SAP MCP Gateway
A reference implementation for connecting SAP Business One to MCP-compatible AI clients, enabling read-only SQL analysis and guarded write workflows.
README
SAP MCP Gateway
A sanitized reference implementation for connecting SAP Business One to MCP-compatible AI clients.
This repository demonstrates a gateway architecture for Service Layer access, read-only SQL analysis, OAuth/PKCE client flows, local action drafts and explicit write gates. It is a public competence showcase and not a production deployment package.
Included
- MCP over stdio and HTTP
- SAP Business One Service Layer reads with bounded pagination
- Optional read-only SQL analysis with query and result limits
- Draft, preflight, review and explicit execution workflow for SAP actions
- OAuth discovery, dynamic client registration and PKCE authorization flow
- Audit logging, stream-size protections and defensive error handling
- Unit and integration-style tests with synthetic data
Quick start
npm ci
npm run typecheck
npm run build
npm test
npm run lint
Copy .env.example to .env for local experimentation. The values in that file are placeholders; never commit credentials or live endpoints.
For a container build:
docker compose -f docker-compose.example.yml up --build
Architecture
src/server.ts— process entry pointsrc/http/— HTTP and MCP transportsrc/mcp/— MCP server constructionsrc/sap/— Service Layer and SQL client adapterssrc/tools/— tool schemas, read operations and guarded action workflowssrc/security/— authentication, OAuth and write safety gatessrc/store/— local draft and audit persistencetests/— automated tests using synthetic fixtures
See docs/architecture.md and docs/security.md for the public design notes.
Public boundary
This split intentionally excludes customer data, generated deployment output, live validation scripts, SSH/Tailscale instructions, server names, production URLs, private operational runbooks and company-specific domain templates. The examples use reserved .invalid hostnames and synthetic values.
The gateway defaults to read-only behavior. Enabling SAP writes requires deliberate configuration and should only be done in an isolated development environment after an independent review.
License
Licensed under the PolyForm Noncommercial License 1.0.0. Private and noncommercial use is permitted; commercial or business use is not permitted under this license. Dependencies and any third-party code remain subject to their own licenses.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.