Claude on SAP through MCP
iteractive.ai builds MCP servers over SAP. MCP, the Model Context Protocol, is the open standard through which Anthropic Claude calls tools, and an MCP server over SAP lets Claude read tables, call BAPIs, query OData services and prepare transactions that a person approves, on SAP ECC 6.0 as well as S/4HANA, on premises or in a private cloud. No S/4HANA migration is needed. The same server pattern connects Claude to Microsoft 365, CRM systems, databases and internal APIs. Our SAP MCP server is published under the MIT licence on GitHub, so your team can inspect every line before it touches your system.
How it is built
Three parts. Claude runs where your data policy allows: Claude Enterprise, Amazon Bedrock in Frankfurt or Google Vertex AI in the EU. The MCP server runs inside your network, next to SAP, and speaks two languages to it: OData for the services SAP already exposes and RFC for tables and BAPIs. Between them sits the control layer: sign-in through the Microsoft or Google accounts people already have, personal data masked before anything leaves the network, and an audit record of every call.
Claude never talks to SAP directly. It asks the MCP server for a tool, the server checks whether that tool is allowed for that user, runs it with a scoped SAP account, writes the audit line and returns the result. If the tool would change data, the server returns a draft and waits for a person to confirm.
Why an MCP server and not a wait for Joule
- SAP Joule for ECC and on-premises systems is tied to moving at least half of your maintenance spend to the cloud. An MCP server over SAP needs no such commitment and leaves a later move to S/4HANA open; it sits beside SAP and reads through interfaces SAP provides for this purpose.
- MCP is an open standard. The server works with Claude first, and with any other MCP client your company adopts later. You are not locked to one model vendor.
- The server covers both OData and RFC/BAPI. Of the SAP MCP servers published on GitHub so far, most stop at OData or at ABAP development tools, and on ECC OData usually means writing custom Z services first. RFC reaches the tables and BAPIs ECC already has.
- No proprietary SAP NetWeaver RFC SDK is required. The RFC side runs through a small Node bridge on an open RFC library, which keeps the install to a Python environment and Node 22.
What Claude can do over SAP in the first week
- Answer questions over any table the scoped SAP account may read: open items per customer, stock per plant, production order status, purchase orders waiting for goods receipt. Claude explains SAP field names to the user; the query stays within the roles of that account.
- Call allowlisted BAPIs: lists and details of materials, customers, vendors, sales and purchase documents, open items for dunning. Each BAPI is named in a list your IT team controls.
- Query OData services on S/4HANA: material master, production orders, purchase orders through the standard API_ services. On ECC the same goes through RFC or your existing Z services.
- Prepare a transaction as a draft: a purchase requisition from a request in plain language, with material, quantity and plant filled in, waiting for a person to confirm. Writes are switched on per BAPI during the pilot, after your IT team has approved each one.
- Match public tenders to what you produce: a connector to the EU tenders database TED reads new notices and Claude compares them with your material master.
The security model, written down
- Read-only by default. Writes exist only for BAPIs on an allowlist and only with an explicit confirmation step by a named person.
- A scoped SAP account per deployment, with the roles the use case needs and nothing more. Named-user propagation from the company directory is on the roadmap.
- An audit line for every call: time in UTC, user, tool, arguments, status, duration and a note. The file is yours and your auditor reads the same lines we do.
- Personal data masked before the model sees it: identification numbers, IBANs and contact details are replaced in the server, not in the prompt.
- The model runs in the EU and your data is not used for training. Where the prompts, files and logs are processed, for how long and by which subprocessor is written down per component before go-live.
- A documented exit: how the server is stopped, the SAP account revoked and the process returned to manual operation.
How a six-week pilot runs
Week one is assessment: which two processes, which tables and BAPIs, which roles, which hosting. Weeks two and three put the MCP server into your network and connect it to Claude with sign-in and audit. Weeks four and five run the two processes with the people who own them, measured against the manual baseline. Week six is the audit review and a go or no-go for the next processes. The pilot has a fixed price; the number is on the table in the first conversation, together with what it covers and what it does not.
The server is open source
The SAP MCP server we deploy is published on GitHub under the MIT licence, with the OData and RFC tools, the BAPI allowlist, the audit log and the Claude Desktop and Claude Code configuration. Your team can run it against a sandbox before we ever talk. Production deployments, the security layer, hosting in your environment and support are what we sell.
Who this is for, and who it is not for
For companies running SAP ECC 6.0, S/4HANA on premises or S/4HANA private cloud, with roughly 200 to 10,000 employees, in Europe or anywhere we can work remotely with your IT team. It is not for a company that wants an agent writing into SAP without a person in the loop, and it is not a certified SAP add-on; it is a layer beside SAP that uses the interfaces SAP provides.
Questions we get asked
Does the server need the SAP NetWeaver RFC SDK?
No. RFC calls go through a Node bridge on an open RFC library, so the install is a Python environment plus Node 22. If your SAP system already has the SAP SDK and PyRFC, the server can use them instead.
Which SAP versions does it work with?
SAP ECC 6.0 and S/4HANA, on premises and private cloud. It has been run against ECC 6.0 and S/4HANA 2025 sandbox systems. For S/4HANA Cloud Public Edition we combine Joule with custom skills on SAP BTP and use the MCP server for cross-system work.
Can Claude change data in SAP?
Only through BAPIs on an allowlist your IT team controls, and only after a named person confirms the draft the server prepared. Everything else is read-only.
Where does the model run and what happens to our data?
Claude runs in Claude Enterprise, on Amazon Bedrock in Frankfurt or on Google Vertex AI in the EU, under your account. Your data is not used for training. Personal data is masked in the server before the model sees it.
How is this different from SAP Joule?
Joule is SAP's assistant inside SAP products and on ECC it comes with a cloud commitment. The MCP server is a vendor-neutral layer beside SAP that works with Claude today and with other MCP clients later, reaches ECC through RFC and OData, and keeps the audit trail in your hands. The two can coexist.
Does it work with ChatGPT or Microsoft Copilot?
MCP is an open standard and the server is not tied to Claude. We implement and support it with Claude; connecting another MCP-capable client is a configuration task on your side.
Can we run it ourselves?
Yes. The code is on GitHub under the MIT licence. What we sell is the production deployment: the security layer, hosting in your environment, the process work with your people and support.
How long does the pilot take and what does it cost?
Six weeks for two processes, at a fixed price that we state in the first conversation together with what it covers. The first conversation is 30 minutes and is free.
Talk to us.
A 30-minute consultation on your scenarios. You will leave with a concrete assessment, whether we work together or not.