ABAP ADT APIBLOCK
MCP-Server for SAP ABAP wrapping abap-adt-api
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This server preserves 127 existing SAP ABAP tools and adds readResultPage for large results. Object CRUD, locking, activation, transports, queries, debugging, refactoring, Git and analysis share one SAP session owned by a trusted local stdio client. SAP authorizations determine what that session can read or change.
Installation and protocol
Use Node22.22.2+ or24.15.0+. Run npm ci and npm run build, then configure your MCP client to launch node with the absolute path to dist/index.js. Existing npm/registry releases do not contain this PR until the owner releases it. No release is published here.
{
"mcpServers": {
"abap-adt": {
"command": "node",
"args": ["/absolute/path/mcp-abap-abap-adt-api/dist/index.js"],
"env": {
"SAP_URL": "https://sap.example.invalid:44300",
"SAP_USER": "YOUR_USER",
"SAP_PASSWORD": "YOUR_PASSWORD",
"SAP_CLIENT": "100",
"SAP_LANGUAGE": "EN"
}
}
}
}Public TypeScript MCP2.0.0 supports modern2026-07-28 discovery and legacy2025-11-25 initialization, validated tools, cancellation and proper errors. This package exposes stdio; it is not an HTTP listener or MCP OAuth provider. Missing credentials still allow discovery. healthcheck reports local configuration and session recovery state, not verified SAP connectivity.
Environment comes from the MCP client. Dotenv loads only when SAP_ENV_FILE explicitly names a file. SAP_URL is an origin without a path, query or embedded credentials. For a private CA set NODE_EXTRA_CA_CERTS before launching Node. TLS verification cannot be disabled. Loopback HTTP is allowed for fixtures; a trusted private HTTP deployment requires SAP_ALLOW_HTTP=1 and exposes credentials to that network.
An authorized broker's static SAP_BEARER_TOKEN can replace the password. Rotate it by restarting the process; this does not implement XSUAA grants or prove tenant acceptance. No password-grant f
135c3f9be0fbOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-abap-abap-adt-api --env SAP_PASSWORD=${SAP_PASSWORD} --env SAP_BEARER_TOKEN=${SAP_BEARER_TOKEN} -- npx -y [email protected]Exposed tools (126)
118 read · 6 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
abapDocumentation | read | Retrieves ABAP documentation. |
activateByName | read | Activate an ABAP object using name and URL |
activateObjects | read | Activate ABAP objects using object references |
adtCompatibiliyGraph | read | Retrieves the ADT compatibility graph. |
adtCoreDiscovery | read | Performs ADT core discovery. |
adtDiscovery | read | Performs ADT discovery. |
annotationDefinitions | read | Retrieves annotation definitions. |
atcChangeContact | read | Changes the contact for an ATC finding. |
atcCheckVariant | read | Retrieves information about an ATC check variant. |
atcContactUri | read | Retrieves the contact URI for an ATC finding. |
atcCustomizing | read | Retrieves ATC customizing information. |
atcExemptProposal | read | Retrieves an ATC exemption proposal. |
atcRequestExemption | read | Requests an ATC exemption. |
atcUsers | read | Retrieves a list of ATC users. |
atcWorklists | read | Retrieves ATC worklists. |
bindingDetails | read | Retrieves details of a service binding. |
checkRepo | read | Checks a Git repository. |
classComponents | read | List class components |
classIncludes | read | Get class includes structure |
codeCompletion | read | Get code completion suggestions |
codeCompletionElement | read | Retrieves code completion element information. |
codeCompletionFull | read | Performs full code completion. |
collectionFeatureDetails | read | Retrieves details for a given collection feature. |
createAtcRun | write | Creates an ATC run. |
createObject | write | Create a new ABAP object |
createTestInclude | read | Creates a test include for a class. |
createTransport | write | Create a new transport request |
createTransportsConfig | read | Creates transport configurations. |
ddicElement | read | Retrieves information about a DDIC element. |
ddicRepositoryAccess | read | Accesses the DDIC repository. |
debuggerAttach | read | Attaches the debugger. |
debuggerChildVariables | read | Retrieves child variables of a debugger variable. |
debuggerDeleteBreakpoints | read | Deletes breakpoints. |
debuggerDeleteListener | read | Stops a debug listener. |
debuggerGoToStack | read | Navigates to a specific stack entry in the debugger. |
debuggerListen | read | Listens for debugging events. |
debuggerListeners | read | Retrieves a list of debugger listeners. |
debuggerSaveSettings | read | Saves debugger settings. |
debuggerSetBreakpoints | read | Sets breakpoints. |
debuggerSetVariableValue | read | Sets the value of a debugger variable. |
debuggerStackTrace | read | Retrieves the debugger stack trace. |
debuggerStep | read | Performs a debugger step. |
debuggerVariables | read | Retrieves debugger variables. |
deleteObject | read | Deletes an ABAP object from the system |
dropSession | destructive | Clear local session cache |
dumps | read | Retrieves a list of dumps. |
extractMethodEvaluate | read | Evaluates an extract method refactoring. |
extractMethodExecute | read | Executes an extract method refactoring. |
extractMethodPreview | read | Previews an extract method refactoring. |
featureDetails | read | Retrieves details for a given feature. |
feeds | read | Retrieves a list of feeds. |
findCollectionByUrl | read | Finds a collection by its URL. |
findDefinition | read | Find symbol definition |
findObjectPath | read | Find path for an object |
fixEdits | read | Applies fix edits. |
fixProposals | read | Retrieves fix proposals. |
fragmentMappings | read | Retrieves fragment mappings. |
getObjectSource | read | Retrieves source code for ABAP objects. For large objects, use startLine/maxLines to page through the source instead of retrieving it all at once. |
getTransportConfiguration | read | Retrieves a specific transport configuration. |
gitCreateRepo | read | Creates a new Git repository. |
gitExternalRepoInfo | read | Retrieves information about an external Git repository. |
gitPullRepo | read | Pulls changes from a Git repository. |
gitRepos | read | Retrieves a list of Git repositories. |
gitUnlinkRepo | read | Unlinks a Git repository. |
hasTransportConfig | read | Check if transport configuration exists |
inactiveObjects | read | Get list of inactive objects |
isProposalMessage | read | Checks if a given object is a proposal message. |
loadTypes | read | Loads object types. |
lock | read | Lock an object |
login | read | Authenticate with ABAP system |
logout | destructive | Terminate ABAP session |
mainPrograms | read | Retrieves the main programs for a given include. |
nodeContents | read | Retrieves the contents of a node in the ABAP repository tree. |
objectRegistrationInfo | read | Get registration information for an ABAP object |
objectStructure | read | Get object structure details |
objectTypes | read | Retrieves object types. |
packageSearchHelp | read | Performs a package search help. |
prettyPrinter | read | Formats ABAP code using the pretty printer. |
prettyPrinterSetting | read | Retrieves the pretty printer settings. |
publishServiceBinding | read | Publishes a service binding. |
pushRepo | read | Pushes changes to a Git repository. |
reentranceTicket | read | Retrieves a reentrance ticket. |
remoteRepoInfo | read | Retrieves information about a remote Git repository. |
renameEvaluate | write | Evaluates a rename refactoring. |
renameExecute | write | Executes a rename refactoring. |
renamePreview | write | Previews a rename refactoring. |
revisions | read | Retrieves revisions for an object. |
runClass | read | Runs a class. |
runQuery | read | Runs a SQL query on the target system. |
searchObject | read | Search for objects |
setObjectSource | read | Sets source code for ABAP objects |
setPrettyPrinterSetting | read | Sets the pretty printer settings. |
setTransportsConfig | read | Sets transport configurations. |
stageRepo | read | Stages changes in a Git repository. |
switchRepoBranch | read | Switches the branch of a Git repository. |
syntaxCheckCdsUrl | read | Perform ABAP syntax check with CDS URL |
syntaxCheckCode | read | Perform ABAP syntax check. Provide the source in |
syntaxCheckTypes | read | Retrieves syntax check types. |
systemUsers | read | Retrieves a list of system users. |
tableContents | read | Retrieves the contents of an ABAP table. |
tracesCreateConfiguration | read | Creates a trace configuration. |
tracesDbAccess | read | Retrieves database access information for a trace. |
tracesDelete | read | Deletes a trace. |
tracesDeleteConfiguration | read | Deletes a trace configuration. |
tracesHitList | read | Retrieves the hit list for a trace. |
tracesList | read | Retrieves a list of traces. |
tracesListRequests | read | Retrieves a list of trace requests. |
tracesSetParameters | read | Sets trace parameters. |
tracesStatements | read | Retrieves statements for a trace. |
transportAddUser | read | Adds a user to a transport. |
transportConfigurations | read | Retrieves transport configurations. |
transportDelete | read | Deletes a transport. |
transportInfo | read | Get transport information for an object source |
transportReference | read | Retrieves a transport reference. |
transportRelease | read | Releases a transport. |
transportSetOwner | read | Sets the owner of a transport. |
transportsByConfig | read | Retrieves transports by configuration. |
unLock | read | Unlock an object |
unPublishServiceBinding | read | Unpublishes a service binding. |
unitTestEvaluation | read | Evaluates unit test results. |
unitTestOccurrenceMarkers | read | Retrieves unit test occurrence markers. |
unitTestRun | read | Runs unit tests. |
usageReferenceSnippets | read | Retrieves usage reference snippets. |
usageReferences | read | Find symbol references |
userTransports | read | Retrieves transports for a user. |
validateNewObject | read | Validate parameters for a new ABAP object |
Trust audit
BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
exec(
exec(
exec(["audit", "--omit=dev"], dir);
url: `http://127.0.0.1:${server.address().port}`,dropSession, logout
const base = `http://127.0.0.1:${(server.address() as any).port}`;This server preserves 127 existing SAP ABAP tools and adds `readResultPage` for large results. Object CRUD, locking, activation, transports, queries, debugging, refactoring, Git and analysis share one
Gates applied: no_behavioural_pass.
135c3f9be0fbfull audit observations/trust-audit/mcp-server/mario-andreschak__abap-adt-api.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 135c3f9be0fb | BLOCK | D | 68 | first audit |
Questions
What is the ABAP ADT API MCP server?
MCP-Server for SAP ABAP wrapping abap-adt-api
What tools does ABAP ADT API expose?
126 in total: 118 read-only, 6 that write, and 2 that can delete or overwrite (dropSession, logout). Every one is listed on this page with its risk.
Is ABAP ADT API safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (68/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ABAP ADT API need?
It reads SAP_BEARER_TOKEN and SAP_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ABAP ADT API run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-abap-abap-adt-api at 0.1.1.
How current is this page?
The grade is for one exact copy of the source (135c3f9be0fb), read on 2026-10-06. The repository is watched and re-audited when it changes.