# SAP MCP Bridge

> Application to connect any SAP system with the installed MCP client

- **Type:** MCP server
- **Install:** `agentstack add mcp-muhammad-abdullah333-sap-mcp-bridge`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Muhammad-Abdullah333](https://agentstack.voostack.com/s/muhammad-abdullah333)
- **Installs:** 0
- **Category:** [Integrations](https://agentstack.voostack.com/c/integrations)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Muhammad-Abdullah333](https://github.com/Muhammad-Abdullah333)
- **Source:** https://github.com/Muhammad-Abdullah333/SAP-MCP-Bridge

## Install

```sh
agentstack add mcp-muhammad-abdullah333-sap-mcp-bridge
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# SAP MCP Connection Manager

Connect an AI assistant to your SAP system, with a safety policy you control.

SAP MCP Connection Manager keeps your SAP connections in one place and makes them available to **Claude Desktop** and **Codex (ChatGPT)** through a local [MCP](https://modelcontextprotocol.io) server. The AI can then read and work with ABAP development objects through the same development interface (ADT) that Eclipse uses. Every request is checked against the safety policy you set for that connection before it reaches SAP.

Windows 10 and 11.

## Install

1. Download `SAP-MCP-Desktop-Bridge--Windows-Setup.exe` from [Releases](../../releases).
2. Run it. It installs for your Windows user only, needs no administrator rights, and opens the manager when it finishes.
3. Windows may show a SmartScreen notice the first time. Choose **More info → Run anyway**.

**You don't need to install Node.js or anything else.** The installer includes its own Node.js runtime, the desktop shell and the MCP server. The only other things you need are:

- **Claude Desktop** or **Codex**, installed. A ChatGPT browser session alone can't use a local connector.
- **An SAP account with ADT access**, a reachable HTTPS address, and your company's CA certificate if its servers use a private one.

To update, run a newer installer. Your connections, passwords and certificates are kept.

For unattended or managed installs, run the installer with `/S`. It installs without showing any window, doesn't open the app, and reports the result as its exit code (0 means success). If it fails, the reason is written to `%TEMP%\sap-mcp-bridge-install-error.log`.

## Set up a connection

1. Open **SAP MCP Connection Manager** from the Start menu.
2. Click **+ New** and enter the connection name, SAP client, HTTPS address and your user and password. The **Setup Guide** (top right) shows how to find the address and export a CA certificate.
3. Choose the **safety policy** (see below). A new connection starts as *Read only*.
4. Click **Create connection**, then **Configure MCP clients**. Claude Desktop and Codex are detected and set up for you, and their existing configuration is backed up first.
5. Fully quit and reopen Claude Desktop or Codex.

**Test through MCP** and **Full diagnostics** start the connection exactly as your AI client will, and tell you where it fails.

With more than one connection, the one marked **Default system** is used whenever a request doesn't name a system. Only one connection can be the default.

## Safety policy

Each connection answers two questions.

**What may it change?**
- **Read only**: nothing can be changed.
- **Custom can be changed, standard is read only**: changes are confined to the customer namespace (`Z*`, `Y*`, `$*` and `/namespace/` packages). Choosing this also denies the debugger, abapGit and running ABAP snippets or classes.
- **Standard and custom can both be changed**: changes are allowed wherever your SAP account is authorised.

**What data may it read?**
- **Tables only**: it can open a table you name, and can't write its own SQL.
- **Tables and its own SQL queries**: it can also write SQL that joins and filters across tables.

Lists of packages, transports, tables and tools narrow this further. Entries go one per line and accept the wildcards `*` and `?`, and a denial always wins over an allowance. The form shows a Low, Medium or High rating worked out from the whole policy. It also names anything the chosen level does **not** cover, with the list entry that closes it.

The policy is enforced by the MCP server itself, before a request reaches SAP, so telling the AI to ignore it has no effect. It is a safeguard, not a replacement for SAP authorisations: everything the AI does runs as your SAP user.

## What it can't do

- **Smartforms, Adobe Forms and SAPscript can't be edited by the AI.** They're built in SAP GUI (SMARTFORMS, SFP, SE71), and ADT doesn't offer them. Make form changes manually; the AI can still help with the code around a form, such as its print program.
- **Workflow definitions, LSMW projects and other SAP GUI-only tools** aren't reachable either.

## Your data

- Everything stays on your computer. The manager runs a small local service that only this computer can reach.
- It connects to your SAP system, and to the sign-in service you configured if you use browser SSO or OAuth. A few optional SAP tools fetch public reference material, such as SAP's API release information, but only when used. Nothing else reaches out.
- Connections and certificates are kept in `%LOCALAPPDATA%\SAP MCP Desktop Bridge`. Passwords are encrypted with Windows DPAPI, so only your Windows account can read them.
- **Encrypted backup** exports your connections, passwords and certificates, protected by a passphrase you choose. It can be opened on another computer with that passphrase, so treat both with care.

The full [privacy policy](PRIVACY.md) sets out what is stored, what is sent where, and how to remove it.

## Uninstall

Close the manager, then run:

```powershell
powershell -ExecutionPolicy Bypass -File "$env:LOCALAPPDATA\Programs\SAP MCP Desktop Bridge\Uninstall.ps1"
```

This removes the app and its Start-menu shortcut. Your connections and saved passwords are kept, in case you reinstall. Delete `%LOCALAPPDATA%\SAP MCP Desktop Bridge` to remove them as well. Also remove the `SAP-Bridge` entry from Claude Desktop's and Codex's MCP settings.

## Building from source

The source is in `src` (manager, desktop shell and MCP host), `packaging` (installer and build scripts) and `test`. `packaging/vendor-patch` holds our patched copy of the MCP server's policy engine. It's kept as the file it replaces, which is why it sits under a `node_modules` path. No dependencies are committed.

Everything the installer contains comes from this repository or from a public source, pinned by version and hash. It needs Windows, Node.js 24 and Python 3:

1. `python packaging/fetch-base.py` downloads the Node.js runtime and Electron and checks them against the SHA-256 hashes in `packaging/pins.json`. It then installs the MCP server and its dependencies from npm with `npm ci`, exactly as locked in `packaging/vendor/package-lock.json`.
2. `npm test` runs the test suite, including the end-to-end policy test against the real MCP server.
3. `packaging\windows\build.ps1` builds the installer into `dist\`. The same inputs always give the same app contents: `python packaging/payload-digest.py ` prints a fingerprint of them that doesn't depend on which compressor packed them, and every GitHub build publishes its fingerprint for comparison.
4. `python packaging/windows/verify-release.py dist` checks the build against this source and writes its checksums.

The [Windows build](.github/workflows/windows.yml) workflow runs these same steps on GitHub Actions for every change, and runs the installer tests too.

## Code signing

Releases aren't code-signed yet, so Windows shows a SmartScreen notice the first time you run the installer: choose **More info → Run anyway**. Signing is planned.

Until then you can check what you downloaded. Each release lists the SHA-256 of its files in `SHA256SUMS-.txt`. Every release is built from this repository by the [Windows build](.github/workflows/windows.yml) on GitHub Actions, which publishes a fingerprint of the app's contents that you can reproduce from this source (see *Building from source*).

## Support the project

It's free and open source. If it helps you, a ⭐ on GitHub helps other SAP developers find it, and bug reports and ideas are welcome as [issues](https://github.com/Muhammad-Abdullah333/SAP-MCP-Bridge/issues).

## License

MIT, see [LICENSE](LICENSE). Bundled components keep their own licenses, listed in [THIRD-PARTY-NOTICES.txt](THIRD-PARTY-NOTICES.txt).

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Muhammad-Abdullah333](https://github.com/Muhammad-Abdullah333)
- **Source:** [Muhammad-Abdullah333/SAP-MCP-Bridge](https://github.com/Muhammad-Abdullah333/SAP-MCP-Bridge)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-muhammad-abdullah333-sap-mcp-bridge
- Seller: https://agentstack.voostack.com/s/muhammad-abdullah333
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
