Atlas / MCP servers / rakeshgangwar / ERPNext

ERPNextSAFE

mcp/rakeshgangwar/erpnext

Connect AI assistants to your ERPNext instance via the Model Context Protocol (MCP) using the official Frappe API.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
11 4r · 6w · 1d
Transport
stdio
License
MIT
Stars
122
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol server for ERPNext integration

This is a TypeScript-based MCP server that provides integration with ERPNext/Frappe API. It enables AI assistants to interact with ERPNext data and functionality through the Model Context Protocol.

Features

Resources

  • Access ERPNext documents via erpnext://{doctype}/{name} URIs
  • JSON format for structured data access

Tools

  • get_doctypes - Get a list of all available DocTypes
  • get_doctype_fields - Get fields list for a specific DocType
  • get_documents - Get a list of documents for a specific doctype
  • get_document - Get a single document by name, including all child tables
  • create_document - Create a new document in ERPNext
  • update_document - Update an existing document in ERPNext
  • delete_document - Permanently delete a document
  • submit_document - Submit a document (set docstatus to 1)
  • cancel_document - Cancel a submitted document (set docstatus to 2)
  • call_method - Call an ERPNext/Frappe whitelisted server-side API method
  • run_report - Run an ERPNext report

Configuration

The server requires the following environment variables:

  • ERPNEXT_URL - The base URL of your ERPNext instance
  • ERPNEXT_API_KEY (optional) - API key for authentication
  • ERPNEXT_API_SECRET (optional) - API secret for authentication

Development

Install dependencies:

npm install

Build the server:

npm run build

For development with auto-rebuild:

npm run watch

Installation

To use with Claude Desktop, add the server config:

On MacOS: ~/Library/Application Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json

{
"mcpServers": {
"erpnext": {
"command": "node",
"args": ["/path/to/erpnext-server/build/index.js"],
"env": {
"ERPNEXT_URL": "http://your-erpnext-instance.com",
"ERPNEXT_API_KEY": "your-api-key",
"ERPNEXT_API_
Read from source at commit d6fcc7b6bb0bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add erpnext-server --env ERPNEXT_API_KEY=${ERPNEXT_API_KEY} --env ERPNEXT_API_SECRET=${ERPNEXT_API_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "erpnext-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ERPNEXT_API_KEY": "${ERPNEXT_API_KEY}",
        "ERPNEXT_API_SECRET": "${ERPNEXT_API_SECRET}"
      }
    }
  }
}
03

Exposed tools (11)

4 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
call_methodwriteCall an ERPNext/Frappe whitelisted server-side API method. Can invoke any whitelisted method — use with caution. Args are passed as JSON body (POST) or query params (GET).
cancel_documentwriteCancel a submitted document (set docstatus to 2). Cancelled documents cannot be modified — use amend workflow to create a corrected copy.
create_documentwriteCreate a new document in ERPNext
delete_documentdestructivePermanently delete a document from ERPNext. This action cannot be undone. Submitted documents must be cancelled before deletion.
get_doctype_fieldsreadGet fields list for a specific DocType
get_doctypesreadGet a list of all available DocTypes
get_documentreadGet a single document by DocType and name, including all child tables and linked data
get_documentsreadGet a list of documents for a specific doctype
run_reportwriteRun an ERPNext report
submit_documentwriteSubmit a document (set docstatus to 1). Only works on submittable doctypes. Submitted documents can only be cancelled, not reverted to draft.
update_documentwriteUpdate an existing document in ERPNext
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_document
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, zod, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/security-and-authentication.md:277
// Load environment variables from .env file if it exists
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d6fcc7b6bb0bfull audit observations/trust-audit/mcp-server/rakeshgangwar__erpnext.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d6fcc7b6bb0bSAFEB89first audit
06

Questions

What is the ERPNext MCP server?

Connect AI assistants to your ERPNext instance via the Model Context Protocol (MCP) using the official Frappe API.

What tools does ERPNext expose?

11 in total: 4 read-only, 6 that write, and 1 that can delete or overwrite (delete_document). Every one is listed on this page with its risk.

Is ERPNext safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ERPNext need?

It reads ERPNEXT_API_KEY and ERPNEXT_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ERPNext run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as erpnext-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (d6fcc7b6bb0b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement