Atlas / MCP servers / mariodefelipe / SAP Datasphere

SAP DatasphereCAUTION

mcp/mariodefelipe/sap-datasphere

SAP Datasphere MCP Server - AI-powered access to SAP Datasphere APIs

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
21 20r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
48
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/sap-datasphere-mcp/) [](https://www.npmjs.com/package/@mariodefe/sap-datasphere-mcp) [](https://www.python.org/downloads/) [](https://modelcontextprotocol.io/) [](https://opensource.org/licenses/MIT) [](https://pypi.org/project/sap-datasphere-mcp/) []()

Production-ready Model Context Protocol (MCP) server that enables AI assistants to seamlessly interact with SAP Datasphere environments for real tenant data discovery, metadata exploration, analytics operations, ETL data extraction, database user management, data lineage analysis, and column-level data profiling — with built-in config-driven PII masking so sensitive fields never reach the LLM.

📦 Which version do I install?

pip install sap-datasphere-mcp gives you 2.x. The 2.x server is dual-era: it answers both the modern server/discover handshake and the legacy initialize one, so 2025-era clients keep working without changes.

Stay on 1.x only if your environment cannot install SDK 2.x:

pip install 'sap-datasphere-mcp<2'

🆕 What's New (v2.0.1 — MCP SDK v2 / stateless spec)

  • Ported to MCP Python SDK 2.0.0 and the 2026-07-28 stateless specification. Handlers moved from the remo
Read from source at commit 8bb60c4d850bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add sap-datasphere-mcp --env DATASPHERE_CLIENT_SECRET=${DATASPHERE_CLIENT_SECRET} --env DATASPHERE_TOKEN_URL=${DATASPHERE_TOKEN_URL} --env MCP_HTTP_AUTH_TOKEN=${MCP_HTTP_AUTH_TOKEN} -- npx -y @mariodefe/[email protected]
claude-desktop
{
  "mcpServers": {
    "sap-datasphere-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@mariodefe/[email protected]"
      ],
      "env": {
        "DATASPHERE_CLIENT_SECRET": "${DATASPHERE_CLIENT_SECRET}",
        "DATASPHERE_TOKEN_URL": "${DATASPHERE_TOKEN_URL}",
        "MCP_HTTP_AUTH_TOKEN": "${MCP_HTTP_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (21)

20 read · 1 write · 0 destructive.

ToolRiskDescription
execute_querywriteExecute a SQL query against Datasphere data (simulated)
get_analytical_metadatareadRetrieve CSDL metadata for analytical consumption of a specific asset. Returns analytical schema with dimensions, measures, hierarchies, and aggregation information for BI and analytics integration. Automatically identifies analytical elements based on SAP annotations.
get_analytical_service_documentreadGet the OData service document for a specific analytical asset. Returns the service root with available entity sets and their URLs. Lightweight endpoint to discover what data is available without retrieving full metadata.
get_available_scopesreadList available OAuth2 scopes for the current user, showing which scopes are granted and which are available but not granted. Includes scope descriptions and the token
get_catalog_metadatareadGet CSDL metadata for the SAP Datasphere catalog service. Retrieves the OData metadata document (CSDL XML) that describes the catalog service schema including entity types, properties, relationships, and available operations. Essential for understanding the catalog structure.
get_consumption_metadatareadGet CSDL metadata for SAP Datasphere consumption models. Retrieves the overall consumption service schema including entity types, properties, navigation relationships, and complex types. Essential for understanding the consumption layer structure and planning data integrations.
get_current_userreadGet authenticated user information including user ID, email, display name, roles, permissions, and account status. Use this to understand the current user
get_relational_entity_metadatareadGet detailed metadata for a specific relational entity including column definitions, data types, SQL type mappings, and ETL extraction capabilities. Optimized for data warehouse loading and transformation workflows.
get_relational_metadatareadRetrieve CSDL metadata for relational consumption of a specific asset. Returns complete schema information including tables, columns, data types, primary/foreign keys, and relationships for relational data access and ETL planning. Includes SQL type mapping.
get_relational_odata_servicereadGet the OData service document for a relational asset showing available entity sets, navigation properties, function imports, and query capabilities. Essential for ETL planning and understanding data extraction options.
get_repository_search_metadatareadGet metadata for repository search capabilities. Retrieves information about searchable object types, searchable fields, available filters, and entity definitions. Essential for building advanced search queries and understanding repository structure.
get_space_inforeadGet detailed information about a specific Datasphere space
get_tenant_inforeadRetrieve SAP Datasphere tenant configuration and system information including tenant ID, region, version, license type, storage quota/usage, user count, space count, enabled features, and maintenance windows. Use this for system administration and capacity planning.
list_analytical_datasetsreadList all available analytical datasets within a specific asset. Discovers analytical models that can be queried for business intelligence and reporting. Returns entity sets with their names, types, and URLs for data access.
list_connectionsreadList all data source connections and their status
list_relational_entitiesreadList all available relational entities (tables/views) within a specific SAP Datasphere asset for row-level data access and ETL operations. Returns OData entity sets that can be queried for detailed data extraction.
list_spacesreadList all Datasphere spaces with their status and metadata
search_catalogreadUniversal search across all catalog items in SAP Datasphere using advanced search syntax. Supports searching across KPIs, assets, spaces, models, views, and tables. Use SCOPE:<scope_name> prefix for targeted searches. Boolean operators (AND, OR, NOT) supported.
search_repositoryreadGlobal search across all repository objects in SAP Datasphere. Search through tables, views, analytical models, data flows, and transformations. Provides comprehensive object discovery with lineage and dependency information.
search_tablesreadSearch for tables and views across Datasphere spaces
test_connectionreadTest the connection to SAP Datasphere and verify OAuth authentication status. Use this tool to check if the MCP server can successfully connect to SAP Datasphere.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (22)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
auth/oauth_handler.py:203
logger.info(f"Access token acquired successfully (expires in {token.expires_in}s)")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
auth/oauth_handler.py:283
logger.info(f"Token refreshed successfully (expires in {token.expires_in}s)")
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ruff.toml
.ruff.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.secrets.baseline
.secrets.baseline
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_input_validation.py:132
"SPACE/../../admin",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_input_validation.py:133
"../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_sdk_v2_protocol.py:136
return await c.call_tool("get_space_info", {"space_id": "SPACE/../../admin"})
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:128
# Streamable HTTP on http://127.0.0.1:8080/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:152
curl -N -X POST http://127.0.0.1:8080/mcp/ \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_sdk_v2_protocol.py:221
base = f"http://127.0.0.1:{port}"
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_no_live_tenant_data.py:52
DENYLIST = [base64.b64decode(t).decode() for t in _DENIED_B64]
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-asyncio, black, ruff, mypy, pre-commit
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, fastapi, uvicorn, PyYAML
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
AUTHORIZATION_FIX_COMPLETE.md:52
Administrative operations requiring elevated permissions:
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
OAUTH_PERMISSIONS_GUIDE.md:29
- **DW Space Administrator** - Full access to space data and APIs
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
DEPLOYMENT.md:180
cat > .env << EOF
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
OAUTH_REAL_CONNECTION_SETUP.md:74
Open `.env` in a text editor and fill in your actual values:
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
OAUTH_REAL_CONNECTION_SETUP.md:119
The MCP server needs to be updated to load OAuth configuration from environment variables.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
OAUTH_REAL_CONNECTION_SETUP.md:137
1. Load `.env` configuration on startup
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
OAUTH_REAL_CONNECTION_SETUP.md:161
# Load environment variables
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
EXACT_API_FLOW.md:10
POST https://ailien-test.authentication.eu20.hana.ondemand.com/oauth/token
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8bb60c4d850bfull audit observations/trust-audit/mcp-server/mariodefelipe__sap-datasphere.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088bb60c4d850bCAUTIONB83first audit
06

Questions

What is the SAP Datasphere MCP server?

SAP Datasphere MCP Server - AI-powered access to SAP Datasphere APIs

What tools does SAP Datasphere expose?

21 in total: 20 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SAP Datasphere safe to connect to an agent?

With care. The audit graded it B (83/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does SAP Datasphere need?

It reads DATASPHERE_CLIENT_SECRET, DATASPHERE_TOKEN_URL and MCP_HTTP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SAP Datasphere run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mariodefe/sap-datasphere-mcp at 2.0.3.

How current is this page?

The grade is for one exact copy of the source (8bb60c4d850b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement