npm · abap-adt-mcp
$npx -y abap-adt-mcp@2.7.1 SAP_SYSTEMS_FILE — Path to a JSON file mapping destination names to system configs (url, client, authType basic/sso/sso2/oauth, credentials). Recommended; keep the file mode 0600. See systems.example.json
SAP_SYSTEMS · secret — Inline JSON map of destinations (same shape as SAP_SYSTEMS_FILE). Contains credentials — prefer SAP_SYSTEMS_FILE
SAP_DEFAULT_DESTINATION — Destination name used when a tool call omits `destination` (alternatively mark an entry with "default": true)
SAP_AUTH_TYPE — Default auth type for entries that don't specify one: sso (default), sso2, basic, or oauth
MCP_HTTP_PORT — When set (1024-65535), serve Streamable HTTP on http://127.0.0.1:<port>/mcp with bearer-token auth instead of stdio
MCP_HTTP_HOST — Bind address for the HTTP transport (default 127.0.0.1). Set 0.0.0.0 only inside containers that publish the port
MCP_HTTP_TOKEN · secret — Bearer token for the HTTP transport; auto-generated and written to ~/.abap-adt-mcp/http-token when unset
MCP_HTTP_MAX_SESSIONS — Maximum concurrent MCP sessions on the HTTP transport (default 16); further initialize requests get 503
MCP_HTTP_MAX_BODY_BYTES — Largest request body the HTTP transport accepts, in bytes (default 4194304); larger bodies are refused with HTTP 413
MCP_HTTP_SESSION_TTL_MINUTES — Idle minutes after which an HTTP session (and its SAP sessions/locks) is closed (default 30)
MCP_HTTP_ALLOWED_ORIGINS — Comma-separated Origin values allowed on the HTTP transport (loopback origins always allowed when bound to loopback; * allows any)
MCP_HTTP_ALLOWED_HOSTS — Comma-separated Host header values allowed (DNS-rebinding protection; loopback hosts always allowed when bound to loopback)
MCP_EXPORT_ROOT — When set, exportPackageSources may only write inside this directory
MCP_AUDIT_FILE — Path of a JSONL audit trail: one record per tool call (tool, destination, duration, outcome ok/error/denied/unavailable, policy gate, redacted argument summary)
MCP_READ_ONLY — Set to 1 to make every destination read-only (server-side; only read-only annotated tools plus login/logout run). Per-destination policies live in systems.json
MCP_ALLOW_DATA_PREVIEW — Set to 1 to let tableContents read table and CDS rows on every destination that does not state policy.allowDataPreview itself (reading table data is off by default)
MCP_ALLOW_FREE_SQL — Set to 1 to allow runQuery and tableContents with sqlQuery on every destination that does not state policy.allowFreeSql itself (free SQL is off by default; implies table data)
MCP_TOOLSETS — Toolsets to publish: comma list (core,source,objects,transports,analysis,tests,atc,data,discovery,runtime,refactoring,rap,services,git,debugger,traces) or a preset: all (default) or focused
MCP_DISABLED_TOOLSETS — Toolsets to hide, comma list (core cannot be disabled)
MCP_MAX_RESPONSE_CHARS — Character budget for a single tool response before results are paged/truncated (default 40000, minimum 5000). Raise it if your MCP host accepts larger tool outputs
SAP_ALLOW_REENTRANCE_TICKET — Set to 1 to enable the reentranceTicket tool (disabled by default: it returns a live SAP logon credential into the conversation)
SAP_URL — Legacy single-system mode: base URL of the SAP system, e.g. https://host:44300
SAP_USER — Legacy single-system mode: SAP username
SAP_PASSWORD · secret — Legacy single-system mode: SAP password
SAP_CLIENT — Legacy single-system mode: SAP client number, e.g. 100
SAP_LANGUAGE — Legacy single-system mode: logon language, e.g. EN
SAP_BROWSER_PATH — SSO destinations: path to a Chromium/Chrome/Edge binary for the browser login (auto-detected when unset)
SAP_BROWSER_PROFILE_DIR — SSO destinations: directory of the persistent browser profile that keeps the identity-provider session (default ~/.abap-adt-mcp/sso/<host>)
SAP_SSO2_COMMAND — Legacy single-system sso2 mode: absolute path to the trusted local ticket provider
SAP_SSO2_ARGS — Legacy single-system sso2 mode: JSON array of provider arguments (never put a ticket here)
SAP_SSO2_TIMEOUT_MS — Legacy single-system sso2 mode: provider timeout in milliseconds (default 30000; range 1000-300000)
SAP_TLS_INSECURE — Legacy single-system mode: set to 1 to skip TLS certificate verification for that system only (sandboxes with self-signed certificates)
SAP_OAUTH_TOKEN_URL — Legacy single-system mode with SAP_AUTH_TYPE=oauth: OAuth2 token endpoint (client_credentials)
SAP_OAUTH_CLIENT_ID — Legacy single-system mode with SAP_AUTH_TYPE=oauth: OAuth2 client id
SAP_OAUTH_CLIENT_SECRET · secret — Legacy single-system mode with SAP_AUTH_TYPE=oauth: OAuth2 client secret
SAP_OAUTH_SCOPE — Legacy single-system mode with SAP_AUTH_TYPE=oauth: optional OAuth2 scope
MCP_PROFILE_GATE — Platform gate for toolsets the destination does not expose (debugger, traces, abapGit, ...): enforce (default, refuse before calling SAP), warn (log only) or off
MCP_SOURCE_CACHE_TTL_SECONDS — Lifetime of the per-session source cache used by grepPackage, cdsViewInfo and syntaxCheckCode (default 300; 0 keeps entries until logout)
MCP_CACHE_DIR — Directory for the cached SAP cloudification repository used by apiReleaseState (default ~/.abap-adt-mcp/cache)
MCP_API_CLASSIFICATION_FILES — Extra classification files for apiReleaseState, comma list: a path inside SAP's cloudification repository (partner/objectClassifications_ACME.json) or an https URL