ERPNextSAFE
Connect AI assistants to your ERPNext instance via the Model Context Protocol (MCP) using the official Frappe API.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol server for ERPNext integration
This is a TypeScript-based MCP server that provides integration with ERPNext/Frappe API. It enables AI assistants to interact with ERPNext data and functionality through the Model Context Protocol.
Features
Resources
- Access ERPNext documents via
erpnext://{doctype}/{name}URIs - JSON format for structured data access
Tools
get_doctypes- Get a list of all available DocTypesget_doctype_fields- Get fields list for a specific DocTypeget_documents- Get a list of documents for a specific doctypeget_document- Get a single document by name, including all child tablescreate_document- Create a new document in ERPNextupdate_document- Update an existing document in ERPNextdelete_document- Permanently delete a documentsubmit_document- Submit a document (set docstatus to 1)cancel_document- Cancel a submitted document (set docstatus to 2)call_method- Call an ERPNext/Frappe whitelisted server-side API methodrun_report- Run an ERPNext report
Configuration
The server requires the following environment variables:
ERPNEXT_URL- The base URL of your ERPNext instanceERPNEXT_API_KEY(optional) - API key for authenticationERPNEXT_API_SECRET(optional) - API secret for authentication
Development
Install dependencies:
npm install
Build the server:
npm run build
For development with auto-rebuild:
npm run watch
Installation
To use with Claude Desktop, add the server config:
On MacOS: ~/Library/Application Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json
{
"mcpServers": {
"erpnext": {
"command": "node",
"args": ["/path/to/erpnext-server/build/index.js"],
"env": {
"ERPNEXT_URL": "http://your-erpnext-instance.com",
"ERPNEXT_API_KEY": "your-api-key",
"ERPNEXT_API_d6fcc7b6bb0bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add erpnext-server --env ERPNEXT_API_KEY=${ERPNEXT_API_KEY} --env ERPNEXT_API_SECRET=${ERPNEXT_API_SECRET} -- npx -y [email protected]{
"mcpServers": {
"erpnext-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ERPNEXT_API_KEY": "${ERPNEXT_API_KEY}",
"ERPNEXT_API_SECRET": "${ERPNEXT_API_SECRET}"
}
}
}
}Exposed tools (11)
4 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
call_method | write | Call an ERPNext/Frappe whitelisted server-side API method. Can invoke any whitelisted method — use with caution. Args are passed as JSON body (POST) or query params (GET). |
cancel_document | write | Cancel a submitted document (set docstatus to 2). Cancelled documents cannot be modified — use amend workflow to create a corrected copy. |
create_document | write | Create a new document in ERPNext |
delete_document | destructive | Permanently delete a document from ERPNext. This action cannot be undone. Submitted documents must be cancelled before deletion. |
get_doctype_fields | read | Get fields list for a specific DocType |
get_doctypes | read | Get a list of all available DocTypes |
get_document | read | Get a single document by DocType and name, including all child tables and linked data |
get_documents | read | Get a list of documents for a specific doctype |
run_report | write | Run an ERPNext report |
submit_document | write | Submit a document (set docstatus to 1). Only works on submittable doctypes. Submitted documents can only be cancelled, not reverted to draft. |
update_document | write | Update an existing document in ERPNext |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
delete_document
@modelcontextprotocol/sdk, axios, zod, @types/node, typescript
// Load environment variables from .env file if it exists
Gates applied: no_behavioural_pass.
d6fcc7b6bb0bfull audit observations/trust-audit/mcp-server/rakeshgangwar__erpnext.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d6fcc7b6bb0b | SAFE | B | 89 | first audit |
Questions
What is the ERPNext MCP server?
Connect AI assistants to your ERPNext instance via the Model Context Protocol (MCP) using the official Frappe API.
What tools does ERPNext expose?
11 in total: 4 read-only, 6 that write, and 1 that can delete or overwrite (delete_document). Every one is listed on this page with its risk.
Is ERPNext safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ERPNext need?
It reads ERPNEXT_API_KEY and ERPNEXT_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ERPNext run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as erpnext-server at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (d6fcc7b6bb0b), read on 2026-10-07. The repository is watched and re-audited when it changes.