Shayona Business Operations MCP
Integrates with Frappe sites through Frappe APIs and native permission checks, allowing access to Shayona business DocTypes such as Customer Service Credential. It resolves authenticated Frappe users and defers to Frappe authorization for access to site data.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Shayona Business Operations MCPshow me a redacted preview of the credential email for customer Acme"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Shayona Business Operations MCP
mcp_shayona is a standalone MCP service for Shayona-specific operational
workflows that do not belong in the ERPNext transactional-domain MCP service.
The package is currently foundation-only: it exposes no business tools and
does not yet send credential emails.
Scope
This project will provide narrowly bounded, typed MCP capabilities over business data owned by the installed site applications. The first planned capability is an approval-bound, redacted-preview workflow for delivering a customer service credential by email.
It is not a generic Frappe CRUD gateway, an ERPNext Sales/Purchase/Accounts server, an identity provider, or a replacement for native Frappe permissions. The service will not expose usernames or decrypted passwords in MCP results, previews, errors, logs, traces, or approval state.
Related MCP server: Business Operations Agent Kit
Application boundaries
shayonaowns the Shayona business DocTypes and data, includingCustomer Service Credential.mcp_shayonaconsumes that data through Frappe APIs and native permission checks; it does not recreate the DocType.mcp_erpnextowns bounded ERPNext transactional capabilities. It is a reference-only architecture source for this project and is not a runtime, HTTP, import, or package dependency ofmcp_shayona.mcp_identityowns shared MCP authentication-mode and Frappe identity primitives.mcp_shayonaimports that existing Python package from the Bench environment; it does not copy or redesign the identity implementation.
Standalone runtime
mcp_shayona is a Bench/Python package and standalone MCP process, not a
site-installed business app. Its future server entrypoint will explicitly
select a site, call frappe.init(site=..., sites_path=..., force=True),
connect, resolve the authenticated Frappe user through mcp_identity, call
frappe.set_user(), and then execute typed capabilities. The target site must
not require bench --site <site> install-app mcp_shayona; the app is not
listed in the site's installed-app list and Task 01 adds no hooks, DocTypes,
patches, fixtures, or scheduled jobs needed at runtime.
For HTTP, the service will preserve the verified mcp_identity model:
trusted-header mode validates a server-only Bearer secret and resolves the
request's X-MCP-User-Email to an enabled non-Guest Frappe User; OAuth mode
uses the native Frappe opaque token's subject and never falls back to headers,
the stdio user, or a shared secret. Frappe authorization remains authoritative
after identity resolution.
MCP SDK baseline
The official MCP Python SDK verified for this task is mcp 2.2.0, released on
2026-09-07. The package constraint is mcp>=2.2,<3: it starts on the current
stable v2 line while preventing an unreviewed future major upgrade. New
implementation must use the v2 MCPServer API and its current transport/auth
APIs. It must not copy mcp_erpnext's legacy mcp>=1.0,<2.0 constraint or the
removed mcp.server.fastmcp.FastMCP import path.
References: official v2 SDK, v2.2.0 release, and v1-to-v2 migration guide.
Documentation
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
Stateless PII redaction over MCP/REST. Free ≤1000 words or $0.01/call; file upload supported.
Guarded MCP server for agent-readable business truth, provenance, readiness, and discovery.
Tenant-scoped control layer for agent-to-agent systems: governed routing, approvals, evidence.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceProvides an isolated MCP gateway for SynapXnet AIOps, DataOps, and MLOps evidence-to-remediation workflows, with OAuth validation, scoped tool discovery, persistent approvals, and audit tracking.AGPL 3.0
- AlicenseNot gradedqualityBmaintenanceMCP server that provides read-only business operations tools: list businesses, get status, identify missing inputs, and prepare email drafts/attachment manifests from synthetic evidence, with strict no-send/no-write safeguards.Apache 2.0
- AlicenseNot gradedqualityAmaintenanceAn MCP server exposing scoped, read-only enterprise operations tools with fail-closed credential handling. It returns opaque approval IDs for mutations and requires a separate operator approval command to release one-time capabilities.MIT
- AlicenseNot gradedqualityBmaintenanceSafe-write Shopify operations MCP server with plan-before-execute writes, out-of-band approval, and tamper-evident audit trail.28 npmMIT