Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

ARC-1

NPM · ARC-1 · 2 COMPONENTS · SCANNED SEP 20

MCP server for SAP ABAP systems

0 this week 83 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 90 of 216 dependencies flagged as unhealthy (1 deprecated). View diagnostics → Partial
Provenance & Transparency74
  • Repository check failed: the declared repository URL redirects; it must resolve directly. See how to fix → View diagnostics → Fail
  • Cryptographically verified build provenance (signed, bound to marianfoo/arc-1). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 2 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability56
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 8504 tokens (~1063/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
  • Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the ARC-1 MCP server?

ARC-1 runs locally as an npm package, launched with npx -y arc-1. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · arc-1

# add to Claude Code
claude mcp add marianfoo-arc-1 -- npx -y arc-1
// .cursor/mcp.json
{
  "mcpServers": {
    "marianfoo-arc-1": {
      "command": "npx",
      "args": [
        "-y",
        "arc-1"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "marianfoo-arc-1": {
      "command": "npx",
      "args": [
        "-y",
        "arc-1"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add marianfoo-arc-1 -- npx -y arc-1
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "marianfoo-arc-1": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "arc-1"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add marianfoo-arc-1 --command npx --arg -y --arg arc-1
# ~/.hermes/config.yaml
mcp_servers:
  marianfoo-arc-1:
    command: "npx"
    args: ["-y", "arc-1"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "marianfoo-arc-1": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "arc-1"
      ]
    }
  }
}
# add to Vellum
assistant mcp add marianfoo-arc-1 -t stdio -c npx -a -y arc-1
// mcp.json
{
  "mcpServers": {
    "marianfoo-arc-1": {
      "command": "npx",
      "args": [
        "-y",
        "arc-1"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 20 Sept 26 −3
    • Stability: pass → 0.80 functional
  • 19 Sept 26 0
    • Stability: 0.97 → pass security
  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

  • 12 Sept 26 −3
    • Stability: pass → 0.77 functional
  • 11 Sept 26 0
    • Stability: 0.97 → pass security
  • 10 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed npm/arc-1@0.9.18

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem npm
Reason Verified
Discovered via Registry attestation endpoint
Source repo marianfoo/arc-1
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/marianfoo/arc-1/.github/workflows/release.yml@refs/heads/main
Rekor log index 1839808092
Predicate type https://slsa.dev/provenance/v1
Subject digest sha512:e1b0be5f85d385173fe53fa29155adfce01e12f39a4b829465548ef8074f122f568eb1629736caf9e43edaa602071f9efea9d416dc63b353555d2beb2

Background: How many MCP packages publish verified provenance →

Dependencies 216 packages
Packages resolved 216
Deprecated 1
Stale 87
No linked repository 2
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 8 exposed · ~8,504 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
SAPContext ~1,136

Get compressed dependency context or CDS blast-radius impact for an ABAP / CDS object. Decision rule — pick the action based on the user's question: - "What breaks if I change <CDS view>?" / "Who consumes <I_*>?" / "Impact analysis on <DDLS>" / "Blast radius" → action="impact" - "Understand dependencies before editing <object>" / "What does X depend on?" → action="deps" (default) - "Find all callers of <object>" (cache-warmup required) → action="usages" action="impact" (CDS blast-radius, DDLS only): ALWAYS use this for CDS change-impact questions. Returns upstream AST dependencies plus downstream where-used results classified into RAP-aware buckets: projectionViews, bdefs, serviceDefinitions, serviceBindings, accessControls (DCLS), metadataExtensions (DDLX), abapConsumers, documentation (SKTD), tables, other. Also emits additive sibling-consistency diagnostics (consistencyHints + siblingExtensionAnalysis) when sibling DDLS variants in the same package show asymmetric metadata-extension coverage. DO NOT replicate this with SAPQuery against DDDDLSRC/ACMDCLSRC/DDLXSRC_SRC/SRVDSRC_SRC — those text scans produce noise (non-dependency matches, package group nodes) that this classifier already filters out. Optional includeIndirect=true widens to transitive consumers. Optional siblingCheck=false disables sibling analysis; siblingMaxCandidates controls fan-out (default 4, hard cap 10). action="deps" (default): Returns only the public API contracts (method signatures, interface definitions, type declarations) of all objects that the target depends on — NOT the full source code. The most token-efficient way to understand dependencies. Instead of N separate SAPRead calls returning full source (~200 lines each), returns ONE response with compressed contracts (~15-30 lines each). Typical compression: 7-30x fewer tokens. What deps extracts per dependency: - Classes: CLASS DEFINITION with PUBLIC SECTION only (methods, types, constants). PROTECTED, PRIVATE and IMPLEMENTATION st…

NameTypeReqDescription
actionstringAction: "impact" = CDS blast-radius analysis (DDLS only). USE THIS for any question like "what breaks if I change <view>", "who consumes <I_*>", "impact analysis on <CDS>", "downstream of <view>". Re…
depthnumberDependency depth: 1 = direct deps only (default), 2 = deps of deps, 3 = maximum. Higher depth = more context but more SAP calls.
groupstringRequired for FUNC type. The function group containing the function module.
includeIndirectbooleanOnly for action="impact". Include indirect (transitive) downstream where-used entries. Default false.
maxDepsnumberMaximum dependencies to resolve (default 20). Lower = faster + fewer tokens.
namestringyesObject name (e.g., ZCL_ORDER)
siblingCheckbooleanOnly for action="impact". Enable sibling metadata-extension consistency analysis. Default true.
siblingMaxCandidatesnumberOnly for action="impact". Maximum sibling DDLS candidates to compare. Default 4; hard cap 10.
sourcestringOptional: provide source directly instead of fetching from SAP. Saves one round-trip if you already have the source from SAPRead.
typestringObject type. Required for action="deps" and action="usages". Optional for action="impact" — defaults to DDLS (the only supported type for impact).

No output schema declared.

No examples provided.

SAPDiagnose ~1,226

Run diagnostics on ABAP objects and analyze runtime errors. Actions: - "syntax": Syntax check an ABAP object. Requires name + type. Optional: version ("active" or "inactive", defaults to active). Optional: source — when supplied, SAP compiles the given content as if it lived at the object's URI (pre-write dry-run, nothing is written). Omit source to check what is stored. - "unittest": Run ABAP unit tests. Requires name + type. - "atc": Run ATC code quality checks. Requires name + type. Optional: variant. - "cds_testcases": Get SAP-suggested ABAP Unit test cases for a CDS entity (CDS Test Double Framework). Requires name (the CDS entity / DDLS source name; no type needed). Returns one test-method suggestion per testable semantic (whole view, calculated fields, CAST/JOIN/CASE) to scaffold a cl_cds_test_environment unit test. Read-only; SAP_BASIS 8.16+ (ABAP Platform 2025 / S/4HANA 2025) only. - "object_state": Compare active and inactive source versions. Requires name + type. For CLAS, also compares main, definitions, implementations, macros, and testclasses includes (up to 10 parallel reads per class; sequence calls when sweeping many classes). Returns ETags, byte lengths, hashes, and divergence flags. - "quickfix": Get SAP quick fix proposals for a specific source position. Requires name + type + source + line. Optional: column, sourceUri for exact ADT include/source targets. - "apply_quickfix": Apply one quick fix proposal and return text deltas (does not write source). Requires name + type + source + line + proposalUri + proposalUserContent. Optional: column, sourceUri, proposalAffectedObjects. proposalUserContent may be an empty string; pass it through exactly from quickfix. - "dumps": List or read ABAP short dumps (ST22). Without id: lists recent dumps (filter by user, maxResults). With id: returns focused chapter sections by default; set includeFullText=true to include the full formatted dump blob. Optional sections=[kap0,kap3,...] to request specific chapter…

NameTypeReqDescription
actionstringyesDiagnostic action
analysisstringTrace analysis type (for traces action with id). hitlist = execution hot spots, statements = call tree, dbAccesses = database access stats.
columnnumberSource column number for quickfix evaluation (default 0 for quickfix actions).
detailUrlstringADT detail URL for gateway_errors detail mode (preferred over id+errorType). Accepts absolute or /sap/bc/adt/... path.
errorTypestringGateway error type for gateway_errors detail by id (for example "Frontend Error"). Required when using id without detailUrl.
fromstringOptional lower time boundary for feed-based diagnostics actions (system_messages/gateway_errors).
idstringDump or trace ID (for dumps/traces actions). Omit to list, provide to get details.
includeFullTextbooleanFor dumps detail mode only: include full formattedText blob. Default false to reduce token usage.
linenumberSource line number for quickfix evaluation (required for quickfix/apply_quickfix).
maxResultsnumberMaximum results to return for dumps/system_messages/gateway_errors (default 50, bounded to a safe cap).
namestringObject name (for syntax/unittest/atc/object_state); the CDS entity / DDLS source name for cds_testcases
proposalAffectedObjectsarrayOptional affectedObjects array from quickfix action. Include content for each affected source unit when applying multi-object quickfixes.
proposalUristringQuickfix proposal URI from quickfix action (required for apply_quickfix).
proposalUserContentstringOpaque userContent from quickfix action (required for apply_quickfix). May be an empty string; pass through exactly.
sectionsarrayDump chapter IDs to include for dumps detail mode (for example ["kap0","kap3","kap8"]). Omit to use focused defaults.
sourcestringCurrent source code (required for quickfix/apply_quickfix).
sourceUristringExact ADT source URI for quickfix/apply_quickfix. Defaults to the type/name main source; use this for class includes such as /includes/definitions.
tostringOptional upper time boundary for feed-based diagnostics actions (system_messages/gateway_errors).
typestringObject type (PROG, CLAS, etc.) (for syntax/unittest/atc/object_state)
userstringFilter dumps by SAP user (for dumps action)
variantstringATC check variant (for atc action)
versionstringSource version for syntax check (default "active"). Use "inactive" to validate pending changes.

No output schema declared.

No examples provided.

SAPLint ~405

Run local abaplint rules on ABAP and CDS source code. System-aware: auto-selects cloud or on-prem rules based on detected system type. Actions: - "lint": Check source for issues. Returns errors and warnings. Works for ABAP (PROG, CLAS, INTF, FUNC) and CDS views (DDLS) — catches syntax errors, naming conventions, field order, legacy view patterns. - "lint_and_fix": Lint + auto-fix all fixable issues (keyword case, obsolete statements, etc.). Returns fixed source. - "list_rules": List all available rules with current config. No source needed. - "format": Pretty-print ABAP source via SAP's ADT formatter (uses the SAP system's global formatter settings). Requires source. Returns the formatted source. - "get_formatter_settings": Read the SAP system's global PrettyPrinter settings (indentation, keyword style). No params. - "set_formatter_settings": Update the SAP system's global PrettyPrinter settings. Requires indentation (bool) and/or style (keywordUpper|keywordLower|keywordAuto|none). Blocked in read-only mode. For server-side checks (ATC, syntax check, unit tests), use SAPDiagnose instead. Note: lint/lint_and_fix/list_rules run locally; format/*_formatter_settings call the SAP system.

NameTypeReqDescription
actionstringyesCheck type
indentationbooleanPrettyPrinter: indent source (for set_formatter_settings)
namestringObject name (used for filename detection)
rulesobjectRule overrides: { "rule_name": false } to disable, { "rule_name": { "severity": "Warning" } } to configure. Overrides system defaults.
sourcestringABAP or CDS source code to lint/format (not needed for list_rules/get_formatter_settings)
stylestringPrettyPrinter: keyword casing (for set_formatter_settings)

No output schema declared.

No examples provided.

SAPManage ~930

Probe and report SAP system capabilities. Use this BEFORE attempting operations that depend on optional features (abapGit, RAP/CDS, AMDP, HANA, UI5/Fiori, CTS transports, FLP customization). Also handles package (DEVC) lifecycle operations. Actions: - "features": Get cached feature status from last probe (fast, no SAP round-trip). Returns which features are available, their mode (auto/on/off), and when they were last probed. - "probe": Re-probe the SAP system now (runs feature probes, auth checks, and ADT discovery refresh). Use this on first use or if you suspect feature availability has changed. - "cache_stats": Show object cache health and warmup state. - "flp_list_catalogs": List FLP business catalogs. - "flp_list_groups": List FLP groups. - "flp_list_tiles": List tiles in a catalog (requires "catalogId"). - "create_package": Create a package (DEVC) via ADT packages API. - "delete_package": Delete an existing package. - "flp_create_catalog": Create a business catalog (requires "domainId", "title"). - "flp_create_group": Create a group (requires "groupId", "title"). - "flp_create_tile": Create a tile in a catalog (requires "catalogId", "tile"). - "flp_add_tile_to_group": Add a catalog tile to a group (requires "groupId", "catalogId", "tileInstanceId"). - "flp_delete_catalog": Delete a business catalog (requires "catalogId"). Returns JSON with features, each having: id, available (bool), mode, message, and probedAt timestamp. Also returns systemType ("btp" or "onprem") for understanding available capabilities. "available: false" means do NOT attempt operations that depend on it.

NameTypeReqDescription
actionstringyesAction to execute. Read actions: features, probe, cache_stats, flp_list_catalogs, flp_list_groups, flp_list_tiles. Mutating package/FLP actions require writable safety config and write scope in authe…
catalogIdstringFLP catalog identifier — accepts either full ID (X-SAP-UI2-CATALOGPAGE:MY_CAT) or domain ID (MY_CAT). Required for flp_list_tiles, flp_create_tile, flp_add_tile_to_group, flp_delete_catalog.
descriptionstringPackage description (required for create_package).
domainIdstringDomain ID for FLP catalog creation (e.g., ZARC1_SALES).
groupIdstringFLP group/page identifier (required for flp_create_group, flp_add_tile_to_group).
namestringPackage name (required for create_package and delete_package).
newPackagestringTarget package to move the object to. Required for change_package.
objectNamestringObject name to move (e.g., ZCL_MY_CLASS). Required for change_package.
objectTypestringADT object type (e.g., CLAS/OC, DDLS/DF, PROG/P). Required for change_package.
objectUristringADT URI of the object to move (e.g., /sap/bc/adt/oo/classes/zcl_my_class). If not provided, resolved automatically from objectName + objectType via search.
oldPackagestringCurrent package of the object. Required for change_package.
packageTypestringPackage type for create_package (default: development).
recordChangesbooleanWhether the created package records object changes in transport requests. Defaults to true for non-LOCAL software components or when a transport layer is set; false for literal LOCAL packages.
softwareComponentstringSoftware component for create_package (default: LOCAL).
superPackagestringParent package for create_package (defaults to empty root package).
tileobjectTile definition for flp_create_tile.
tileInstanceIdstringTile instance ID in the source catalog (required for flp_add_tile_to_group).
titlestringTitle for FLP catalog/group creation.
transportstringOptional transport request (corrNr) for create_package, delete_package, or change_package.
transportLayerstringTransport layer for create_package (optional; required by some transportable landscapes).

No output schema declared.

No examples provided.

SAPNavigate ~442

Navigate code: find definitions, references (where-used), code completion, and class hierarchy. Use for "go to definition", "where is this used?", "what does this class inherit?", and auto-complete. For references: uses the full scope-based Where-Used API returning detailed results with line numbers, snippets, and package info. Optional objectType filter narrows results to a specific ADT type in slash format (e.g., CLAS/OC, PROG/P). Type+name params are auto-normalized (e.g., type="clas" works). For hierarchy: returns superclass, implemented interfaces, and direct subclasses via SEOMETAREL. You can use type+name instead of uri (e.g., type="CLAS", name="ZCL_ORDER") for a where-used list without needing the full ADT URI. For CDS entities (DDLS), prefer SAPContext(action="impact") — it returns the same where-used data pre-classified into RAP buckets (projection views, BDEFs, SRVDs, access controls, metadata extensions, documentation, ABAP consumers), which answers "what breaks if I change this view" directly without manual bucketing.

NameTypeReqDescription
actionstringyesNavigation action
columnnumberColumn number (1-based)
linenumberLine number (1-based)
namestringObject name — alternative to uri for references.
objectTypestringFor references action: filter where-used results by ADT object type in slash format (e.g., PROG/P, CLAS/OC, FUGR/FF, INTF/OI). On systems supporting the scope endpoint, only returns references from o…
sourcestringCurrent source code (for definition/completion)
typestringObject type (PROG, CLAS, INTF, FUNC, etc.) — alternative to uri for references.
uristringSource URI of the object. Optional for references if type+name are provided.

No output schema declared.

No examples provided.

SAPRead ~2,524

Read SAP ABAP objects. Types: PROG, CLAS, INTF, FUNC, FUGR (use expand_includes=true to get all include sources), INCL, DDLS, DCLS (CDS access controls), DDLX (CDS metadata extensions — UI annotations), BDEF, SRVD, SRVB (service bindings — returns structured binding info: OData version, publish status, service definition ref), SKTD (Knowledge Transfer Documents — Markdown documentation attached to ABAP objects like CDS views, BDEFs, classes), TABL (DDIC TABL — covers transparent tables like T000 AND DDIC structures like BAPIRET2; returns CDS-like source. ARC-1 auto-resolves the URL: tries /sap/bc/adt/ddic/tables/ first, falls back to /sap/bc/adt/ddic/structures/. Note: there is no separate STRU type — TABL is the canonical short type for both, mirroring TADIR R3TR TABL and abapGit conventions), VIEW, DOMA (DDIC domains — returns type info, value table, fixed values), DTEL (data elements — returns domain, labels, search help), TRAN (transaction codes — returns description, program, package), TABLE_CONTENTS (simple row preview — no filter or single-column filter; use TABLE_QUERY for multi-column WHERE), TABLE_QUERY (structured multi-column query on DDIC tables and CDS views via the freestyle endpoint — supports AND conditions, column selection; gated by allowDataPreview; use instead of TABLE_CONTENTS when filtering on multiple fields. Note: CDS views require SAP_BASIS 752+ — NW 7.50/7.51 rejects them with "TABLE is invalid here"), DEVC, SOBJ (BOR business objects — returns method catalog or full implementation), SYSTEM, COMPONENTS, MSAG (message classes — returns class metadata + messages array), TEXT_ELEMENTS, VARIANTS. For CLAS: omit include to get the full class source (definition + implementation combined). The include param is optional — use it only to read class-local sections: definitions (local types), implementations (local helper classes), macros, testclasses (ABAP Unit). For CLAS with method param: use method="*" to list all methods with signatures and vis…

NameTypeReqDescription
actionstringSet to "diff" for a unified diff between two source versions (uses from/to) — cheaper than fetching both sources. Source types only: PROG, CLAS, INTF, FUNC, FUGR, INCL, DDLS, DCLS, BDEF, SRVD, DDLX,…
columnsarrayFor TABLE_QUERY: columns to SELECT (default: all). Example: ["MATNR","BWART","BUDAT","MENGE"].
expand_includesbooleanFor FUGR type only. When true, recursively expands the function group include tree — the main source plus all nested INCLUDEs (the FUNCTION...ENDFUNCTION bodies live in nested LZ<grp>U01/U02 includes…
force_refreshbooleanFor source reads: bypass cached source and inactive-list state before reading. Use when you know the object changed outside ARC-1.
formatstringOutput format. "text" (default): raw source code. "structured" (CLAS only): JSON with metadata (description, language, category) + decomposed source (main, testclasses, definitions, implementations,…
fromstringaction="diff" OLD side: "active" (default), "inactive", a revision id from SAPRead(type="VERSIONS"), or a /sap/bc/adt/ revision URI.
grepstringRegex pattern (case-insensitive) to search within the object source. Returns only matching lines with 1-based line numbers and ±3 context lines, instead of the full source — token-efficient. For CLAS…
groupstringFor FUNC/VERSIONS type. The function group containing the function module. Optional for FUNC — auto-resolved via SAPSearch if omitted. Required for VERSIONS when querying a function module revision f…
includestringFor CLAS: DO NOT use this to read the main class — omit include entirely to get the full class source (CLASS DEFINITION + CLASS IMPLEMENTATION). This parameter reads class-LOCAL auxiliary files only:…
includeSignaturebooleanFor FUNC type only. When true, response is JSON: {source, signature: {importing[], exporting[], changing[], tables[], exceptions[], raising[]}} — each parameter parsed into {kind, name, type, byValue…
maxResultsnumberFor DEVC: max number of objects to list (default 200, clamped to [1, 1000]). Larger packages may be silently truncated by SAP at this limit; raise it if needed.
maxRowsnumberFor TABLE_CONTENTS and TABLE_QUERY: max rows to return (default 100)
methodstringFor CLAS: method name to read a single method implementation (e.g., "get_name", "zif_order~process"). Use "*" to list all methods with signatures and visibility. For SOBJ: BOR method name to read. If…
namestringObject name (e.g., ZTEST_PROGRAM, ZCL_ORDER, MARA)
objectTypestringFor API_STATE and VERSIONS: SAP object type (CLAS, INTF, PROG, FUNC, INCL, DDLS, DCLS, BDEF, SRVD, etc.). For API_STATE: auto-detected from name if omitted. For VERSIONS: required to pick the correct…
sqlFilterstringFor TABLE_CONTENTS: condition expression only (no WHERE, no SELECT), e.g. "MANDT = '100'" or "MATNR LIKE 'Z%'".
tostringaction="diff" NEW side (default "inactive" = pending unactivated changes). Same values as from.
typestringyesObject type to read (on-prem): PROG, CLAS, INTF, FUNC, FUGR, INCL, DDLS, DCLS, DDLX, BDEF, SRVD, SRVB, SKTD, TABL (transparent tables and DDIC structures), VIEW, DOMA, DTEL, MSAG, TRAN, TABLE_CONTENT…
versionstringSource version to read. "active" (default) returns the last activated version. "inactive" returns the user's unactivated draft or active if no draft exists. "auto" returns the draft if one exists, el…
versionUristringFor VERSION_SOURCE: URI of a specific revision from SAPRead(type="VERSIONS") response (.revisions[].uri). Must start with /sap/bc/adt/.
wherearrayFor TABLE_QUERY: structured WHERE conditions, ANDed together. Each item: {field, op, value?}. Allowed ops: =, !=, <>, <, <=, >, >=, LIKE, NOT LIKE, IN, NOT IN, IS NULL, IS NOT NULL. For IN/NOT IN: va…

No output schema declared.

No examples provided.

SAPSearch ~527

Search for ABAP objects. Search by name pattern with wildcards (* for any characters). Returns object type, name, package, description, and ADT URI. Use this to find classes, programs, function modules, tables, etc. 2. TADIR lookup (searchType="tadir_lookup"): Exact cross-package object lookup for one or more names via ADT repository quick search. Use this before create/reset workflows instead of long SAPQuery TADIR IN-lists. Tips: BOR business objects appear as SOBJ type in results. The uri field from results can be used directly with SAPNavigate for references. The objectType field from results can be passed directly to SAPRead/SAPWrite/SAPActivate (ARC-1 auto-normalizes slash suffixes like DDLS/DF, CLAS/OC, PROG/P). Note: Searches object names only (classes, tables, CDS views, etc.) — field/column names are not searchable here. To find fields by name, use SAPRead(type='DDLS', include='elements') for CDS views or SAPQuery against DD03L.

NameTypeReqDescription
maxResultsnumberMaximum results (default 100)
namesarrayFor tadir_lookup: exact object names to resolve across packages. Prefer this over long SAPQuery TADIR IN-lists.
objectTypestringFor source_code search: filter by object type (e.g., PROG, CLAS, FUNC). For tadir_lookup: single type filter; use objectTypes for multiple.
objectTypesarrayFor tadir_lookup: optional ADT/TADIR type filters (e.g., TABL, DDLS, BDEF, SRVB, CLAS/OC).
querystringSearch pattern for object search, or comma/whitespace-separated names for tadir_lookup.
searchTypestringSearch mode: "object" (default) searches by object name, "tadir_lookup" does exact cross-package object lookup.
sourcestringFor tadir_lookup only: data source for the lookup. "adt" (default) uses the ADT info-system endpoint — workbench-resolvable objects only. "db" issues SQL against table TADIR — also surfaces orphan/gh…

No output schema declared.

No examples provided.

SAPTransport ~1,314

Manage CTS transport requests (SE09/SE10 equivalent). Actions: list (defaults to current user, modifiable transports — both Workbench and Customizing), get (details with tasks and objects), create (K=Workbench, W=Customizing, T=Transport of Copies), release, delete, remove_object (remove an object, keep the request), reassign (change owner), release_recursive (release tasks first, then parent), check (check if a package requires a transport — provide type, name, package), history (find transports referencing an object — provide type, name; read-only, works without SAP_ALLOW_TRANSPORT_WRITES). Transport IDs look like A4HK900123. Status: D=modifiable, R=released.

NameTypeReqDescription
actionstringyeslist: show transports (defaults to current user, modifiable only). Pass summary=true for a headers-only overview that omits each transport's object lists (keeps an objectCount) — far cheaper when man…
descriptionstringTransport description text (required for create)
idstringTransport request ID, e.g. A4HK900123 (required for get/release/delete/reassign/release_recursive/remove_object)
namestringObject name (for check, history, or remove_object actions)
ownerstringNew owner SAP username (required for reassign)
packagestringPackage name. For create: optional — defaults to $TMP, pass an explicit package to influence the transport route (SAP infers K/W/T from the package's TADIR route). For check: required.
pgmidstringProgram ID for remove_object: "R3TR" (whole object) or "LIMU" (sub-object). Required — object type alone does not determine pgmid.
recursivebooleanApply recursively to child tasks (for delete/reassign). release_recursive always recurses.
removeLockedObjectsbooleanFor delete only. Strip locked objects from each task before deleting, so a request that still holds a locked object (e.g. a deleted object's lingering record → HTTP 400 "...contains locked objects")…
statusstringTransport status filter (for list). D=modifiable (default), R=released, "*"=all statuses.
summarybooleanFor list only. Headers-only overview: omit each transport's (and task's) object lists, keeping id/description/owner/status/target plus an objectCount. Use it to scan many open transports cheaply, the…
targetstringExplicit transport target (Transportziel / TR_TARGET) for create — what the user means by "create a transport with target X". Forms: a system ("C11"), system.client ("C11.021"), or target group ("/TR…
transportLayerstringTransport layer for create (optional, advanced). Sent as the ?transportLayer= query param to override which consolidation route — and therefore which target — SAP resolves. OMIT IT by default: SAP re…
typestringObject type for check/history/remove_object actions (PROG, CLAS, DDLS, etc.). Not used by create — the SAP backend infers transport type (K/W/T) from the package's TADIR route on the CreateCorrection…
userstringSAP username to filter by (for list). Defaults to the current SAP user. Use "*" to list all users.

No output schema declared.

No examples provided.

Common questions

What is the ARC-1 MCP server?

ARC-1 is an MCP server listed in the public MCP registry as io.github.marianfoo/arc-1. MCP server for SAP ABAP systems. This page covers its npm package (arc-1).

Is the ARC-1 MCP server safe to use?

ARC-1 scores 83 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the ARC-1 MCP server expose?

ARC-1 exposes 8 tools: SAPRead, SAPSearch, SAPNavigate, SAPLint, SAPDiagnose, and 3 more. Their descriptions and schemas cost roughly 8,504 tokens of context every time the server is loaded.

Is the ARC-1 MCP server still maintained?

ARC-1 is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the ARC-1 MCP server under?

ARC-1 declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.