Install
$ agentstack add mcp-coaspe-sap-abap-mcp ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
sap-abap-mcp
A local Model Context Protocol server that lets Codex and Claude work with SAP ABAP through the official ABAP Development Tools (ADT) HTTP services.
It can inspect and edit ABAP source, run quality checks, manage transports, use abapGit and the RAP generator, inspect runtime data, compare systems, and perform repository refactorings without VS Code, SAP GUI, or an ABAP FS virtual workspace.
Quick start
You need Node.js 20 or later, network or VPN access to SAP, and an SAP HTTPS URL, three-digit client number, username, and ADT Basic Auth permission.
1. Configure SAP
Windows:
npx.cmd @coaspe/sap-abap-mcp@latest setup
macOS or Linux:
npx @coaspe/sap-abap-mcp@latest setup
The wizard calls the local connection alias Server name and the endpoint SAP URL. Windows and macOS validate SAP before saving and protect the password with DPAPI or Keychain. Linux saves only non-secret settings and prints the password environment-variable commands to run before starting the MCP client.
2. Register the MCP server
After setup, run the command for your client on Windows:
codex mcp add sap-abap -- npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest serve --profile DEV100
claude mcp add --transport stdio --scope user sap-abap -- npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest serve --profile DEV100
On macOS or Linux, replace npx.cmd with npx:
codex mcp add sap-abap -- npx --yes --prefer-online @coaspe/sap-abap-mcp@latest serve --profile DEV100
claude mcp add --transport stdio --scope user sap-abap -- npx --yes --prefer-online @coaspe/sap-abap-mcp@latest serve --profile DEV100
Replace DEV100 with the Server name selected in the wizard. Restart the client, then use codex mcp list, claude mcp get sap-abap, or /mcp to confirm that the process starts. The completed wizard already performs live SAP verification; /mcp alone does not prove that SAP authentication succeeded.
Prefer a plugin install? Follow [Claude Code and Codex plugin marketplaces](#claude-code-and-codex-plugin-marketplaces); the included setup skill guides the same local wizard without putting the SAP password in chat. See the detailed [Windows](#detailed-setup-on-windows), [macOS](#detailed-setup-on-macos), and [Linux](#linux-and-containers) sections for platform-specific behavior and server management.
ABAP FS parity status
The pinned ABAP FS 2.6.5 source exposes 43 MCP tools. This server provides a strict-compatible subset of 42; the omitted tool is manage_subagents, which depends on the VS Code agent host. With 10 headless feature extensions and read_deferred_result, this server advertises 53 tools in total.
The first development-parity slice implements BDEF source creation, one-request batch activation, class-runner execution, the ABAP FS REPL contract, and detailed semantic inspection. These SAP-dependent capabilities remain unverified until they succeed against the selected live connection; call get_sap_capabilities for per-connection evidence.
Snippet execution requires ZCL_ABAP_REPL and an active SICF service at /sap/bc/z_abap_repl. Generic report/program-console execution is not implemented.
What it supports
The server provides all 42 strict-compatible headless tools from the pinned ABAP FS baseline, ten grouped feature extensions, and one infrastructure tool for continuing oversized results.
| Area | Capabilities | |---|---| | Connections | Multiple SAP profiles, lazy login, system metadata, ADT discovery export | | Repository reads | Search, metadata, source ranges, batch reads, URI reads, source search, enhancements | | Semantic services | Completion details, definition lookup, documentation, type hierarchy, components, quick-fix discovery, SAP formatter preview | | Source writes | Exact source replacement, BDEF source creation, syntax diagnostics, single- and one-request batch activation, text elements | | Refactoring | Rename, package move, extract method, quick-fix application, formatting, deletion | | Quality | ABAP Unit, ATC, diagnostics, test-include creation | | Transports | List, details, objects, compare, create, release, delete, owner/user management, object resolution | | Versions | Active revision history, revision comparison, inactive source, guarded revision restore | | abapGit | Repository list, remote information, create, pull, unlink, stage, push, check, branch switch | | RAP | Availability, paged schema, defaults, validation, preview, generation, service binding details and publication | | Runtime | Guarded class-runner and fixed-contract ABAP REPL execution, debugger, breakpoints, stack, variables, dumps, traces, heartbeat checks | | Cross-system | Source comparison across configured SAP systems | | Dependency analysis | Bounded where-used dependency graph | | SAP GUI integration | Validated WebGUI transaction URL generation and optional local launch | | Data | Read-only ADT SQL queries with bounded or file-based output | | Artifacts | Mermaid validation/viewer and DOCX test documentation |
The ten grouped extension tools are:
inspect_abap_coderefactor_abap_codemanage_abapgitmanage_rap_generatormanage_abap_versionscompare_abap_systemsget_abap_dependency_graphrun_sap_transactionget_sap_capabilitiesrun_abap_application
Grouping related actions keeps the tool-schema footprint lower than exposing every operation as a separate MCP tool. read_deferred_result is the additional infrastructure tool; it reads the remaining UTF-8 chunks of a large result without repeating the SAP operation.
MCP directories and registries
The canonical registry identity is io.github.Coaspe/sap-abap-mcp, defined in [server.json](server.json). Directory installs must run this package as a local stdio server; SAP profiles and credentials stay on the user's machine and are never hosted by a registry.
Before the first SAP-facing request, create and verify at least one local SAP profile using the commands in [Quick start](#quick-start) or [llms-install.md](llms-install.md). The Claude plugin may start successfully without a profile; after installation, run /sap-abap-mcp:sap-abap-setup to complete local SAP setup. A generic registry launch runs @coaspe/sap-abap-mcp with the serve argument and exposes all locally configured profiles; every SAP-facing tool still requires an explicit connectionId.
Registry publication does not change the live-evidence boundary. SAP-dependent development-parity capabilities remain unverified until they succeed against the selected live connection.
The public Smithery listing installs the validated local MCPB bundle and exposes all 53 runtime tools.
Privacy Policy
SAP ABAP MCP runs locally and does not send SAP profiles, credentials, source code, or tool results to a publisher-operated service. It communicates only with destinations selected by the user, including the configured SAP system and the user's MCP host. See the complete [PRIVACY.md](PRIVACY.md) and [TERMS.md](TERMS.md).
Claude Code and Codex plugin marketplaces
This repository is also a dual-compatible plugin marketplace. The plugin starts the same npm latest package as a local stdio process, so SAP profiles, credentials, and ADT traffic stay on the user's computer. Profiles are user-scoped outside the plugin cache and survive plugin updates.
Claude Code:
/plugin marketplace add Coaspe/sap-abap-mcp
/plugin install sap-abap-mcp@coaspe-sap
/reload-plugins
Run the namespaced setup skill after reloading:
/sap-abap-mcp:sap-abap-setup
The skill reuses an existing profile or guides profile creation, local password entry, and live ADT verification. Use /mcp to confirm that the sap-abap process is connected, but do not treat that status as proof that an SAP profile is authenticated; the setup skill verifies SAP with doctor.
Codex:
codex plugin marketplace add Coaspe/sap-abap-mcp
Then install SAP ABAP MCP from the Coaspe SAP Developer Tools marketplace in the Codex app and start a new task. Ask Codex to set up SAP ABAP MCP; the included sap-abap-setup skill keeps passwords out of chat and guides profile creation, authentication, and live ADT verification.
Prerequisites
Ask your SAP administrator for:
- The SAP HTTPS base URL, for example
https://sap-dev.company.com - The three-digit SAP client number
- Your SAP user name
- ADT development permissions required by the operations you intend to use
- Confirmation that
/sap/bc/adtand Basic Auth are enabled
Your machine needs:
- Node.js 20 or later
- Codex or Claude Code
- Network or VPN access to SAP
- npm registry access to install the public package
Verify Node.js first:
node --version
Detailed setup on Windows
1. Run interactive setup
npx.cmd @coaspe/sap-abap-mcp@latest setup
The first run may ask whether npm may download the package; enter y to continue. The setup wizard collects the SAP URL, client, username, environment, and optional writable-package restriction. Server name is the local name used later as connectionId, for example DEV100. Keep production servers classified as production; they are read-only even if the package restriction is empty.
When SAP password: appears, enter the password and press Enter; the input remains hidden. The server configuration and password are stored only after the MCP validates the credentials against SAP. Windows protects the password with DPAPI and never writes it to the profile file.
The setup command is one line in both PowerShell and Command Prompt. For advanced multiline commands, PowerShell continues a line with a backtick (` `), while Command Prompt (cmd.exe) uses a caret (^`); do not mix them.
2. Verify ADT connectivity
npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest doctor DEV100
A completed setup already performs this live check. Run doctor again whenever you want to recheck ADT connectivity; a successful response contains "ok": true.
3. Register the MCP server
Codex CLI:
codex mcp add sap-abap -- npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest serve --profile DEV100
Claude Code:
claude mcp add --transport stdio --scope user sap-abap -- npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest serve --profile DEV100
Restart the client after registration. Use codex mcp list, claude mcp get sap-abap, or the client's /mcp command to verify the connection.
The registration deliberately uses the moving npm tag @latest together with --prefer-online. Whenever Codex or Claude starts a new MCP process, npm checks which published version latest points to and runs that version. For example, a user who originally ran 0.4.7 will automatically run 0.4.8 after 0.4.8 is promoted to latest and the client is restarted. An already-running MCP process is not replaced in place. Maintainers should promote only tested releases to latest.
4. Change or remove a saved server
Edit a server with its current values as defaults. The wizard tests the updated settings and password before replacing the saved configuration:
npx.cmd @coaspe/sap-abap-mcp@latest setup edit DEV100
Remove a server and its stored SAP and abapGit credentials:
npx.cmd @coaspe/sap-abap-mcp@latest setup remove DEV100
Omit DEV100 to choose from the saved servers. Removal always shows the selected server and asks for confirmation; the default answer is No.
5. Start with read-only requests
List the configured SAP systems and verify DEV100.
Find class ZCL_DEMO in DEV100 and read its RUN method.
Run syntax diagnostics and show a formatter preview without changing the source.
Build a depth-1 dependency graph for ZCL_DEMO.
Detailed setup on macOS
Use npx instead of npx.cmd:
npx @coaspe/sap-abap-mcp@latest setup
npx @coaspe/sap-abap-mcp@latest setup edit DEV100
npx @coaspe/sap-abap-mcp@latest setup remove DEV100
codex mcp add sap-abap -- npx --yes --prefer-online @coaspe/sap-abap-mcp@latest serve --profile DEV100
The wizard tests the SAP connection and stores the password in macOS Keychain.
Linux and containers
Linux runs the same interactive setup, but it does not persist credentials:
npx @coaspe/sap-abap-mcp@latest setup
The wizard saves the non-secret server configuration and prints the exact hidden-input and export commands for its profile-specific password variable. Run those commands in the same shell that starts the MCP client, then run the printed doctor command. For example, server name DEV-100 uses SAP_ABAP_MCP_PASSWORD_DEV_100. The Linux environment store is read-only, so auth login and auth logout are unavailable and no plaintext credential file is created.
Codex desktop setup
If the codex command is not available, add a stdio MCP server in Codex settings:
- Name:
sap-abap - Command on Windows:
npx.cmd - Command on macOS:
npx - Arguments:
--yes
--prefer-online
@coaspe/sap-abap-mcp@latest
serve
--profile
DEV100
Multiple SAP systems
Create one profile per SAP client, for example DEV100, QAS200, and PRD100. To expose all profiles through one MCP server, register serve without --profile:
codex mcp add sap-abap -- npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest serve
Every SAP-facing tool requires an explicit connectionId, which prevents accidental cross-system routing. Cross-system comparison requires the same object to exist in both selected profiles.
abapGit credentials
Public repositories require no additional setup. Store credentials for each private repository URL separately:
npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest abapgit auth login DEV100 `
--repository-url "https://github.example.com/team/repo.git" `
--username "GIT_USER"
Status and removal:
npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest abapgit auth status DEV100 `
--repository-url "https://github.example.com/team/repo.git"
npx.cmd --yes --prefer-online @coaspe/sap-abap-mcp@latest abapgit auth logout DEV100 `
--repository-url "https://github.example.com/team/repo.git"
Credentials are selected by canonical repository URL so credentials for one remote cannot be sent to another. Passwords and tokens are not accepted as MCP tool arguments, and credentials embedded in a repository URL are rejected.
Write-safety model
Repository-changing operations enforce these rules:
- Profiles marked
productionreject writes. - A non-empty
allowedPackageslist restricts writes to those packages; an empty list allows all packages. - Packages other than
$TMPrequire a transport request. - Exact source replacement reads the current source, obtains an SAP lock, rechecks it under the lock, writes, runs syntax diagnostics, optionally activates, and unlocks.
- Rename, package move, method extraction, quick-fix application, formatting, deletion, and revision restore use a preview plan.
- Preview plans expire after ten minutes and require the exact returned confirmation value.
- Execution re-runs the SAP preview or source-state check and rejects stale plans.
- Multi-object quick-fixes perform syntax preflight and attempt rollback if a later write fails.
- RAP generation performs initial validation, content validation, and dry-run preview immediately before generation.
- abapGit push accepts only a fresh SAP staging snapshot and requires explicit object selection or
stageAll=true. - SAP transaction parameters use a restricted character set and are passed to the OS launcher as argument-array values rather than shell text.
- ADT SQL accepts only
SELECTand `WITH
…
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Coaspe
- Source: Coaspe/sap-abap-mcp
- License: MIT
- Homepage: https://www.npmjs.com/package/@coaspe/sap-abap-mcp
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.