Three ways to your ERP. No VPN. No tunnel.
Transport and ERP authentication are deliberately kept orthogonal – tools, policies, and audit trails behave identically no matter which mode you choose.
Requirement
Every one of the three paths requires a Microtech Gen24 installation with the GraphQL interface enabled. SuperBRAIN reads your tenant's schema live via introspection – no redundant, second copy of your business data is ever created.
1. Direct HTTPS
SuperBRAIN connects directly to an externally reachable GraphQL interface of your Microtech Gen24. Ideal for a quick pilot when an endpoint can already be exposed.
- No connector rollout required
- ERP credentials are held only as encrypted secret references
- Requires an externally reachable, firewall-controlled GraphQL endpoint
2. Connector with a technical user
The BVP SuperBRAIN Connector runs as a Windows service inside your network or directly on the Microtech server, opening only an outbound, encrypted connection to the platform.
- Outbound WSS/TLS 1.3 connection – no inbound firewall rule required
- ERP credentials stay local, DPAPI-protected, never leave your network
- Only approved, signature-verified GraphQL operations are ever transported
3. Connector with OAuth Client Credentials
Same connector approach, but ERP authentication uses Microtech's own OAuth (Client Credentials) against a confidential, service-bound technical user – no manual password management.
- Rotatable, confidential client secrets instead of static passwords
- Scope-bound access to exactly the tenant required
- Our recommended path for production, long-term connections
What the Connector explicitly is not
The BVP SuperBRAIN Connector is not a generic TCP, SOCKS, VPN, or HTTP proxy. It transports only approved, manifest-bound Microtech GraphQL operations to exactly one locally configured ERP endpoint. Unknown operations are rejected locally before they ever leave the network.