
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
frappe-mcp-server
Advanced tools
MCP server for Frappe Framework — interact with Frappe sites via Claude, Copilot, and other MCP clients
mcp-name: io.github.muthanii/frappe_mcp
A Model Context Protocol (MCP) server for Frappe Framework. Connect Claude Desktop, VS Code Copilot, and other MCP clients to any Frappe/ERPNext site via its REST API.
| Distribution | Reference | Page |
|---|---|---|
| PyPI | frappe-mcp-server | pypi.org/project/frappe-mcp-server |
| Docker Hub | muthanii/frappe-mcp | hub.docker.com/r/muthanii/frappe-mcp |
| GitHub Container Registry | ghcr.io/muthanii/frappe-mcp | ghcr package |
| MCP Registry | io.github.muthanii/frappe_mcp | registry API |
| Glama | — | glama.ai/mcp/servers/muthanii/frappe_mcp |
| Source | — | github.com/muthanii/frappe_mcp |
docker run command, no Python install neededWith uvx (no install):
FRAPPE_URL=https://your-site.com \
FRAPPE_API_KEY=your-api-key \
FRAPPE_API_SECRET=your-api-secret \
uvx frappe-mcp-server
With pip:
pip install frappe-mcp-server
frappe-mcp-server
With Docker (Docker Hub):
docker run -i --rm \
-e FRAPPE_URL=https://your-site.com \
-e FRAPPE_API_KEY=your-api-key \
-e FRAPPE_API_SECRET=your-api-secret \
muthanii/frappe-mcp
With Docker (GHCR):
docker run -i --rm \
-e FRAPPE_URL=https://your-site.com \
-e FRAPPE_API_KEY=your-api-key \
-e FRAPPE_API_SECRET=your-api-secret \
ghcr.io/muthanii/frappe-mcp
Every tool ships MCP tool annotations and a declared outputSchema, so a client can tell read tools from destructive ones before calling them.
| Tool | Description | Access | Destructive | Idempotent |
|---|---|---|---|---|
frappe_ping | Check connectivity and credentials | read-only | no | yes |
frappe_get_doc | Retrieve a single document by doctype + name | read-only | no | yes |
frappe_search_docs | Search/list documents with filters | read-only | no | yes |
frappe_create_doc | Create a new document | write | no | no |
frappe_update_doc | Update an existing document | write | yes | yes |
frappe_delete_doc | Delete a document — irreversible | write | yes | no |
frappe_run_method | Call a whitelisted server-side method | write | yes | no |
frappe_run_method is marked destructive because its effect is determined entirely by the method you name.
| Environment variable | Required | Description |
|---|---|---|
FRAPPE_URL | Yes | Base URL of your Frappe site (e.g. https://erp.example.com) |
FRAPPE_API_KEY | Yes | Frappe API key |
FRAPPE_API_SECRET | Yes | Frappe API secret |
FRAPPE_VERIFY_SSL | No | Set to false to skip TLS verification (default: true) |
FRAPPE_TIMEOUT | No | Request timeout in seconds (default: 30) |
Add this to your claude_desktop_config.json or Copilot config.
Via uvx:
{
"mcpServers": {
"frappe": {
"command": "uvx",
"args": ["frappe-mcp-server"],
"env": {
"FRAPPE_URL": "https://your-site.com",
"FRAPPE_API_KEY": "your-api-key",
"FRAPPE_API_SECRET": "your-api-secret"
}
}
}
}
Via Docker:
{
"mcpServers": {
"frappe": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "FRAPPE_URL",
"-e", "FRAPPE_API_KEY",
"-e", "FRAPPE_API_SECRET",
"muthanii/frappe-mcp"
],
"env": {
"FRAPPE_URL": "https://your-site.com",
"FRAPPE_API_KEY": "your-api-key",
"FRAPPE_API_SECRET": "your-api-secret"
}
}
}
}
pip install -e .
frappe-mcp
MIT — see LICENSE.
FAQs
MCP server for Frappe Framework — interact with Frappe sites via Claude, Copilot, and other MCP clients
We found that frappe-mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.