SAP-MCP-Bridge

mcp
Security Audit
Fail
Health Pass
  • License — License: MIT
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Community trust — 14 GitHub stars
Code Fail
  • network request — Outbound network request in packaging/fetch-base.py
  • exec() — Shell command execution in packaging/vendor-patch/make-patch.js
  • fs module — File system access in packaging/vendor-patch/make-patch.js
  • exec() — Shell command execution in packaging/vendor-patch/node_modules/abap-adt-mcp/dist/lib/policy.js
  • network request — Outbound network request in packaging/vendor/package-lock.json
Permissions Pass
  • Permissions — No dangerous permissions requested

No AI report is available for this listing yet.

SUMMARY

Application to connect any SAP system with the installed MCP client

README.md

SAP MCP Connection Manager

Connect an AI assistant to your SAP system, with a safety policy you control.

SAP MCP Connection Manager keeps your SAP connections in one place and makes them available to Claude Desktop and Codex (ChatGPT) through a local MCP server. The AI can then read and work with ABAP development objects through the same development interface (ADT) that Eclipse uses. Every request is checked against the safety policy you set for that connection before it reaches SAP.

Windows 10 and 11.

Install

  1. Download SAP-MCP-Desktop-Bridge-<version>-Windows-Setup.exe from Releases.
  2. Run it. It installs for your Windows user only and needs no administrator rights. It offers to connect Claude Desktop and Codex (their settings are backed up first) and to open the manager when it finishes.
  3. Windows may show a SmartScreen notice the first time. Choose More info → Run anyway.

You don't need to install Node.js or anything else. The installer includes its own Node.js runtime, the desktop shell and the MCP server. The only other things you need are:

  • Claude Desktop or Codex, installed. A ChatGPT browser session alone can't use a local connector.
  • An SAP account with ADT access, a reachable HTTPS address, and your company's CA certificate if its servers use a private one.

To update, run a newer installer. Your connections, passwords and certificates are kept. If the manager or a Bridge MCP server is running, the installer closes it; restart Claude Desktop or Codex afterwards.

For unattended or managed installs, run the installer with /VERYSILENT /SUPPRESSMSGBOXES /NORESTART. It shows no window and doesn't open the app. The exit code reports the result: 0 means success, and 10 means the app is installed but Claude Desktop or Codex couldn't be connected (the reason is in %TEMP%\sap-mcp-bridge-install-error.log and in the manager). Add /MERGETASKS="!clients" to install without touching Claude Desktop or Codex.

Set up a connection

  1. Open SAP MCP Connection Manager from the Start menu.
  2. Click + New and enter the connection name, SAP client, HTTPS address and your user and password. The Setup Guide (top right) shows how to find the address and export a CA certificate.
  3. Choose the safety policy (see below). A new connection starts as Read only.
  4. Click Create connection, then Configure MCP clients. Claude Desktop and Codex are detected and set up for you, and their existing configuration is backed up first.
  5. Fully quit and reopen Claude Desktop or Codex.

Test through MCP and Full diagnostics start the connection exactly as your AI client will, and tell you where it fails.

If Claude Desktop or Codex isn't connected

Bridge never changes a client's settings file it can't read safely, and if one client fails it puts the others back as they were. The manager's Logs show which file, why, and what to do. The usual causes:

  • The client wasn't found. You installed the Bridge before Claude Desktop or Codex. Install the client, then choose Configure MCP clients.
  • Its settings file contains a mistake, often a missing or extra comma after editing it by hand. For Claude Desktop, open Settings → Developer → Edit Config. For Codex, open config.toml at the path shown in Logs. Correct it, or put back one of the .backup files Bridge keeps next to it, then choose Configure MCP clients.
  • The file couldn't be saved. It's read-only, held open by another program (OneDrive syncing, antivirus), or the disk is full.
  • A connector named SAP-Bridge already exists that Bridge didn't create. Rename or remove it, then retry.
  • It's connected, but you don't see SAP-Bridge. The client wasn't fully restarted. Closing the Claude Desktop window can leave it running in the system tray, so quit it from there.

With more than one connection, the one marked Default system is used whenever a request doesn't name a system. Only one connection can be the default.

Safety policy

Each connection answers two questions.

What may it change?

  • Read only: nothing can be changed.
  • Custom can be changed, standard is read only: changes are confined to the customer namespace (Z*, Y*, $* and /namespace/ packages). Choosing this also denies the debugger, abapGit and running ABAP snippets or classes.
  • Standard and custom can both be changed: changes are allowed wherever your SAP account is authorised.

What data may it read?

  • Tables only: it can open a table you name, and can't write its own SQL.
  • Tables and its own SQL queries: it can also write SQL that joins and filters across tables.

Lists of packages, transports, tables and tools narrow this further. Entries go one per line and accept the wildcards * and ?, and a denial always wins over an allowance. The form shows a Low, Medium or High rating worked out from the whole policy. It also names anything the chosen level does not cover, with the list entry that closes it.

The policy is enforced by the MCP server itself, before a request reaches SAP, so telling the AI to ignore it has no effect. It is a safeguard, not a replacement for SAP authorisations: everything the AI does runs as your SAP user.

What it can't do

  • Smartforms, Adobe Forms and SAPscript can't be edited by the AI. They're built in SAP GUI (SMARTFORMS, SFP, SE71), and ADT doesn't offer them. Make form changes manually; the AI can still help with the code around a form, such as its print program.
  • Workflow definitions, LSMW projects and other SAP GUI-only tools aren't reachable either.

Your data

  • Everything stays on your computer. The manager runs a small local service that only this computer can reach.
  • It connects to your SAP system, and to the sign-in service you configured if you use browser SSO or OAuth. A few optional SAP tools fetch public reference material, such as SAP's API release information, but only when used. Nothing else reaches out.
  • Connections and certificates are kept in %LOCALAPPDATA%\SAP MCP Desktop Bridge. Passwords are encrypted with Windows DPAPI, so only your Windows account can read them.
  • Encrypted backup exports your connections, passwords and certificates, protected by a passphrase you choose. It can be opened on another computer with that passphrase, so treat both with care.

The full privacy policy sets out what is stored, what is sent where, and how to remove it.

Uninstall

Open Settings → Apps → Installed apps, find SAP MCP Desktop Bridge and choose Uninstall.

This removes the app and its Start-menu shortcut. Your connections and saved passwords are kept, in case you reinstall. Delete %LOCALAPPDATA%\SAP MCP Desktop Bridge to remove them as well. Also remove the SAP-Bridge entry from Claude Desktop's and Codex's MCP settings.

Building from source

The source is in src (manager, desktop shell and MCP host), packaging (installer and build scripts) and test. packaging/vendor-patch holds our patched copy of the MCP server's policy engine. It's kept as the file it replaces, which is why it sits under a node_modules path. No dependencies are committed.

Everything the installer contains comes from this repository or from a public source, pinned by version and hash. It needs Windows, Node.js 24 and Python 3:

  1. python packaging/fetch-base.py downloads the Node.js runtime, Electron and two build tools, rcedit and Inno Setup, and checks them against the SHA-256 hashes in packaging/pins.json. It then installs the MCP server and koffi, which the app uses to call Windows' own password encryption, from npm with npm ci, exactly as locked in packaging/vendor/package-lock.json.
  2. npm test runs the test suite, including the end-to-end policy test against the real MCP server.
  3. packaging\windows\build.ps1 builds the installer into dist\ with Inno Setup, from packaging/windows/installer.iss. The same inputs always give the same app contents: python packaging/payload-digest.py <payload.zip> prints a fingerprint of them that doesn't depend on which compressor packed them, and every GitHub build publishes its fingerprint for comparison.
  4. python packaging/windows/verify-release.py dist checks the build against this source and writes its checksums.

The Windows build workflow runs these same steps on GitHub Actions for every change, and runs the installer tests too.

Code signing

Releases aren't code-signed yet, so Windows shows a SmartScreen notice the first time you run the installer: choose More info → Run anyway. Signing is planned.

Microsoft Defender and some other antivirus products flagged the 1.0.0 and 1.0.1 installers with generic machine-learning detections such as Trojan:Win32/Sabsik.EN.B!ml. These were false positives. Those installers unpacked themselves and ran hidden PowerShell, and the app used hidden PowerShell to decrypt saved passwords, which is the pattern such heuristics look for. From 1.0.2 the installer is a standard Inno Setup installer, and the app calls Windows' password encryption directly and contains no scripts. If your antivirus still flags a release, please open an issue and report the file to the vendor as a false positive (for Defender, use Microsoft's file submission). Don't turn off your antivirus to install it.

Until then you can check what you downloaded. Each release lists the SHA-256 of its files in SHA256SUMS-<version>.txt. Every release is built from this repository by the Windows build on GitHub Actions, which publishes a fingerprint of the app's contents that you can reproduce from this source (see Building from source).

Support the project

It's free and open source. If it helps you, a ⭐ on GitHub helps other SAP developers find it, and bug reports and ideas are welcome as issues.

License

MIT, see LICENSE. Bundled components keep their own licenses, listed in THIRD-PARTY-NOTICES.txt.

Reviews (0)

No results found