Connect SAP SuccessFactors
Import your workers and their current job from SAP SuccessFactors, the HR platform. You connect Oho to SuccessFactors once, and Oho creates your workers and keeps them in step with SuccessFactors on the schedule you choose — so people don't have to be added in two places.
This connector is still being rolled out. It imports workers and their current job, along with worker status and organisation details such as department and work location — but not full job history yet. If you hit something unexpected, contact support@weareoho.com.
Your SuccessFactors workers in Oho — each ready for credentials to be added and checked — kept in step with SuccessFactors, without maintaining two lists.
Before you start
You'll need:
- Your people already recorded in SuccessFactors, with the details you want in Oho — their names, contact details, and current job.
- A SuccessFactors administrator with access to the Admin Center, to register an OAuth client in Step 1. This connector needs IT involvement, so loop them in early.
- Your SuccessFactors Company ID and API server URL (specific to your data centre, for example
apiXX.sapsf.com).
Step 1: Get your auth details
Admin access to the SuccessFactors Admin Center. The OAuth client and certificate are set up inside SuccessFactors, not in Oho.
SuccessFactors uses OAuth 2.0 with a SAML bearer assertion. Your administrator registers an OAuth client, which issues an API key, and you download a certificate Oho uses to sign in.
- In SuccessFactors, go to Admin Center → OAuth Configuration for OData → Register Client Application.
- Register the client for the Oho integration; SuccessFactors generates an API key.
- Under Access Settings, tick SAML 2.0 Bearer Assertion and set the SAML 2.0 Audience to
www.successfactors.com. - Generate and download the X.509 certificate (and its private key) for the client.
Technical detail: the SAML bearer assertion flow
- Oho signs a SAML assertion with the client certificate and exchanges it, together with the API key, for an OAuth access token — then uses that token to read the OData API.
- The client must be granted access to the OData entities Oho reads. If the certificate is rotated in SuccessFactors, reconnect the integration with the new certificate.
- See the shared Get your auth details.
The certificate and private key grant access to worker PII. Never post them in email, chat, or a ticket, and re-issue them if the connection is removed.
Expected outcome: you have your SuccessFactors API key, Company ID, API server URL, and certificate ready to enter into Oho.
Step 2: Connect it in Oho
In the left menu under Admin, click Integrations, then start a new integration.

Pick SAP SuccessFactors from the list of sources.

Enter your API key, Company ID, and API server URL, upload the certificate, then click Next.

Expected outcome: Oho signs in to SuccessFactors and moves you on to field mapping.
Step 3: Map your fields
Oho creates one worker per SuccessFactors user. It recognises a returning worker by their user ID, carried on source.externalId — so a re-sync updates the existing worker in place rather than creating a duplicate.
SuccessFactors has its own names for things such as status, department, and location; the setup screen asks you to line each one up with its Oho value before your first sync. For what each field expects, which are required, and how re-syncs avoid duplicates, see the shared Map your fields reference, and the SAP SuccessFactors integration reference for what this connector imports at a glance.
A SuccessFactors value you leave unmapped still imports, but Oho can't place it correctly until it's mapped. If a new value appears in SuccessFactors later, Oho flags it so you can map it.
Expected outcome: every SuccessFactors value the setup screen lists maps to its Oho equivalent, and each worker carries their user ID as the match key.
Step 4: Set the schedule
Choose how often the sync runs, then name it and save.
- Once — a one-off load to get started.
- Recurring — Oho re-reads SuccessFactors on a schedule, so new starters, role changes, and terminations flow through automatically. The OAuth client and certificate must stay valid for future runs.

Expected outcome: the connection is saved and scheduled, and appears in your Integrations list.
Step 5: Run & verify your first sync
Run it now with Save & Run, or wait for the first scheduled run. Once it's run, confirm your people are in: they appear under All Workers, and each credential you later add is checked against its official source (see One-off verification).

If the run didn't bring everyone in, check the run history and the Common questions below.
Expected outcome: your people are in Oho under All Workers, ready for credentials to be added and checked.
What happens next
- Your people appear under All Workers, ready for checks.
- To keep those checks current, add a verification source for the credential types you hold — synced credentials then verify at the register automatically.
- If recurring, you don't re-import by hand — change it in SuccessFactors and Oho picks it up on the next run.
Common questions
Sign-in failed at setup. Confirm the SAML audience is set to www.successfactors.com and the certificate uploaded matches the registered client. Check the API server URL is the one for your data centre.
The sync found nothing. The OAuth client may lack access to the OData entities Oho reads. Grant it read access to those entities, then run again.
The sync stopped after a certificate change. The certificate was rotated in SuccessFactors — reconnect the integration in Oho with the new certificate.
I don't see Integrations. This is an admin area — if it's not in your menu, ask an admin in your organisation, or contact support@weareoho.com.
Related
- SAP SuccessFactors integration — what the SuccessFactors connector imports, at a glance
- Add a data source — all the ways to bring data into Oho
- Integrations — every source Oho can connect to