HanaSAFE
SAP HANA MCP server — Enterprise Model Context Protocol server for SAP HANA. Use with Claude Code, VS Code. npm: hana-mcp-server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/hana-mcp-server) [](https://www.npmjs.com/package/hana-mcp-server) [](https://nodejs.org/) [](LICENSE) [](https://modelcontextprotocol.io/)
SAP HANA MCP Server implements the Model Context Protocol for SAP HANA and SAP HANA Cloud. AI clients discover schema, run SQL with guardrails, and optionally merge business/domain metadata so agents interpret codes and tables consistently—without replacing your database as the system of record.
📚 Documentation
✅ Prerequisites
- Node.js 18+
- A SAP HANA or SAP HANA Cloud database reachable on the SQL port from the machine running the server
- An MCP client (Claude Desktop, Claude Code, VS Code, Cursor, Cline, Windsurf, or custom HTTP client)
- Credentials supplied via env (see Security)
📦 Installati
c912c4910a7fOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add hana-mcp-server --env HANA_PASSWORD=${HANA_PASSWORD} --env MCP_HTTP_AUTH_ENABLED=${MCP_HTTP_AUTH_ENABLED} -- npx -y [email protected]{
"mcpServers": {
"hana-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"HANA_PASSWORD": "${HANA_PASSWORD}",
"MCP_HTTP_AUTH_ENABLED": "${MCP_HTTP_AUTH_ENABLED}"
}
}
}
}Exposed tools (38)
35 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
goal | read | What the query should achieve |
hana_connection_test | read | Test HANA database connection and show configuration |
hana_describe_function | read | Return parameter names, types, data types, and positions for a function from SYS.FUNCTION_PARAMETERS. |
hana_describe_index | read | Describe the structure of a specific index |
hana_describe_procedure | read | Return parameter names, types (IN/OUT/INOUT), data types, and positions from SYS.PROCEDURE_PARAMETERS. |
hana_describe_table | read | Describe the structure of a specific table |
hana_describe_view | read | Return the view definition (SQL) and column metadata from SYS.VIEWS and SYS.VIEW_COLUMNS. |
hana_explain_plan | write | Run EXPLAIN PLAN for a SELECT/WITH query and return operator tree from EXPLAIN_PLAN_TABLE. Only SELECT/WITH are accepted. |
hana_explain_table | read | Return column metadata merged with optional business semantics from HANA_SEMANTICS_PATH or HANA_SEMANTICS_URL (JSON keys: SCHEMA.TABLE or DB.SCHEMA.TABLE when catalog_database is set). Optional catalog_database reads SYS.* from another MDC database (e.g. HSP). |
hana_get_column_stats | read | Retrieve column statistics (distinct count, null count, min/max) from SYS.COLUMN_STATISTICS (cached) or via live COUNT queries (live=true). With live=true a specific column_name is required. |
hana_get_ddl | write | Retrieve the DDL (CREATE statement) for a TABLE, VIEW, PROCEDURE, FUNCTION, TRIGGER, or SEQUENCE from SYS.OBJECT_DEFINITION. Requires appropriate privileges. |
hana_get_dependencies | read | Show what an object depends on or what depends on it, from SYS.OBJECT_DEPENDENCIES. Capped at 200 rows. |
hana_get_expensive_queries | read | Return the most expensive statements from M_EXPENSIVE_STATEMENTS ordered by duration. Requires MONITORING privilege. |
hana_get_partition_info | read | Return partition metadata (type, level, record count, loaded state) from SYS.TABLE_PARTITIONS. Returns empty result for unpartitioned tables. |
hana_get_sample_data | read | Fetch the first N rows from a table using SELECT TOP. Result is shaped by the same row/column/cell caps as hana_execute_query. |
hana_get_session_info | read | Return CURRENT_USER, CURRENT_SCHEMA, connected database name, SYSTEM_ID, and HANA version from DUMMY and M_DATABASE. |
hana_get_table_stats | read | Return row count, table type, column-store flag, primary key flag, and disk size (requires MONITORING privilege for disk size) from SYS.TABLES and SYS.M_TABLE_SIZES. |
hana_list_calculation_views | read | List calculation views from the _SYS_BIC schema (SAP BW/S4 analytical views). Supports prefix filter and pagination. |
hana_list_constraints | read | List primary key, unique, check, and foreign key constraints for a table (SYS.CONSTRAINTS + SYS.REFERENTIAL_CONSTRAINTS). |
hana_list_foreign_keys | read | List referential constraints (foreign keys) showing column, referenced table/column, and delete rule from SYS.REFERENTIAL_CONSTRAINTS. |
hana_list_functions | read | List scalar and table functions from SYS.FUNCTIONS. Supports prefix filter and pagination. |
hana_list_indexes | read | List all indexes for a specific table |
hana_list_privileges | read | List effective privileges for a user (or CURRENT_USER if omitted) from SYS.EFFECTIVE_PRIVILEGES. Requires CATALOG READ privilege or querying own privileges. |
hana_list_procedures | read | List stored procedures and their parameter counts from SYS.PROCEDURES. |
hana_list_schemas | read | List schemas in the HANA database with optional prefix filter and pagination (HANA_LIST_DEFAULT_LIMIT / offset). |
hana_list_sequences | write | List sequences from SYS.SEQUENCES, showing start, min, max, increment, cycle, and cache settings. |
hana_list_synonyms | read | List synonyms in a schema from SYS.SYNONYMS, showing target object schema, name, and type. |
hana_list_tables | read | List tables in a schema with optional name prefix and pagination (HANA_LIST_DEFAULT_LIMIT / offset). |
hana_list_views | read | List views in a schema from SYS.VIEWS. Supports prefix filter and pagination. |
hana_query_builder | read | Build a SQL query for HANA database |
hana_query_next_page | read | Fetch the next page of a truncated SELECT using snapshotId from a previous hana_execute_query result (same SQL and parameters; TTL HANA_QUERY_SNAPSHOT_TTL_MS). |
hana_schema_explorer | read | Explore HANA database schemas and tables |
hana_search_columns | read | Find all columns matching a LIKE pattern across all tables (or within a schema). Uses SYS.TABLE_COLUMNS. Results capped at 1000. |
hana_search_tables | read | Find all tables matching a LIKE pattern across all schemas (or within a specific schema). Uses SYS.TABLES. Results capped at 2000. |
hana_show_config | read | Show the HANA database configuration |
hana_show_env_vars | read | Show all HANA-related environment variables (for debugging) |
hana_test_connection | read | Test connection to HANA database |
schemas | read | List of schema names in the HANA database |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
.markdownlint.json
import { cn } from '../../utils/cn';import { getDatabaseTypeColor, getDatabaseTypeShortName } from '../../utils/databaseTypes'import { cn } from '../../utils/cn'import { colors, shadows, borderRadius } from '../../utils/theme'import { cn } from '../../utils/cn'**Cursor / local IDE over HTTP:** set `HANA_*` in the shell (or process manager) that runs `start:http`, then add an HTTP MCP entry with `url` `http://127.0.0.1:3100/mcp` (`"type": "fetch"` or `"type"
| Endpoint | `POST` JSON-RPC to `/mcp` (default base `http://127.0.0.1:3100`) |
The server exposes **Streamable HTTP** MCP at **`POST /mcp`** (default `http://127.0.0.1:3100/mcp`). HANA credentials apply to the **Node process** that runs the HTTP server, not to the IDE MCP entry
"url": "http://127.0.0.1:3100/mcp"
curl -s http://127.0.0.1:3100/mcp
@heroicons/react, @tailwindcss/forms, @vitejs/plugin-react, autoprefixer, axios, chalk, clsx, cors
@sap/hana-client, axios, jose, nodemon
The server exposes **Streamable HTTP** MCP at **`POST /mcp`** (default `http://127.0.0.1:3100/mcp`). HANA credentials apply to the **Node process** that runs the HTTP server, not to the IDE MCP entry
The HTTP transport does **not** implement a full OAuth 2.0 **authorization-server** flow (no hosted `/authorize` or `/token` on this app). It behaves as a **resource endpoint**: callers send **`Author
The server can also run over HTTP. One JSON‐RPC request per POST; no persistent session.
docs/hana_mcp_ui.gif
hana-mcp-ui/hana_mcp_ui.gif
Gates applied: no_behavioural_pass.
c912c4910a7ffull audit observations/trust-audit/mcp-server/hatrigt__hana.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c912c4910a7f | SAFE | B | 89 | first audit |
Questions
What is the Hana MCP server?
SAP HANA MCP server — Enterprise Model Context Protocol server for SAP HANA. Use with Claude Code, VS Code. npm: hana-mcp-server
What tools does Hana expose?
38 in total: 35 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Hana safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Hana need?
It reads HANA_PASSWORD and MCP_HTTP_AUTH_ENABLED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (c912c4910a7f), read on 2026-10-07. The repository is watched and re-audited when it changes.