Developers

Karibu ID with SAP Ariba — an integration recipe

Developer guide

A guide, not code, built only from Karibu ID's published contract (contracts/openapi.json, v0.57.0): the reader API, the reader webhooks, the exports and, for a platform, Connect (FA v5.7 §36.7, FA §17.6). It describes one way a buyer can bring Karibu ID records into supplier onboarding in SAP Ariba. Karibu ID has no partnership with SAP; SAP Ariba is a trademark of its owner. Karibu ID reports findings, never verdicts: whether to qualify a supplier stays the buyer's decision.

What you need

  • A reader organisation in Karibu ID with exports on, and a reader admin.
  • Middleware you run between the two (an integration suite or your own service) that can receive an HTTPS POST and call both APIs, and a store for the signing secret and the access token.

1. Invite suppliers from Ariba

  1. Export the suppliers you are onboarding (company name, registration number, a contact's work email, your reference) and send them to Karibu ID as one CSV: POST /v1/reader/invitations/imports (each row checked in plain words).
  2. Follow each invitation by its id: reader_invitation_status events (opened, accepted, declined, bounced, expired) and GET /v1/reader/exports/invitations?format=csv.
  3. When a company shares with you (share_granted), link the Ariba supplier to its KE.

2. Qualification evidence

  • Your own policy's statement on the record: run it with POST /v1/reader/policy-runs and list the statements with GET /v1/reader/exports/statements.
  • The record itself, signed: GET /v1/reader/exports/records/{ke}; attach it to the supplier's qualification.
  • Your own decision and its audit pack, where you record them in Karibu ID: GET /v1/reader/exports/decisions and GET /v1/reader/exports/audit-packs/{ke}/{pack_id}.

3. Changes after onboarding

Subscribe a webhook endpoint (POST /v1/reader/webhooks), verify KaribuID-Signature on every delivery (HMAC-SHA256 over <t>. and the raw body; 300 seconds), and route ledger_high, finding_new and report_superseded to the supplier's review in Ariba. The bodies carry ids only.

4. A procurement platform

If you run a procurement platform for many buyers, use Connect instead (see the Connect developer guide): a grant the company agrees to, for stated scopes and a fixed term, with its own webhooks (grant.created, record.updated, statement.ready and the others).

Mirrored from Karibu ID’s published integration recipes (commit 00ba731), built from contract version 0.59.0.