hybris-mcp-lite
Provides read-only access to a local SAP Commerce (Hybris) instance through HAC, enabling FlexibleSearch queries and inspection of types, beans, configuration, logs, monitoring, and cronjobs.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@hybris-mcp-liteWhich cronjobs failed recently in my local Hybris instance?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
hybris-mcp-lite

A read-only MCP server that lets Claude (or any MCP client) look inside a local SAP Commerce (Hybris) instance through HAC, in plain language.
Local/dev only. Not for production.
Why
HAC is useful, but it is a lot of tabs and forms when you just want a quick answer. This server exposes a small set of read-only HAC features as MCP tools, so you can ask about types, beans, config, cronjobs, logs and FlexibleSearch from your editor or chat client and stay where you are.
Related MCP server: local-mcp-toolbox
Example prompts
"What attributes does Product have, and which of them are localized?"
"Which cronjobs failed recently?"
"Show me the value of
catalog.sync.workers.""Find the 10 most recently modified products in the Staged catalog."
"Tail the last 200 log lines and show me only the errors."
Tools
Tool | What it does |
| Run a FlexibleSearch query, or translate it to SQL with |
| Attributes, deployment table and subtypes of a type from the type system. |
| Implementation class and aliases of a Spring bean. |
| Read one property or all properties. Values of keys matching |
| Tail the local console log (1 to 2000 lines), with an optional regex filter. |
| Memory, threads, thread dump, cache or cluster diagnostics. |
|
|
Quick start
git clone https://github.com/andreescocard/hybris-mcp-lite.git
cd hybris-mcp-lite
npm install
npm run buildThen register the server with your client. You need a running local HAC and a HAC user.
Claude Code
claude mcp add hybris-hac-lite \
-e HAC_URL=https://localhost:9002/hac -e HAC_USER=admin -e HAC_PASS=... \
-e HAC_INSECURE_TLS=true -e HAC_LOG_PATH=/path/to/console.log \
-- node /absolute/path/to/hybris-mcp-lite/dist/index.jsClaude Desktop
{
"mcpServers": {
"hybris-hac-lite": {
"command": "node",
"args": ["/absolute/path/to/hybris-mcp-lite/dist/index.js"],
"env": {
"HAC_URL": "https://localhost:9002/hac",
"HAC_USER": "admin",
"HAC_PASS": "your-local-password",
"HAC_INSECURE_TLS": "true",
"HAC_LOG_PATH": "/path/to/console.log"
}
}
}
}Configuration
Variable | Required | Description |
| no | HAC base URL. Default |
| yes | HAC user. |
| yes | HAC password. |
| for | Path to the local console log file. |
| no | Request timeout in ms. Default 30000. |
| no | Set to |
| no | Set to |
Safety by design
Read-only tool set. There is no Groovy console, ImpEx, SQL, system update, cache clear or reindex tool.
commit=false. The tools that go through HAC's scripting console always submit withcommit=false, so HAC rolls back any write.Config masking.
config_getmasks values of keys that look like secrets (pass,secret,token,key,credential).Private-host guard. The server refuses a
HAC_URLunless the host is localhost, 127.x, ::1, 10.x, 172.16-31.x, 192.168.x,*.localor*.localhost.HAC_ALLOW_REMOTE=trueoverrides this.Opt-in insecure TLS. Certificate checks are only disabled when you set
HAC_INSECURE_TLS=true.
One caveat: masking applies to config_get only. Output from logs_tail and monitoring_info (including thread dumps) is not masked and may contain sensitive data. Anything a tool returns is sent to your MCP client and its model.
Development
npm test # unit tests
npm run smoke # runs every tool against the HAC in your env varsDisclaimer
Intended for local and development instances only, not for production. Provided as is, with no warranty.
SAP Commerce and Hybris are trademarks of SAP SE. This project is not affiliated with or endorsed by SAP.
License
MIT
Author
André Escocard, LinkedIn.
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
Guarded MCP server for agent-readable business truth, provenance, readiness, and discovery.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables read-only observability of a Linux host via MCP, exposing allowlisted systemd, docker, nginx, logs, disk, and cert info without shell access.MIT
- AlicenseAqualityAmaintenanceA secure, local-first MCP server for read-only inspection and troubleshooting of development environments, exposing narrow, typed, auditable capabilities for repository inspection, log summarization, Docker review, and security scanning without granting unrestricted machine access.8MIT
- AlicenseNot gradedqualityCmaintenanceRead-only MCP server to inspect allowlisted Docker containers, systemd services, JSONL logs, and HTTP health endpoints without arbitrary shell access.MIT
- AlicenseNot gradedqualityAmaintenanceEnables local MCP access to attach to isolated backend environments, monitor runtime health/logs, check security posture, manage snapshots and diffs, audit events, and view sanitized remote inventory.9 npmApache 2.0