sap-mcp-server
Provides read access and approval-gated write access to SAP ECC and S/4HANA via OData and RFC/BAPI, with tools for material master, production orders, purchase orders, table reads, BAPI calls, and audit logging.
Provides search and detail retrieval for EU public tenders on Tenders Electronic Daily (TED) by CPV code, country, open status, and publication number.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@sap-mcp-serverlist production orders for plant 1000"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
sap-mcp-server
An MCP server that gives Claude (Desktop, Code, API) read access and approval-gated write access to SAP ECC and S/4HANA through OData and RFC/BAPI, without the proprietary SAP NetWeaver RFC SDK. The OData side talks to the SAP Gateway over HTTP. The RFC side runs through a small Node bridge on open-rfc, an Apache-2.0 licensed package that implements the RFC protocol without the SAP SDK. Every call is written to an audit log.
Why
SAP Joule ships with S/4HANA Cloud and with recent S/4HANA on-premise releases connected to BTP. ECC 6.0 has no Joule, and the only supported route to one is a migration. This server is the sidecar pattern: SAP stays as it is, the model runs where you choose (Claude Desktop, Claude Code, the Claude API, Amazon Bedrock), and the only thing between them is this process. It uses the two interfaces most SAP systems already expose, OData on the Gateway and RFC on the application server, and writes every call to an audit log.
Related MCP server: abap-adt-mcp
Tools
Tool | Path | What it does |
| OData | Reads the Gateway service catalog; connection test |
| OData | Lists OData services registered on the Gateway, optionally filtered by substring |
| OData | Reads any entity set ( |
| OData | Material master. S/4HANA |
| OData | Production orders. S/4HANA |
| OData | Purchase orders. S/4HANA |
| write | Without |
| RFC |
|
| RFC |
|
| RFC |
|
| RFC | Calls a BAPI or function module from the read-only allowlist in |
| TED | Searches EU public tenders on Tenders Electronic Daily by CPV code. Needs no SAP connection |
| TED | Details of one TED notice: lots, deadlines, estimated values, CPV codes, place of performance |
Requirements
Python 3.10 or newer
Node.js 22.14 or newer for the RFC tools (open-rfc requires it). The OData and TED tools work without Node
An SAP user with the authorizations you intend to grant: Gateway service access for OData;
S_RFCplusS_TABU_DISorS_TABU_NAMforread_tableNetwork access from the machine running this server to the Gateway HTTP(S) port and to the application server RFC port (
33NN, whereNNis the system number)
Install
Clone the repository (git clone https://github.com/romankorim/sap-mcp-server.git), then:
cd sap-mcp-server
python3 -m venv .venv
.venv/bin/pip install -r requirements.txt
cd rfc-bridge && npm install && cd ..
chmod +x run.shConfigure
cp .env.example .envEdit .env:
Variable | Meaning |
| OData root on the Gateway, usually |
| SAP client number |
| SAP user for OData and, unless |
|
|
| Application server host and system number for RFC |
| RFC logon language, default |
| Optional separate technical user for RFC |
| Audit log file; a relative path is resolved next to |
| Path to the node binary when it is not on PATH. Claude Desktop starts servers with a minimal PATH, so on macOS this is usually needed |
| Preferred language of multilingual TED fields, default |
|
|
| OData service and entity set names behind the three convenience tools; see |
.env is re-read on every tool call, so a changed host or password takes effect without restarting the client. Values in .env take precedence over the process environment. Single-quote values that contain spaces or shell characters.
Run
./run.shrun.sh loads .env, picks .venv/bin/python when it exists (otherwise $PYTHON or python3) and starts server.py on stdio. MCP clients start it the same way; you only run it by hand to see startup errors. On Windows call the venv interpreter directly with server.py as the argument; the server reads .env itself.
Claude Desktop
Quit Claude Desktop completely before editing the config file. The app rewrites claude_desktop_config.json from memory when it quits, so it overwrites any edit made while it is running.
File location: macOS ~/Library/Application Support/Claude/claude_desktop_config.json, Windows %APPDATA%\Claude\claude_desktop_config.json.
{
"mcpServers": {
"sap": {
"command": "/absolute/path/to/sap-mcp-server/run.sh",
"args": []
}
}
}Start the app again. The sap tools appear in the tools list; sap_ping and rfc_ping are the first calls to try.
Claude Code
claude mcp add sap -- /absolute/path/to/sap-mcp-server/run.shSecurity model
Read-only by default. All OData tools use GET. All RFC tools call read-only function modules.
bapi_callaccepts only names in theREAD_BAPISset inrfc_tools.py. Extending the list is a code change, not a runtime option.read_tablereads whatever the RFC user is authorized to read, except tables that hold credentials, secrets or personal data:USR*,USH*,RSEC*,SEC*,PA0*,PA9*,HRP*,T77*,RFCDES,USRBAPI,SECSTOREand theSSF_PSEtables are refused unlessSAP_ALLOW_SENSITIVE_TABLES=1is set for an audited admin session. Restrict the user withS_TABU_DISorS_TABU_NAMon the SAP side as well.Writes are two-step.
create_purchase_requisitionreturns a proposal unlessconfirm=Trueis passed; the intended flow is that a person reviews the proposal and the client calls again withconfirm=True. The SAP write itself is not implemented yet.Credentials come from
.envor the environment; the server never logs them. The audit record stores the SAP user name, not the password.TLS certificate verification is on by default.
The audit log is one JSON line per call, appended to
AUDIT_LOG_PATH:
{"ts": "2026-10-01T09:12:44+00:00", "user": "SAPUSER", "tool": "read_table", "args": {"table": "MARA", "fields": "MATNR,MTART,MATKL", "where": "MTART = 'FERT'", "max_rows": 20, "skip_rows": 0}, "status": "ok", "ms": 412, "note": "rfc_user=SAPUSER"}Fields: ts (UTC), user (SAP_USER), tool, args (the call arguments, so filters and WHERE clauses end up in the log), status (ok, error, proposed, not_implemented, or http_<code> for failed OData requests), ms, note. Treat the file as sensitive: it contains every query sent to SAP.
Known limits
RFC_READ_TABLEreturns each row as one character line of at most 512 bytes. Wide tables need an explicit field list. SelectingRPRCTRfromFAGLFLEXTfails on the systems we tested.The
whereargument is split into 72-characterOPTIONSlines on whitespace. A single token longer than 72 characters is rejected.odata_querycapstopat 200.On ECC the S/4HANA
API_*OData services do not exist. PointSAP_SVC_*andSAP_ES_*to your own Z services, or use the RFC tools.create_purchase_requisitiondoes not write to SAP yet.The TED API answers with HTTP 429 above roughly 10 requests per minute.
OData V2 only.
The RFC bridge starts a Node process per call, with no connection pooling. Each call opens a new logon, which adds latency.
Roadmap
BAPI_PR_CREATEwrite path behind the existingconfirm=TruegateS/4HANA
API_*style read services on ECC through Z Gateway servicesOData V4
Maintainer
Maintained by iteractive.ai, AI implementation for SAP and enterprise systems. Commercial support and production deployments: https://iteractive.ai/services/claude-sap-mcp
License
MIT, see LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
- StackOneOAuthcom.stackone
Give AI agents 30,000+ safe, token-optimized actions across Workday, SAP, Oracle + hundreds more.
Your audit methodology inside Claude: findings, risks, controls and workpapers in your team format.
- platform7nOAuthtech.p7n
Connect Claude to your Platform7n workspaces — chat, links, and tasks. One-click OAuth.
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Related MCP Servers
- FlicenseAqualityDmaintenanceEnables AI assistants to integrate with SAP systems via OData REST APIs for querying entity sets, performing CRUD operations, and executing function imports. It features automatic service discovery, CSRF token management, and smart connection handling without requiring the SAP RFC SDK.1112-
- AlicenseAqualityDmaintenanceEnables AI assistants like Claude Code to directly connect to SAP ABAP systems via the ADT REST API with read/write capabilities, featuring AI-friendly high-level tools and built-in safety measures such as read-only mode, prefix whitelisting, and automatic locking.9313 npmMIT
- AlicenseNot gradedqualityAmaintenanceEnables AI assistants and n8n workflows to interact with SAP S/4HANA and ECC systems via OData, IDoc, and RFC/BAPI, with governed read-only-by-default access and multiple authentication types.3ISC
- AlicenseAqualityAmaintenanceEnables AI agents to discover, inspect, and call SAP RFC-enabled function modules (BAPIs/RFCs) with configurable read/write policies, transaction support, audit logging, and ABAP source retrieval.6MIT