sap-mcp
MCP server for SAP S/4HANA via the ADT API. Runs locally over stdio.
Setup on a new machine
Prerequisites (install these first):
- Node.js >= 20.12 (needs
process.loadEnvFile; also providesnpm) — required - Claude Code — required to use the server (only the registration step needs it)
- Network/VPN reachability to your SAP hosts (e.g.
fiori-dev...) — required - git — optional; only used for
git clone. No git? See below.(To install on Windows:winget install --id Git.Git -e, then reopen yourterminal. macOS:brew install git. Verify withgit --version.)
Then:
git clone https://github.com/abap-studio/sap-mcp.git
cd sap-mcp
npm install
cp .env.example .env # PowerShell/CMD: copy .env.example .env
No git? Instead of
git clone, download the repo from GitHub: greenCode button -> Download ZIP, unzip it, thencdinto the folder andcontinue fromnpm install. (git is only nicer later, for pulling updateswithgit pullinstead of re-downloading.)
Now edit .env and fill in the real HOST/CLIENT for each system plusyour own SAP USER/PASS. The real hostnames are intentionally not in thisrepo — get them from whoever maintains it. Then verify and register:
node test.mjs # PASS = install OK (does NOT check credentials)
node test.mjs --live # PASS = credentials + SAP reachable <-- the real proof
# Register with Claude Code (use the ABSOLUTE path to server.js on this machine):
claude mcp add sap-adt --scope user -- node C:\Users\<name>\sap-mcp\server.js
Start a fresh Claude Code session afterwards for the server to load.
node test.mjsreports PASS even before you edit.env— it only checks thatthe server boots and loads profiles.node test.mjs --liveis what actuallyconfirms your credentials and SAP connectivity.
Updating an existing install
If you already have sap-mcp set up, pull the latest and restart Claude Code:
cd sap-mcp
git pull # no git? re-download the ZIP over your folder (keep your .env)
npm install # only needed if dependencies changed; harmless to run anyway
node test.mjs # confirm it still boots
You do not need to re-run claude mcp add — the registration persists. Your.env is never touched by an update (it's gitignored), so your credentials andprofiles carry over.
Important — quit and restart Claude Code after updating. New tools are onlydiscovered when a Claude Code session starts. If an update adds a tool(like
create_programbelow), a reconnect or/mcprefresh is not enough:fully quit Claude Code and open a fresh session. (Behaviour-only changes toexisting tools just need the server to respawn, which a new session also does.)
To confirm the update loaded, start a fresh session and ask Claude to runlist_servers, or check that the new tool is available.
What's new (2026-07)
This release roughly doubles the toolset (25 → 45). These are new tools, so youmust fully quit and restart Claude Code after updating (see the note above).
- Source editors for the objects that were create-only. You could previouslycreate a class but never edit one — that's fixed:
update_class/patch_class,update_bdef/patch_bdef,update_srvd/patch_srvd,update_cds/patch_cds,update_function_module. Each locks → writes → unlocks and can activate;thepatch_*variants do a surgical exact-string replace and refuse to writewhen the target text matches zero or more than one time. syntax_check— run ADT's syntax/consistency check on an object withoutactivating it. Read-only and safe on any profile, including production. Use itafter writing source and beforeactivate_object; passversion:"inactive"to check source you have saved but not yet activated.- New object types:
create_structure/update_structure/patch_structure(DDIC structures),create_interface/update_interface/patch_interface,create_ddlx/update_ddlx/patch_ddlx(CDS metadataextensions — the UI annotations a Fiori Elements app needs),create_domain,create_data_element,create_function_group,create_function_module. where_used— the ADT where-used list: find everything that depends on anobject before you change or delete it. Read-only; results are capped and thetrue total is always reported (a common table can have tens of thousands).run_atc— run an ATC (ABAP Test Cockpit) static-analysis check on anobject and report the findings. Read-only. Picks up the system's configuredcheck variant automatically. Usesyntax_checkfor fast error checking andrun_atcbefore releasing a transport.list_transports— find your open transport requests, so you can pass areal request number to the create/update tools.- Fix:
get_object_infonow sendsAccept: */*, so DDIC metadata (domains,data elements, tables) is readable instead of failing with HTTP 406. update_table/patch_table— modify an EXISTING DDIC table's source:update_tableoverwrites the whole definition,patch_tabledoes a surgicalexact-string replace (add/change a field). Both lock → write → unlock andoptionally activate; blocked on production. Mirrors theupdate_program_source/patch_program_sourcepair. New tools — restartClaude Code after updating (see above).create_program— create a brand-new classic ABAP report (executableprogram,PROG/P) and activate it in one call. Previously the server couldonly edit an existing program; now it can create one from scratch. Refusesto run on production profiles. This is a new tool, so you must restartClaude Code after updating (see above).- Data-driven profiles — profiles are now discovered from your
.env: everySAP_<KEY>_HOSTyou define becomes a switchable profile named<KEY>, with nocode change needed to add a system. Profile switching is case-insensitive. - Production write-block widened — writes are now blocked on both
ABLP(production) andABLQ(QAS). Read access still works on every profile.
Testing your install
The node test.mjs / node test.mjs --live steps above are the self-check(npm test runs the structural one). The bundled harness talks to the serverover stdio — no Claude Code needed.
Once registered, you can also verify through Claude Code — ask it to runlist_servers, or a query_table with SELECT MANDT, MTEXT FROM T000.
Credentials
Each person uses their own named SAP user per system. All connectiondetails and credentials live in .env (gitignored); server.js contains noreal hostnames. Never commit or share .env — sharing a service account breaksthe SE24/transport audit trail and usually violates license terms.
Fill in HOST, CLIENT, USER and PASS for each profile in .env. EverySAP_<KEY>_HOST you define becomes a switchable profile named <KEY> — thelist below is illustrative, not fixed, so add or rename systems freely:
| Profile | Role |
|---|---|
ABLD |
Development |
dev120 |
Development (client 120) |
snet |
QA/Test |
ABLQ |
QAS (read-only) |
ABLP |
Production |
snet2 |
S/4HANA on-prem |
Protecting a system from writes
Add a READONLY (or PROD) flag next to any profile in .env and every writeon it — create, edit, activate — is refused. Reads keep working:
SAP_PRD2_HOST="https://sap-prd2.example.com:44300"
SAP_PRD2_CLIENT="100"
SAP_PRD2_USER=""
SAP_PRD2_PASS=""
SAP_PRD2_READONLY=true # or SAP_PRD2_PROD=true
Accepted values: true / 1 / yes / y / X. Do this for everyproduction system you add — no code change needed. AddSAP_PRD2_LABEL="Production" to control how the profile is described bylist_servers.
The flag protects a profile, not a system. If two profiles point at thesame host and client, flag both — otherwise writes still reach that clientthrough the unflagged one.
ABLP and ABLQ are also blocked by a built-in list in server.js, so theystay protected even if the flag is missing. The two sources are additive: amissing flag can never unblock a system that was protected before.
Run list_servers to confirm — protected profiles are shown as [read-only].A blocked write reports which rule stopped it.
Disclaimer
This software is provided "as is", without warranty of any kind, express orimplied. You use it entirely at your own risk.
- No liability. The author accepts no responsibility for any damage, dataloss, downtime, security incident, or other harm — to your computer, your SAPsystems, or your data — arising from the use, misuse, or inability to use thissoftware.
- Your access, your responsibility. You supply your own SAP credentials in
.env. Keep that file private, use your own named user, and connect only tosystems you are authorized to access. - Production risk remains. Writes to the
ABLP(production) profile areblocked, but the tool can still read from any system you configure. Use itat your own discretion. - Compliance is on you. Ensure your use complies with your organization'spolicies and your SAP license terms before connecting.
- Not affiliated with SAP. SAP and S/4HANA are trademarks of SAP SE. Thisis an independent, unofficial tool and is not endorsed by or affiliated withSAP SE.
License
MIT. The license text includes the binding "as is" / no-warranty /no-liability terms; the Disclaimer above restates them in plain language.