SAP DocumentationSAFE
Fast MCP server for unified SAP docs search (SAPUI5, CAP, OpenUI5, wdi5) with BM25 full-text search
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server that gives AI assistants (Claude, Cursor, ChatGPT, etc.) access to SAP documentation through a unified search and fetch interface. It combines a local full-text + semantic index over git-cloned SAP docs with optional live queries to SAP Help, SAP Community, and Software Heroes — all exposed as MCP tools.
Install
[![Add to Werkbank][werkbank-badge]][werkbank-install]
Or add it to any MCP client that supports streamable HTTP:
{
"mcpServers": {
"sap-docs": {
"type": "http",
"url": "https://mcp-sap-docs.marianzeis.de/mcp"
}
}
}No API key or login required — the server is public and read-only.
Public Hosted Endpoint
Ready to use — no setup required | Variant | URL | |---------|-----| | SAP Docs |http://mcp-sap-docs.marianzeis.de/mcp| | ABAP |https://mcp-abap.marianzeis.de/mcp|
Variants
mcp-sap-docs is the upstream repository for two MCP server variants that share one codebase and differ by configuration (MCP_VARIANT / .mcp-variant):
Documentation Sources
Offline sources (local index, always available)
b8809c6260a1OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-sap-docs -- npx -y [email protected]
{
"mcpServers": {
"mcp-sap-docs": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (24)
24 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
SAPUI5 | read | Official SAPUI5 Markdown documentation |
abap_feature_matrix | read | ABAP FEATURE MATRIX: abap_feature_matrix(query= |
abap_lint | read | LINT ABAP CODE: abap_lint(code= |
abap_search_help | read | Helps users construct effective search queries for ABAP and RAP documentation |
abap_troubleshoot | read | Guides users through troubleshooting common ABAP development issues |
collect-vanilla | read | Collect vanilla MCP results (append-only, 5 queries per agent) |
context | read | Development context (RAP, CDS, classic ABAP, etc.) |
domain | read | SAP domain (UI5, CAP, ABAP, etc.) |
error_message | read | Error message or symptom description |
fetch | read | GET FULL DOCUMENT CONTENT: fetch(id= |
flavor | read | ABAP flavor: standard (on-premise) or cloud (BTP) |
pairwise-eval | read | Pairwise LLM-as-judge eval: local MCP (reranker on) vs vanilla MCP for 44 eval queries |
sap_community_search | read | SEARCH SAP COMMUNITY: sap_community_search(query= |
sap_discovery_center_search | read | SEARCH SAP BTP SERVICES: sap_discovery_center_search(query= |
sap_discovery_center_service | read | GET SAP BTP SERVICE DETAILS: sap_discovery_center_service(serviceId= |
sap_get_object_details | read | GET SAP OBJECT DETAILS: sap_get_object_details(object_type= |
sap_search_help | read | Helps users construct effective search queries for SAP documentation |
sap_search_objects | read | SEARCH SAP RELEASED OBJECTS: sap_search_objects(query= |
sap_troubleshoot | read | Guides users through troubleshooting common SAP development issues |
search | read | SEARCH ABAP/RAP DOCUMENTATION: search(query= |
technology | read | SAP technology stack (UI5, CAP, ABAP, etc.) |
topic | read | ABAP topic (RAP, CDS, BOPF, etc.) |
ui5_version_diff | read | UI5 VERSION DIFF: ui5_version_diff(library= |
wdi5 | read | wdi5 end-to-end test framework documentation |
Trust audit
SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (20)
.cursorignore
.gitmodules
.mcp-variant
.release-please-manifest.json
const hash = createHash('sha1').update(hashInput).digest('hex').slice(0, 12);const packagePath = join(__dirname, "../../package.json");
const sourcesRoot = join(__dirname, "../../sources");
const dataRoot = join(__dirname, "../../data");
PROJECT_ROOT = path.resolve(__dirname, "../../..");
projectRoot = path.resolve(__dirname, "../../..");
for i in $(seq 1 30); do curl -fsS http://127.0.0.1:3001/status >/dev/null && break || sleep 2; done
curl -fsS http://127.0.0.1:3001/status
for i in $(seq 1 30); do curl -fsS http://127.0.0.1:3122/health >/dev/null && break || sleep 2; done
curl -fsS http://127.0.0.1:3122/health
SEARCH_TEST=$(curl -s -X POST http://127.0.0.1:3001/mcp -H "Content-Type: application/json" -d '{"role": "user", "content": "test search"}')console.log(paint(" rank Δrank query", "dim"));console.log(` ΔMRR 95% CI ${paint(ciStr, real ? (ci.point > 0 ? "green" : "red") : "yellow")} ${real ? paint("real", "green") : paint("within noise", "yellow")}`);@abaplint/core, @huggingface/transformers, @modelcontextprotocol/sdk, better-sqlite3, cors, express, fast-glob, gray-matter
IFS= read -r CF_PASSWORD
$Secure = Read-Host "CF password" -AsSecureString
Gates applied: no_behavioural_pass.
b8809c6260a1full audit observations/trust-audit/mcp-server/marianfoo__sap-documentation.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | b8809c6260a1 | SAFE | B | 87 | first audit |
Questions
What is the SAP Documentation MCP server?
Fast MCP server for unified SAP docs search (SAPUI5, CAP, OpenUI5, wdi5) with BM25 full-text search
What tools does SAP Documentation expose?
24 in total: 24 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SAP Documentation safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does SAP Documentation need?
No credential environment variables were found in its source, so it appears to need none.
How does SAP Documentation run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-sap-docs at 0.3.55.
How current is this page?
The grade is for one exact copy of the source (b8809c6260a1), read on 2026-10-06. The repository is watched and re-audited when it changes.