BuildNot yet confirmed elsewhere1 publisher3 min readPublished
SAP's ABAP MCP Server exposes RFC execution to outside agents through one bearer-token endpoint
SAP's ABAP MCP Server, generally available after Sapphire 2026, lets Claude, Copilot or Amazon Q execute RFCs on S/4 through one /mcp endpoint. Each agent needs its own bearer token, a dev.to practitioner guide says, so S/4 teams have to decide what every token may call.
The Engineer · Build desk

What happened
- Beyond RFCs, the server's tools read table data, activate transport requests, run ABAP Unit tests and check syntax, each with a JSON input and output schema.
- The server applies the same tool permissions and audit trails to every MCP client, whichever agent product is on the other end.
- VS Code ADT is RAP-first and trails Eclipse ADT on function modules and classic reports, though both IDEs can point at the same MCP server.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Agent roles have to be fixed before tokens are issued, because uneven grants such as transport_activate for Claude but not Copilot produce inconsistent behavior.
- constraint Shops heavy in procedural ABAP stay on Eclipse ADT for agent work until VS Code coverage of function modules and classic reports catches up.
- cost Every extra agent adds load that the basis team has to monitor, since concurrent resource requests can raise ADT server response times.
The best available account of the server is a practitioner's guide on dev.to [1]. On that account, a call works like this. The agent opens an HTTP/S connection to /mcp, presents a bearer token, and invokes one of a fixed set of tools [4]. Each tool has a JSON input and output schema [3]. The guide says every action passes through those predefined tools and their specific authorizations, so the agent never gets an open session on the system [6]. Generated code is still compiled and executed on the AS ABAP, and the server runs beside ADT without replacing it [15]. The guide does not quote SAP documentation, so its tool descriptions are one team's reading of the release.
Transports are where the guide disagrees with itself. Its tool list includes activating transport requests [3]. Further down, it says agents can suggest or prepare transports but that activation still goes through standard channels [17]. Then it warns about granting Claude the transport_activate tool while restricting Copilot [11]. A tool cannot be both available and out of reach in the same deployment. Before any token gets transport_activate, someone should call it on a sandbox and check whether a transport actually moves.
The permission boundary is the token. According to the guide, the server treats every MCP client the same and enforces identical tool permissions and audit trails whichever agent connects [10]. Each agent gets its own bearer token, and the guide says to treat those like service accounts: rotate them and scope them to the minimum [12]. I think this is the right design. An RFC-capable bearer token is a service account that happens to take instructions from a language model, and S/4 basis teams already have processes for governing service accounts. The guide's author wrote, "You'll spend more time defining what agents can do than worrying about which agent is doing it." [16]
IDE choice depends on the codebase. Eclipse ADT has full MCP tool coverage for classic objects, with limited but growing support for CDS views and AMDP methods [7]. VS Code ADT is RAP-first, and its support for function modules and classic reports trails Eclipse [8]. Both IDEs can run against the same MCP server [9]. A team that mostly maintains procedural ABAP keeps Eclipse for this work.
The guide's subtitle promises to keep adoption within an AI Units budget [14]. Its text does not include unit prices or say which tool calls consume units. The operating cost it does describe is load. Several agents sending resource requests at once can push up response times, and the guide tells teams to watch ADT server logs for MCP-related latency [13]. Agents use the read-only resources, such as table structures and CDS view definitions, to gather context before generating code [5]. Agents that pull a lot of context are the ones to look for in those logs.
What to watch
- SAP's own documentation for the transport activation tool, stating whether an agent can activate a transport or only prepare one.
- Published AI Units metering for MCP tool and resource calls, so per-agent cost can be estimated.
- VS Code ADT closing its gap on function modules and classic reports.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence30
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
SAP's ABAP MCP Server is generally available after Sapphire 2026, according to a practitioner's guide published on dev.to.
- [2]
The ABAP MCP Server lets external agents such as Claude, Copilot and Amazon Q interact with an S/4 system through the Model Context Protocol.
- [3]
The server's tools are standardized function calls for reading table data, executing RFCs, activating transport requests, running ABAP Unit tests and checking syntax, each with a defined JSON input/output schema.
- [4]
The server runs over HTTP/S with bearer token authentication and exposes a single endpoint (/mcp) that agents connect to.
- [5]
MCP resources give read-only access to system metadata such as table structures, data element documentation and CDS view definitions, useful for agents that need context before generating code.
- [6]
The MCP server does not give agents unrestricted access; every action goes through the predefined tools with their specific authorizations.
- [7]
Eclipse ADT has full MCP tool coverage for classic ABAP objects (programs, function modules, classes, interfaces, data elements, tables, views) and limited but growing support for CDS views and AMDP methods.
- [8]
VS Code ADT takes a RAP-first approach, and its coverage of classical objects is incomplete: function modules and classic reports lag behind Eclipse.
- [9]
Teams can run both Eclipse ADT and VS Code ADT against the same MCP server.
- [10]
The server treats all MCP clients equally, enforcing the same tool permissions and audit trails regardless of the client.
- [11]
Granting Claude access to the transport_activate tool while restricting Copilot produces inconsistent behavior; the guide says to define agent roles upfront.
- [12]
Each agent needs its own bearer token; the guide says to treat these like service accounts, rotate them regularly and scope them to the minimum required permissions.
- [13]
Multiple agents hammering the MCP server with resource requests can spike response times; the guide advises monitoring ADT server logs for MCP-related latency.
- [14]
The guide is pitched as explaining how to wire agentic ABAP development into an S/4 program without blowing the AI Units budget.
- [15]
The MCP server runs alongside existing ADT (Eclipse or VS Code), and agents still generate code that is compiled and executed on the AS ABAP.
- [16]
"You'll spend more time defining what agents can do than worrying about which agent is doing it."
- [17]
Agents can suggest or prepare transports, but you still need to activate them through standard channels.
ReportedContestedSource: dev.to practitioner guide2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toThe ABAP MCP Server Is Live — What SAP's Agentic IDE Bet Means for Your S/4 Program
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- AI in enterprise ERPFollow
- Agentic Software DevelopmentFollow
- Model Context ProtocolFollow
Entities
- SAPFollow
- ABAP MCP ServerFollow
- Model Context ProtocolFollow
- ABAPFollow
- SAP S/4HANAFollow
- ABAP Development ToolsFollow
- ClaudeFollow
- GitHub CopilotFollow
- Amazon QFollow
- SAP SapphireFollow