Description
You can use SAP SuccessFactors to integrate with Exclaimer through Bindbee. Exclaimer connects to SAP SuccessFactors using an OAuth2 client application that you register in SAP SuccessFactors. Bindbee uses these credentials to retrieve employee contact data and sync it to Exclaimer for use in email signatures. During setup, you may see Bindbee URLs, authentication prompts, or connection windows.
This integration is available for Exclaimer subscriptions using Microsoft 365 and Google Workspace.
Set up SAP SuccessFactors for Exclaimer integration (SAP SuccessFactors)
Follow the steps below to gather the details required from SAP SuccessFactors before connecting it to Exclaimer.
• Admin access to SAP SuccessFactors, including permission to register OAuth2 client applications.
• Permission to view system version information.
• Access to the Exclaimer subscription (Pro Plan).
• (Optional) A dedicated, scoped integration user. For more information, see the section (Optional pre-requisites) Set up a scoped integration user.
• Admin access to SAP SuccessFactors, including permission to create user accounts.
Set up a dedicated SAP SuccessFactors user for this integration rather than using an administrator account. This limits the data Exclaimer can access. SAP SuccessFactors does not assign permissions to an OAuth2 client; instead, each API call runs under the linked user account and can only access data that the user is authorized to view.
Create a dedicated integration user
Create a user account in SuccessFactors dedicated to running this connection. Your SuccessFactors administrator can create the account using your organization's standard process.
• Give the account a name that clearly identifies its purpose, such as exclaimer_integration.
TIP! Copy the User ID securely. It will be used later.
• Use a shared team mailbox for the email address instead of an individual's mailbox. This ensures password and access notifications reach the team responsible for the account.
• Do not include the account in any manager or HR reporting structures.
Create a permission group
Create a permission group for the integration user. This ensures the role you create in the next step applies only to the integration account.
- In the search bar, enter Manage Permission Groups and open the page.
- Select Create New.
- In Group Name, enter a name that identifies the connection, such as Exclaimer Integration.
- Set User Type to Employee.
- Under Choose Group Members, add only the integration user (User ID) you created earlier.
- Leave Exclude and Granted Permission Roles empty. You will assign the permission roles later.
- Select Done.

Example image showing the Permission Group screen.
Create a permission role
Create a permission role that defines which data the integration user can access.
- In the search bar, enter Manage Permission Roles and open the page.
- Select Create.
- Enter a role name that clearly identifies the connection, such as Exclaimer Integration Role.
- Set User Type to Employee.
- Select Permissions to open the full list of user and administrator permissions.
- Select only the permissions required for your integration.
At a minimum, select:
- General User Permission → User Login. This allows the integration user to authenticate.
-
Manage Integration Tools → the permission that provides OData API access.

Example image showing the Add Permissions screen.
Assign the role to the group
Assign the permission role to the group you created earlier in Create a permission group. This activates the role and determines which employee records the integration can access.
- After saving the role, select Yes when prompted to continue to the role assignment. You can also assign the role later from Manage Permission Roles.
- Enter a name for the assignment that clearly identifies its purpose, such as Exclaimer Integration Assignment.
-
Under Grant Access To, select From groups, then select the permission group you created in step Create a permission group.
IMPORTANT! Do not leave this set to All. This grants the role to every employee in your SuccessFactors instance. - Under Define a Target Population, select Everyone to allow a full sync, or select a permission group to limit the sync to a specific subset of employees.
- Save the assignment.
Verify the effective permissions
SuccessFactors permissions are additive. A user's effective access includes permissions from every role assigned to that user, including roles assigned to all employees in your instance. Verify the effective permissions now to ensure the integration user has only the intended access.
- In the search bar, enter RBP Troubleshooting and open the page.
- Enter the integration user in Access User 1 and select Search.
- Review the roles shown in the results.
You should see only the role you created in Step Create a permission role. If additional roles appear, the integration user may be inheriting broader access from another assignment. Ask your SuccessFactors administrator to exclude the account from that assignment, or confirm whether additional access is required.
To find your API server:
- Navigate to SAP SuccessFactors API server / data center reference page on the SAP Help Portal.
-
Locate the API server value that corresponds to your SAP SuccessFactors login domain.
NOTE: The API server generally mirrors your login domain with an 'api' prefix. For example, a login domain such as 'https://salesdemo2.successfactors.com' corresponds to an API server beginning 'apisalesdemo2'.TIP! Record this value securely. This will be required for the integration.
To find your Company ID:
- Select the initials icon in the header bar, select Show version information.

Example image showing the Show version information option.
-
Locate the Company ID.
Example image showing where to find the Company ID.
NOTE: The credentials in the screenshot are for example purposes only. Please extract your Company ID.TIP! Record the Company ID securely. It will be required for the integration.
To confirm your username:
The username is the User ID you use to sign in to your SAP SuccessFactors dashboard. If you set up a scoped integration user (see Optional pre-requisites: Set up a scoped integration user), enter that account's User ID instead.
Exclaimer uses the permissions assigned to the account you enter. Using a scoped integration user therefore limits the employee data Exclaimer can access.
To register an OAuth2 Client Application:
- In the search bar, enter Manage OAuth2 Client Applications.
- Select Register Client Application.

Example image showing the search bar. Select Register Client Application.
- In Application Name, enter a relevant name for the application.
- In Application URL, enter your application URL.

Enter the Application Name and Application URL.
- Select Generate X.509 Certificate.
- In Common Name (CN), enter a common name for the certificate.

Enter the Common Name (CN).
- Select Generate.
The X.509 Certificate field is populated automatically.
Example image showing the X.509 Certificate.
-
Select Download to save the certificate file.
TIP! Copy the private key securely. It is entered as the Client Secret when integrating with Exclaimer.WARNING! Copy only the private key value from the downloaded certificate file. Do not include the header/footer lines.
Example image showing the downloaded version.
- Select Register to complete registration.
To get your Client ID:
- In the Manage OAuth2 Client Applications, locate the application you registered and select View.

Select the View option.
-
Copy the value shown in the API Key.

Example image showing the API Key.
TIP! Record the API Key securely. It is entered as the Client ID when integrating with Exclaimer.
Access the SAP SuccessFactors integration in Exclaimer
To access the SAP SuccessFactors integration:
-
From the header bar, select the cogwheel icon, then select Sender Management.

This example image is for a Microsoft 365 subscription and shows the Settings menu.
- Navigate to the Enable HRIS access section.
- From the drop-down, select SAP SuccessFactors.
Connect Exclaimer to SAP SuccessFactors (Exclaimer)
• Use an Exclaimer Pro subscription.
• Allow the required Bindbee domains in your network. These domains must load in the browser for the connection window to work:
• cdn.bindbee.dev
• *.bindbee.dev to cover additional subdomains used during the connection flow (for example, API callbacks and authentication redirects)
Have the following SAP SuccessFactors details ready:
• API server
• Company ID
• Username
• Client ID (API Key)
• Client Secret (private key)
To connect to your HRIS to allow Exclaimer to synchronize user contact details:
- From the drop-down list, select SAP SuccessFactors.

From the drop-down, select SAP SuccessFactors.
-
Select Connect.
An authorization window is displayed.

Example image in Exclaimer when trying to connect to the SAP SuccessFactors system.
-
Select Allow and Continue.
WARNING! If the authorization window is not displayed, allowlist cdn.bindbee.dev (and preferably *.bindbee.dev) to ensure the Bindbee SDK loads correctly in the browser.
- Enter your API Server, then select Continue.

Example image in Exclaimer when trying to connect to the SAP SuccessFactors system. Enter your API Server.
- Enter your Company ID.
- Enter your username.

Example image in Exclaimer when trying to connect to the SAP SuccessFactors system. Enter your Company ID and username.
- Select Continue.
- Enter your Client ID (API Key).
- Enter your Client Secret (private key).

Example image in Exclaimer when trying to connect to the SAP SuccessFactors system. Enter your Client ID and Client Secret.
-
Select Connect to complete the integration between Exclaimer and SAP SuccessFactors using Bindbee.
WARNING! Keep the window open until the connection is complete. If you close it too soon, the connection may not finish setting up, and it may not appear as connected in Exclaimer.If you try to connect to SAP SuccessFactors again, you may see a message saying that the connector already exists. If this happens, raise a support ticket so the team can assist you.
- Once a connection is established, the status displays as Connected in Exclaimer.

Once a connection is established with the SAP SuccessFactors system, the Connected text is displayed within Exclaimer.
Manage your SAP SuccessFactors connection (Exclaimer)
Follow the options to manage your SAP SuccessFactors connection:
To re-connect to the SAP SuccessFactors system:
- Select Re-connect.

Select Re-connect.
A message is displayed that reconnecting will remove your existing connection to SAP SuccessFactors, and any data will no longer be available, and a new connection flow will start automatically.
Select OK to reconnect to the SAP SuccessFactors system.
- Select OK to continue.
To disconnect from the SAP SuccessFactors system:
- Select Disconnect. This removes your connection and any synced data.

Select Disconnect.
A message is displayed that disconnecting will entirely remove your connection to SAP SuccessFactors, and any data from the system will no longer be available.
Select OK to disconnect from the SAP SuccessFactors system.
- Select OK to continue.
SAP SuccessFactors connectors automatically synchronize data on a predefined schedule.
To run a manual sync to immediately update employee data in Exclaimer:
- Select Sync Now.

Select Sync Now to start a manual sync.
Troubleshooting
If the authorization window does not appear in Exclaimer:
- Ensure the following domains are allowlisted in your network or browser security tools: cdn.bindbee.dev, and *.bindbee.dev.
- Verify that browser extensions or content blockers are not preventing the page from loading.
- Refresh the browser and try again.
If the connection to SAP SuccessFactors fails during setup, verify that:
- The API server value matches your SAP SuccessFactors login domain.
- The Company ID is correct and copied from the Show Version Information screen.
- The username has permission to access the employee data required for the integration.
- The Client ID (API Key) and Client Secret (private key) are entered correctly, and the private key does not include the certificate header/footer lines.
- The registered OAuth2 Client Application has not been deleted or deactivated in SAP SuccessFactors.
If a scheduled or manual sync does not complete successfully:
- Confirm the connection still shows as Connected in Exclaimer.
- Verify the OAuth2 Client Application credentials have not expired or been revoked in SAP SuccessFactors.
- Check that the username used for the integration still has permission to access employee data.