sap-abap-mcp
# sap-abap-mcp
A custom [MCP](https://modelcontextprotocol.io) server that connects **IBM Bob** to any SAP ABAP system via SOAP/RFC and SAP WebGUI (ITS).
No SAP system details are hardcoded — everything is configured through environment variables, so each user connects to their own system with their own credentials.
---
## Prerequisites
- [Node.js](https://nodejs.org/) v18 or later
- [Git](https://git-scm.com/download/win) (to clone)
- [IBM Bob](https://ibm.com/bob) IDE extension installed
- A valid SAP user account on the target system
---
## Setup (first time)
### Option A — via npx (easiest, no clone needed)
No installation required. Just set your environment variables (Step 3 below) and open the folder in Bob — `npx` will automatically download and run the latest version.
### Option B — via GitHub clone (for development / offline use)
```bash
git clone https://github.com/JayGandhi285/sap-abap-mcp.git
cd sap-abap-mcp
npm install
npm run build
```
Then in `.bob/mcp.json`, change the command from `npx` to `node` and args to `["./build/index.js"]`.
### 3. Set your SAP connection details as environment variables
These five variables tell the server which SAP system to connect to and how to log in.
**Each person sets their own — never share credentials.**
| Variable | Required | Description | Example |
|---|---|---|---|
| `SAP_WEBGUI_URL` | ✅ Yes | Full WebGUI URL of your SAP system | `https://your-sap-host/sap/bc/gui/sap/its/webgui` |
| `SAP_CLIENT` | ✅ Yes | SAP client number | `100` |
| `SAP_USERNAME` | ✅ Yes | Your SAP username | `JSMITH` |
| `SAP_PASSWORD` | ✅ Yes | Your SAP password | `MyPass123` |
| `SAP_LANGUAGE` | ❌ Optional | Logon language (default: `EN`) | `EN` |
**Windows PowerShell** — add to your `$PROFILE` for persistence:
```powershell
$env:SAP_WEBGUI_URL = "https://your-sap-host/sap/bc/gui/sap/its/webgui"
$env:SAP_CLIENT = "100"
$env:SAP_USERNAME = "your_sap_username"
$env:SAP_PASSWORD = "your_sap_password"
$env:SAP_LANGUAGE = "EN"
```
**Mac / Linux** — add to `~/.zshrc` or `~/.bashrc`:
```bash
export SAP_WEBGUI_URL="https://your-sap-host/sap/bc/gui/sap/its/webgui"
export SAP_CLIENT="100"
export SAP_USERNAME="your_sap_username"
export SAP_PASSWORD="your_sap_password"
export SAP_LANGUAGE="EN"
```
> ⚠️ The server will **refuse to start** and print a clear error message if any required variable is missing.
### 4. Open the `sap-abap-mcp` folder in Bob
Bob automatically detects `.bob/mcp.json` in the workspace root and connects to the server.
The SAP tools will appear in Bob's tool list immediately.
---
## Available tools
| Tool | Description |
|---|---|
| `sap_login` | Log in via SAP WebGUI (establishes a session) |
| `sap_navigate` | Navigate to any SAP transaction code (SE16, SM30, SU01, …) |
| `sap_se16_browse` | Browse any transparent SAP table — no login required |
| `sap_rfc_read_table` | Full-power table reader: field selection, WHERE filters, pagination |
| `sap_run_report` | Run an ABAP report/program via SA38 |
| `sap_execute_command` | Send an OK-code / transaction command to the current WebGUI session |
| `sap_get_page` | Fetch any SAP WebGUI URL and return the rendered page text |
---
## Example prompts in Bob
```
Show me all users in the SAP system
Read table T001 and show the company codes
Show me all failed background jobs
List all transport requests owned by RAJAT
```
---
## How it works
- **SOAP/RFC** (`sap_rfc_read_table`, `sap_se16_browse`): Uses `RFC_READ_TABLE` via SOAP with HTTP Basic Auth — stateless, no login session needed.
- **WebGUI session** (`sap_login`, `sap_navigate`, etc.): Performs a full login via SAP ITS WebGUI and keeps session cookies in a local temp file.
---
## Project structure
```
sap-abap-mcp/
├── src/
│ └── index.ts ← MCP server source (TypeScript)
├── build/
│ └── index.js ← Compiled output (generated — not in Git)
├── .bob/
│ └── mcp.json ← Bob MCP config (all placeholders — safe to share)
├── .gitignore
├── package.json
├── tsconfig.json
└── README.md
```
---
## Rebuilding after source changes
```bash
npm run build
```
Then in Bob: **Settings → MCP → Restart server**.
---
## Updating to the latest version
```bash
git pull
npm install
npm run build
```
---
## Security notes
- ✅ No credentials or system URLs are hardcoded anywhere in the source.
- ✅ `.gitignore` excludes `build/`, `node_modules/`, session files, and data dumps.
- ✅ `.bob/mcp.json` contains only `${ENV_VAR}` placeholders — safe to commit to Git.
- ⚠️ Never add real credentials to any file that gets committed to Git.
TDQS
Scored across 7 tools
Several tools have fuzzy boundaries: sap_se16_browse and sap_rfc_read_table both read table data, while sap_navigate, sap_execute_command, and sap_get_page all retrieve rendered SAP pages and can be used to reach transactions. An agent would need to read descriptions very carefully to reliably pick the right tool.
All tools share a sap_ prefix and snake_case style, which helps, but the internal pattern is inconsistent: sap_navigate is a bare verb, sap_se16_browse leads with a transaction code, and sap_rfc_read_table mixes technical context with the action. It is readable but not a uniform verb_noun convention.
Seven tools is a reasonable size for an SAP interaction server and not bloated overall. However, the set could be tightened because some tools are near-duplicates in functionality, such as the two table-reading paths and the multiple page-fetching mechanisms.
Core workflows like login, navigation, table reads, and running reports are covered, but there is no logout or explicit session-management tool, and report output is only exposed as raw page text. Agents can work around some gaps via execute_command or get_page, but the surface is not fully lifecycle-complete.