> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.basement.chat/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.basement.chat/_mcp/server.

# Connection types

A SAP system has three doors for reads. The app tries **all** the doors, in the order of the table below. The connection opens through the door that works. You do not select a door. If a door does not work, this page tells you what to ask the customer.

## The three methods

| Method             | What it is                                                                   | Port (through the VPN)                 | What SAP needs                                                                                                    | What it serves                                                                                                  |
| ------------------ | ---------------------------------------------------------------------------- | -------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- |
| **ADT over HTTPS** | The path that Eclipse (ADT) uses: the web server of SAP, with a certificate. | `443` + instance (for example `44301`) | The service `/sap/bc/adt` active in SICF. An HTTPS port in the ICM, with a certificate that your computer trusts. | All ADT reads: code, search, dictionary, dumps, where-used list.                                                |
| **ADT over HTTP**  | The same path, without encryption.                                           | `80` + instance (for example `8001`)   | The ADT service active. An HTTP port.                                                                             | Reads only: code, search, dumps. Table queries and the where-used list need HTTPS. The app shows **HTTP only**. |
| **ADT over RFC**   | The same ADT reads, through the RFC port instead of the web server.          | The RFC port                           | RFC works (see below). It works also when the ADT web service is off.                                             | Code, search, dictionary, dumps, where-used list.                                                               |
| **Classic RFC**    | The standard communication port of SAP. SAP GUI uses it.                     | `33` + instance (for example `3301`)   | The RFC gateway port is reachable through the VPN. The user has RFC authorization.                                | Tables, system information, jobs, system log, transports. This method serves the most tools.                    |

On most systems today: **classic RFC** works as soon as the VPN reaches the port. **ADT over RFC** works with it. **ADT over HTTPS** works only when the Basis team activated the service and the secure port. Many customers have HTTP only, or no web port.

## How to read the result

After the connection, each method shows a state:

* **Works**: the method answered. The tools of this method are available.
* **HTTP only, no encryption**: the web server answered without HTTPS. It serves the code reads. The other methods do the other reads.
* **Failed**: the method did not answer. The line shows the cause (port closed, service inactive, certificate not trusted). **What to do** shows the correction.
* **Not tried**: the app stopped before this method. When SAP **refuses the logon** (user, password or language), the app does not try the other methods with the same password. This protects your user from a lock.

The connection is **ready** when one method works. More methods give more tools.

## What to ask the Basis team of the customer

Ask only for what is missing. Use the words of the app under **What to do**:

| The app shows                    | The request                                                                                                                                           |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| RFC: port closed                 | Open the port `33` + instance of the SAP server on the VPN and the firewall, for the computers of the analysts.                                       |
| RFC: the server refused its name | SAP accepts only its own name. Compare the **Host** of the connection with SAP Logon.                                                                 |
| ADT: port closed                 | Create an HTTPS port (preferred) or an HTTP port in the ICM (transaction `SMICM`). Open the port on the VPN.                                          |
| ADT: service inactive            | Activate the service `/sap/bc/adt` in transaction `SICF`.                                                                                             |
| ADT: HTTP only                   | Create the HTTPS port in the ICM with a valid certificate. Without it, only code reads go through ADT. Tables and the where-used list go through RFC. |
| ADT: certificate not trusted     | Use a certificate from an authority that your computer trusts, or install the certificate chain of the customer.                                      |
| No authorization                 | Your user needs the RFC authorization (`S_RFC`) for the read modules. The Basis team checks `SU53` directly after the attempt.                        |

> **Note**
>
> The Gateway makes none of these changes in SAP. The Basis team makes them in SAP GUI. The app only shows what is missing.