
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
mcp-abap-abap-adt-api
Advanced tools
MCP server wrapping abap-adt-api for full ABAP ADT development workflows (object CRUD, transports, locking, syntax check, activation) against SAP systems
DISCLAIMER: This server is still in experimental status! Use it with caution!
The MCP-Server mcp-abap-abap-adt-api is a Model Context Protocol (MCP) server designed to facilitate seamless communication between ABAP systems and MCP clients. It is a wrapper for abap-adt-api and provides a suite of tools and resources for managing ABAP objects, handling transport requests, performing code analysis, and more, enhancing the efficiency and effectiveness of ABAP development workflows.
login tool.createTransport and transportInfo.dropSession and logout.The server is published on npm as mcp-abap-abap-adt-api. You don't need to clone or build anything — most MCP clients can launch it directly via npx.
Add it to your MCP client configuration (e.g. Cline, Claude Desktop):
{
"mcpServers": {
"mcp-abap-abap-adt-api": {
"command": "npx",
"args": ["-y", "mcp-abap-abap-adt-api"],
"env": {
"SAP_URL": "https://your-sap-server.com:44300",
"SAP_USER": "YOUR_SAP_USERNAME",
"SAP_PASSWORD": "YOUR_SAP_PASSWORD",
"SAP_CLIENT": "100",
"SAP_LANGUAGE": "EN"
}
}
}
}
If your SAP system uses a self-signed certificate, add "NODE_TLS_REJECT_UNAUTHORIZED": "0" to the env block (development only).
Clone the Repository
git clone https://github.com/mario-andreschak/mcp-abap-abap-adt-api.git
cd mcp-abap-abap-adt-api
Install Dependencies
npm install
Configure Environment Variables
An .env.example file is provided in the root directory as a template for the required environment variables. To set up your environment:
a. Copy the .env.example file and rename it to .env:
cp .env.example .env
b. Open the .env file and replace the placeholder values with your actual SAP connection details:
SAP_URL=https://your-sap-server.com:44300
SAP_USER=YOUR_SAP_USERNAME
SAP_PASSWORD=YOUR_SAP_PASSWORD
SAP_CLIENT=YOUR_SAP_CLIENT
SAP_LANGUAGE=YOUR_SAP_LANGUAGE
Note: The SAP_CLIENT and SAP_LANGUAGE variables are optional but recommended.
If you're using self-signed certificates, you can also set:
NODE_TLS_REJECT_UNAUTHORIZED="0"
IMPORTANT: Never commit your .env file to version control. It's already included in .gitignore to prevent accidental commits.
Build the Project
npm run build
Run the Server
npm run start
(or alternatively integrate the MCP Server into VSCode)
Once the server is running, you can interact with it using MCP clients or tools that support the Model Context Protocol (e.g. Cline). In order to integrate the MCP Server with Cline, use the following MCP Configuration:
"mcp-abap-abap-adt-api": {
"command": "node",
"args": [
"PATH_TO_YOUR/mcp-abap-abap-adt-api/dist/index.js"
],
"disabled": true,
"autoApprove": [
]
},
Use this Custom Instruction to explain the tool to your model:
## mcp-abap-abap-adt-api Server
This server provides tools for interacting with an SAP system via ADT (ABAP Development Tools) APIs. It allows you to retrieve information about ABAP objects, modify source code, and manage transports.
**Key Tools and Usage:**
* **`searchObject`:** Finds ABAP objects based on a query string (e.g., class name).
* `query`: (string, required) The search term.
* Returns the object's URI. Example: `/sap/bc/adt/oo/classes/zcl_invoice_xml_gen_model`
* **`transportInfo`:** Retrieves transport information for a given object.
* `objSourceUrl`: (string, required) The object's URI (obtained from `searchObject`).
* Returns transport details, including the transport request number (`TRKORR` or `transportInfo.LOCKS.HEADER.TRKORR` in the JSON response).
* **`lock`:** Locks an ABAP object for editing.
* `objectUrl`: (string, required) The object's URI.
* Returns a `lockHandle`, which is required for subsequent modifications.
* **`unLock`:** Unlocks a previously locked ABAP object.
* `objectUrl`: (string, required) The object's URI.
* `lockHandle`: (string, required) The lock handle obtained from the `lock` operation.
* **`setObjectSource`:** Modifies the source code of an ABAP object.
* `objectSourceUrl`: (string, required) The object's URI *with the suffix `/source/main`*. Example: `/sap/bc/adt/oo/classes/zcl_invoice_xml_gen_model/source/main`
* `lockHandle`: (string, required) The lock handle obtained from the `lock` operation.
* `source`: (string, required) The complete, modified ABAP source code.
* `transport`: (string, optional) The transport request number.
* **`syntaxCheckCode`:** Performs a syntax check on a given ABAP source code.
* `code`: (string, required) The ABAP source code to check.
* `url`: (string, optional) The URL of the object.
* `mainUrl`: (string, optional) The main URL.
* `mainProgram`: (string, optional) The main program.
* `version`: (string, optional) The version.
* Returns syntax check results, including any errors.
* **`activate`:** Activates an ABAP object. (See notes below on activation/unlocking.)
* `object`: The object to be activated.
* **`getObjectSource`:** Retrieves the source code of an ABAP object.
* `objectSourceUrl`: (string, required) The object's URI *with the suffix `/source/main`*.
**Workflow for Modifying ABAP Code:**
1. **Find the object URI:** Use `searchObject`.
2. **Read the original source code:** Use `getObjectSource` (with the `/source/main` suffix).
3. **Clone and Modify the source code locally:** (e.g., `write_to_file` for creating a local copy, and using `read_file`, `replace_in_file` for modifying this local copy).
4. **Get transport information:** Use `transportInfo`.
5. **Lock the object:** Use `lock`.
6. **Set the modified source code:** Use `setObjectSource` (with the `/source/main` suffix).
7. **Perform a syntax check:** Use `syntaxCheckCode`.
8. **Activate** the object, Use `activate`..
9. **unLock the object:** Use `unLock`.
**Important Notes:**
* **File Handling:** SAP is completly de-coupled from the local file system. Reading source code will only return the code as tool result - it has no effect on file. Files are not synchronized with SAP but merely a local copy for our reference. FYI: It's not strictly necessary for you to create local copies of source codes, as they have no effect on SAP, but it helps us track changes.
* **File Handling:** The local filenames you will use will not contain any paths, but only a filename! It's preferable to use a pattern like "[ObjectName].[ObjectType].abap". (e.g., SAPMV45A.prog.abap for a ABAP Program SAPMV45A, CL_IXML.clas.abap for a Class CL_IXML)
* **URL Suffix:** Remember to add `/source/main` to the object URI when using `setObjectSource` and `getObjectSource`.
* **Transport Request:** Obtain the transport request number (e.g., from `transportInfo` or from the user) and include it in relevant operations.
* **Lock Handle:** The `lockHandle` obtained from the `lock` operation is crucial for `setObjectSource` and `unLock`. Ensure you are using a valid `lockHandle`. If a lock fails, you may need to re-acquire the lock. Locks can expire or be released by other users.
* **Activation/Unlocking Order:** The exact order of `activate` and `unLock` operations might need clarification. Refer to the tool descriptions or ask the user. It appears `activate` can be used without unlocking first.
* **Error Handling:** The tools return JSON responses. Check for error messages within these responses.
## Efficient Database Access
SAP systems contain vast amounts of data. It's crucial to write ABAP code that accesses the database efficiently to minimize performance impact and network traffic. Avoid selecting entire tables or using broad `WHERE` clauses when you only need specific data.
* **Use `WHERE` clauses:** Always use `WHERE` clauses in your `SELECT` statements to filter the data retrieved from the database. Select only the specific rows you need.
* **`UP TO 1 ROWS`:** If you only need a single record, use the `SELECT SINGLE` statement, if you can guarantee that you can provide ALL the key fields for the `SELECT SINGLE` statement. Otherwise, use the `SELECT` statement with the `UP TO 1 ROWS` addition. This tells the database to stop searching after finding the first matching record, improving performance. Example:
```abap
SELECT vgbel FROM vbrp WHERE vbeln = @me->lv_vbeln INTO @DATA(lv_vgbel) UP TO 1 ROWS.
EXIT. " Exit any loop after this.
ENDSELECT.
```
## Checking Table and Structure Definitions
When working with ABAP objects, you may encounter errors related to unknown field names or incorrect table usage. Use the following tools to inspect DDIC (Data Dictionary) objects:
* **`objectStructure`:** Retrieves the structure/metadata of an ABAP object (including DDIC tables and structures) from its object URI. Use `searchObject` first to resolve the object name to a URI.
* **`ddicElement`:** Retrieves details of a DDIC element (e.g. a data element or domain).
* **`ddicRepositoryAccess`:** Reads DDIC repository information for a given path.
* **`tableContents`:** Retrieves the *contents* (rows) of a table, not its definition. Use `runQuery` for ad-hoc `SELECT`s.
> **Note:** Earlier versions of this README listed `GetTable`, `GetStructure`, and `GetTypeInfo`. Those tools are **not** part of this server — they belong to the separate [`mcp-abap-adt`](https://github.com/mario-andreschak/mcp-abap-adt) project. This server (`mcp-abap-abap-adt-api`) exposes the lower-level ADT API tools listed above instead.
## Contributing
Contributions are welcome! Please follow these steps to contribute:
1. **Fork the Repository**
2. **Create a New Branch**
```cmd
git checkout -b feature/your-feature-name
Commit Your Changes
git commit -m "Add some feature"
Push to the Branch
git push origin feature/your-feature-name
Open a Pull Request
This project is licensed under the MIT License.
FAQs
MCP server wrapping abap-adt-api for full ABAP ADT development workflows (object CRUD, transports, locking, syntax check, activation) against SAP systems
The npm package mcp-abap-abap-adt-api receives a total of 99 weekly downloads. As such, mcp-abap-abap-adt-api popularity was classified as not popular.
We found that mcp-abap-abap-adt-api demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.