Abap ADTSAFE
ABAP ADT MCP server for reading SAP objects (programs, classes, tables, CDS) via ADT
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This project provides a server that allows you to interact with SAP ABAP systems using the Model Context Protocol (MCP). Think of it as a bridge that lets tools like FLUJO, Claude or Cline (a VS Code extension) talk to your ABAP system and retrieve information like source code, table structures, and more. It's like having a remote control for your ABAP development environment!
The server is published on npm as `mcp-abap-adt` and listed in the MCP Registry as io.github.mario-andreschak/mcp-abap-adt, so most MCP clients can install it with a single command.
This checkout uses TypeScript MCP SDK 2 and supports modern protocol 2026-07-28 plus legacy 2025-11-25 over stdio, using the SDK's first-message routing. Node.js 22 or 24 LTS is required. The advertised server version comes from package.json. Tool discovery works without SAP credentials; calls that access SAP require the configuration below. See protocol migration guidance.
The sixteen tools are read-only. Native HTTP is not exposed by this executable; any HTTP bridge has its own authentication, Origin and deployment requirements. Classic screen creation/update requested in #17 remains an open enhancement; see the supported workflow and implementation prerequisites.
This guide is designed for beginners, so we'll walk through everything step-by-step. We'll cover:
- Prerequisites: What you need before you start.
- Installation and Setup: Getting everything up and running.
- Running the Server: Starting the server in different mo
45cf6960166eOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-abap-adt --env SAP_PASSWORD=${SAP_PASSWORD} -- npx -y [email protected]Exposed tools (16)
15 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
GetBehaviorDefinition | read | Retrieve RAP Behavior Definition (BDEF) source code (requires ~NW 7.54 / S/4HANA). For large definitions, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetCDSView | read | Retrieve CDS view (DDL source) source code. For large views, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetClass | read | Retrieve ABAP class source code. For large classes, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetFunction | write | Retrieve ABAP Function Module source code. For large function modules, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetFunctionGroup | read | Retrieve ABAP Function Group source code. For large function groups, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetInclude | read | Retrieve ABAP Include Source Code. For large includes, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetInterface | read | Retrieve ABAP interface source code. For large interfaces, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetPackage | read | Retrieve ABAP package details. Use startLine/maxLines to page large serialized package listings. |
GetProgram | read | Retrieve ABAP program source code. For large programs, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetServiceDefinition | read | Retrieve RAP Service Definition (SRVD) source code (requires ~NW 7.54 / S/4HANA). For large definitions, use startLine/maxLines to page through the source instead of retrieving it all at once. |
GetStructure | read | Retrieve ABAP Structure. For large structures, use startLine/maxLines to page through the result instead of retrieving it all at once. |
GetTable | read | Retrieve ABAP table structure. For large tables, use startLine/maxLines to page through the result instead of retrieving it all at once. |
GetTableContents | read | Retrieve contents of an ABAP table. max_rows limits SAP rows; startLine/maxLines page the returned textual XML when its serialized size is still large. |
GetTransaction | read | Retrieve ABAP transaction details. For large results, use startLine/maxLines to page through it instead of retrieving it all at once. |
GetTypeInfo | read | Retrieve ABAP type information. For large results, use startLine/maxLines to page through it instead of retrieving it all at once. |
SearchObject | read | Search for ABAP objects using quick search. maxResults limits matches; startLine/maxLines page the returned textual XML when its serialized size is still large. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
SAP_URL: "http://127.0.0.1:" + sap.address().port,
@types/jest, @types/node, jest, ts-jest, typescript
2. Open the `.env` file in a text editor (like Notepad, VS Code, etc.).
Gates applied: no_behavioural_pass.
45cf6960166efull audit observations/trust-audit/mcp-server/mario-andreschak__abap-adt.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 45cf6960166e | SAFE | B | 89 | first audit |
Questions
What is the Abap ADT MCP server?
ABAP ADT MCP server for reading SAP objects (programs, classes, tables, CDS) via ADT
What tools does Abap ADT expose?
16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Abap ADT safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Abap ADT need?
It reads SAP_PASSWORD and TLS_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Abap ADT run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-abap-adt at 1.2.0.
How current is this page?
The grade is for one exact copy of the source (45cf6960166e), read on 2026-10-06. The repository is watched and re-audited when it changes.