, 2026
Contributors

Prerequisites

Prerequisites

Steps

Step 1 Overview
โ€”

In this tutorial, you enhance the authentication of Intelligent Scenario Lifecycle Management (ISLM) with mutual TLS (mTLS) for communication with SAP AI Core. You configure certificate-based authentication, create the required service bindings, and update the communication setup in SAP S/4HANA.

This tutorial demonstrates a generic approach. You can also use your own public key infrastructure (PKI) if your certificates are issued by a trusted certificate authority supported by SAP BTP.

The diagram illustrates how ISLM is embedded in the overall architecture and how it connects to SAP AI Core. This tutorial focuses on the SAP S/4HANA and SAP BTP components highlighted in the diagram.

Tutorial Overview
Tutorial Overview

Further Information:

Step 2 Generate a Client Certificate in SAP BTP
+
Step 3 Create a Destination Service Instance for API Access
+
Step 4 Download the Client Certificate using the Destination Service API
+
Step 5 Import the Client Certificate into SAP S/4HANA
+
Step 6 Export Public Certificate from ISLM Keystore for mTLS
+
Step 7 Create an SAP AI Core Service Binding with mTLS Authentication
+
Step 8 Import the Root CA Certificate into the Trust Store
+
Step 9 Create an OAuth 2.0 Client for mTLS Authentication
+
Step 10 Update the Destination with the New OAuth Client
+
Step 11 Test the Usage Type for the Generative AI Scenario with mTLS
+
Step 12 Test yourself
+

Resources

Discussion

Share feedback on this tutorial or join the conversation in SAP Community.

Submit detailed feedback Discuss in Community
Steps
Step 1 of 12
1. Overview 2. Generate a Client Certificate in SAP BTP 3. Create a Destination Service Instance for API Access 4. Download the Client Certificate using the Destination Service API 5. Import the Client Certificate into SAP S/4HANA 6. Export Public Certificate from ISLM Keystore for mTLS 7. Create an SAP AI Core Service Binding with mTLS Authentication 8. Import the Root CA Certificate into the Trust Store 9. Create an OAuth 2.0 Client for mTLS Authentication 10. Update the Destination with the New OAuth Client 11. Test the Usage Type for the Generative AI Scenario with mTLS 12. Test yourself

Learn more →