Install
$ agentstack add mcp-muhammad-abdullah333-sap-mcp-bridge ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
SAP MCP Connection Manager
Connect an AI assistant to your SAP system, with a safety policy you control.
SAP MCP Connection Manager keeps your SAP connections in one place and makes them available to Claude Desktop and Codex (ChatGPT) through a local MCP server. The AI can then read and work with ABAP development objects through the same development interface (ADT) that Eclipse uses. Every request is checked against the safety policy you set for that connection before it reaches SAP.
Windows 10 and 11.
Install
- Download
SAP-MCP-Desktop-Bridge--Windows-Setup.exefrom [Releases](../../releases). - Run it. It installs for your Windows user only, needs no administrator rights, and opens the manager when it finishes.
- Windows may show a SmartScreen notice the first time. Choose More info → Run anyway.
You don't need to install Node.js or anything else. The installer includes its own Node.js runtime, the desktop shell and the MCP server. The only other things you need are:
- Claude Desktop or Codex, installed. A ChatGPT browser session alone can't use a local connector.
- An SAP account with ADT access, a reachable HTTPS address, and your company's CA certificate if its servers use a private one.
To update, run a newer installer. Your connections, passwords and certificates are kept.
For unattended or managed installs, run the installer with /S. It installs without showing any window, doesn't open the app, and reports the result as its exit code (0 means success). If it fails, the reason is written to %TEMP%\sap-mcp-bridge-install-error.log.
Set up a connection
- Open SAP MCP Connection Manager from the Start menu.
- Click + New and enter the connection name, SAP client, HTTPS address and your user and password. The Setup Guide (top right) shows how to find the address and export a CA certificate.
- Choose the safety policy (see below). A new connection starts as Read only.
- Click Create connection, then Configure MCP clients. Claude Desktop and Codex are detected and set up for you, and their existing configuration is backed up first.
- Fully quit and reopen Claude Desktop or Codex.
Test through MCP and Full diagnostics start the connection exactly as your AI client will, and tell you where it fails.
With more than one connection, the one marked Default system is used whenever a request doesn't name a system. Only one connection can be the default.
Safety policy
Each connection answers two questions.
What may it change?
- Read only: nothing can be changed.
- Custom can be changed, standard is read only: changes are confined to the customer namespace (
Z*,Y*,$*and/namespace/packages). Choosing this also denies the debugger, abapGit and running ABAP snippets or classes. - Standard and custom can both be changed: changes are allowed wherever your SAP account is authorised.
What data may it read?
- Tables only: it can open a table you name, and can't write its own SQL.
- Tables and its own SQL queries: it can also write SQL that joins and filters across tables.
Lists of packages, transports, tables and tools narrow this further. Entries go one per line and accept the wildcards * and ?, and a denial always wins over an allowance. The form shows a Low, Medium or High rating worked out from the whole policy. It also names anything the chosen level does not cover, with the list entry that closes it.
The policy is enforced by the MCP server itself, before a request reaches SAP, so telling the AI to ignore it has no effect. It is a safeguard, not a replacement for SAP authorisations: everything the AI does runs as your SAP user.
What it can't do
- Smartforms, Adobe Forms and SAPscript can't be edited by the AI. They're built in SAP GUI (SMARTFORMS, SFP, SE71), and ADT doesn't offer them. Make form changes manually; the AI can still help with the code around a form, such as its print program.
- Workflow definitions, LSMW projects and other SAP GUI-only tools aren't reachable either.
Your data
- Everything stays on your computer. The manager runs a small local service that only this computer can reach.
- It connects to your SAP system, and to the sign-in service you configured if you use browser SSO or OAuth. A few optional SAP tools fetch public reference material, such as SAP's API release information, but only when used. Nothing else reaches out.
- Connections and certificates are kept in
%LOCALAPPDATA%\SAP MCP Desktop Bridge. Passwords are encrypted with Windows DPAPI, so only your Windows account can read them. - Encrypted backup exports your connections, passwords and certificates, protected by a passphrase you choose. It can be opened on another computer with that passphrase, so treat both with care.
The full [privacy policy](PRIVACY.md) sets out what is stored, what is sent where, and how to remove it.
Uninstall
Close the manager, then run:
powershell -ExecutionPolicy Bypass -File "$env:LOCALAPPDATA\Programs\SAP MCP Desktop Bridge\Uninstall.ps1"
This removes the app and its Start-menu shortcut. Your connections and saved passwords are kept, in case you reinstall. Delete %LOCALAPPDATA%\SAP MCP Desktop Bridge to remove them as well. Also remove the SAP-Bridge entry from Claude Desktop's and Codex's MCP settings.
Building from source
The source is in src (manager, desktop shell and MCP host), packaging (installer and build scripts) and test. packaging/vendor-patch holds our patched copy of the MCP server's policy engine. It's kept as the file it replaces, which is why it sits under a node_modules path. No dependencies are committed.
Everything the installer contains comes from this repository or from a public source, pinned by version and hash. It needs Windows, Node.js 24 and Python 3:
python packaging/fetch-base.pydownloads the Node.js runtime and Electron and checks them against the SHA-256 hashes inpackaging/pins.json. It then installs the MCP server and its dependencies from npm withnpm ci, exactly as locked inpackaging/vendor/package-lock.json.npm testruns the test suite, including the end-to-end policy test against the real MCP server.packaging\windows\build.ps1builds the installer intodist\. The same inputs always give the same app contents:python packaging/payload-digest.pyprints a fingerprint of them that doesn't depend on which compressor packed them, and every GitHub build publishes its fingerprint for comparison.python packaging/windows/verify-release.py distchecks the build against this source and writes its checksums.
The [Windows build](.github/workflows/windows.yml) workflow runs these same steps on GitHub Actions for every change, and runs the installer tests too.
Code signing
Releases aren't code-signed yet, so Windows shows a SmartScreen notice the first time you run the installer: choose More info → Run anyway. Signing is planned.
Until then you can check what you downloaded. Each release lists the SHA-256 of its files in SHA256SUMS-.txt. Every release is built from this repository by the [Windows build](.github/workflows/windows.yml) on GitHub Actions, which publishes a fingerprint of the app's contents that you can reproduce from this source (see Building from source).
Support the project
It's free and open source. If it helps you, a ⭐ on GitHub helps other SAP developers find it, and bug reports and ideas are welcome as issues.
License
MIT, see [LICENSE](LICENSE). Bundled components keep their own licenses, listed in [THIRD-PARTY-NOTICES.txt](THIRD-PARTY-NOTICES.txt).
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Muhammad-Abdullah333
- Source: Muhammad-Abdullah333/SAP-MCP-Bridge
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.