AI & Analytics Legends The knowledge platform for SAP Analytics
Concept card

MCP — Model Context Protocol in SAP (mechanics)

MCP — Model Context Protocol in SAP (mechanics) — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-09-27

What is MCP — Model Context Protocol in SAP (mechanics)?

How MCP physically shows up in an SAP landscape in September 2026: which SAP component plays server, which plays client, how the calling user's identity reaches S/4HANA, and what the stateless 2026-07-28 revision of the spec changes. For the adopt-or-not decision, see C105.

What it is

The Model Context Protocol (MCP) is an open protocol, built on JSON-RPC 2.0, that standardises how an LLM application (the host, with one client per connection) reaches external servers that expose context and capabilities. Anthropic published it in November 2024 and donated it in December 2025 to the Agentic AI Foundation, a directed fund of the Linux Foundation co-founded by Anthropic, Block and OpenAI; the maintainers still steer the specification. The current revision is 2026-07-28. A server offers three primitives — tools (functions the model may execute), resources (URI-addressed context to read) and prompts (reusable templates) — and the client can offer elicitation (asking the user for missing input).

This card covers the mechanics in SAP: which SAP component plays which role, how identity flows, and what to configure. The strategy question — build, buy, or do not expose — lives in C105; the MCP-versus-A2A boundary lives in C132.

What changed in the protocol in 2026

The 2026-07-28 revision is the most disruptive since launch, and anyone who learned MCP from 2025 material must update three reflexes:

Why it matters

  • The 2026-07-28 revision removed the initialize handshake and sessions — code and training material written against 2025 MCP semantics is now outdated.
  • SAP now ships MCP in five distinct shapes (Integration Suite MCP gateway, CAP @cap-js/mcp, ADT MCP Server, remote SAP-operated servers, developer-tooling servers); scoping starts by naming which one you mean.
  • Identity propagation — PrincipalPropagation via Cloud Connector for on-premise, OAuth2SAMLBearerAssertion for Public Cloud — decides whether an MCP integration is auditable under the SAP API Policy.

Key points

  • MCP: open JSON-RPC 2.0 protocol, published by Anthropic in November 2024, governed since December 2025 under the Linux Foundation's Agentic AI Foundation; current spec revision 2026-07-28.
  • Server primitives: tools, resources, prompts; client feature: elicitation. Roots, Sampling and Logging are deprecated since 2026-07-28.
  • 2026-07-28 makes MCP stateless: no initialize handshake, no Mcp-Session-Id; version and capabilities travel in _meta; servers expose server/discover.
  • HTTP authorization: OAuth 2.1, Protected Resource Metadata (RFC 9728) mandatory, audience-bound tokens via RFC 8707, no token passthrough.
  • SAP Integration Suite creates MCP Server artifacts from API artifacts, OpenAPI-described HTTP endpoints or RFC backends, served by the MCP gateway and published via Developer Hub.
  • CAP exposes services with @mcp (@cap-js/mcp / cds-adapter-mcp): describe, query, call tools; read and unbound actions only for now.
  • ADT MCP Server (Eclipse and VS Code, GA Q2 2026) runs locally on port 2236 by default.
  • On-premise S/4HANA: PrincipalPropagation through Cloud Connector; Public Cloud: OAuth2SAMLBearerAssertion. This card = mechanics; strategy = C105; MCP vs A2A = C132.

Terms used on this page

MCP host / client / server
Host = the LLM application; client = the connector the host opens per server; server = the service exposing tools, resources and prompts.
server/discover
RPC every server must implement since 2026-07-28 to advertise supported protocol versions, capabilities and identity, replacing the removed initialize handshake.
MRTR (multi round-trip request)
2026-07-28 pattern: the server answers input_required and the client retries the original request with the requested inputs, instead of server-initiated callbacks.
Protected Resource Metadata
RFC 9728 document an HTTP MCP server must publish so clients can discover which authorization server issues tokens for it.
MCP gateway (SAP Integration Suite)
Runtime layer of Integration Suite that serves MCP Server artifacts as MCP-compatible endpoints, sharing security and traffic policies with the API gateway.
Developer Hub
Integration Suite portal where an MCP Server is published as a product and where an agent subscription generates OAuth client credentials and the redirect URI.
Principal propagation
Forwarding the calling business user's identity to the backend — via Cloud Connector and short-lived X.509 certificates for on-premise ABAP systems.
ADT MCP Server
Local MCP server built into ABAP Development Tools (Eclipse, VS Code) that lets coding agents perform ABAP development tasks; default endpoint localhost:2236/mcp.

Sources

  1. Model Context Protocol — specification changelog, revision 2026-07-28
  2. Model Context Protocol — Authorization (2026-07-28)
  3. MCP blog — MCP joins the Agentic AI Foundation (9 Dec 2025)
  4. SAP Help — SAP Integration Suite: MCP Server (MCP gateway)
  5. SAP Community — Principal Propagation for MCP Servers: Integration Suite to S/4HANA On-Premise (Sep 2026)
  6. CAP documentation — Model Context Protocol Adapter (@cap-js/mcp)
  7. SAP Help — ADT for VS Code: Enabling ADT MCP Server
  8. SAP Community — Public Release of the MCP server for SAP BTP administration (Aug 2026)
  9. SAP API Policy v.4.2026a (PDF)
  10. SAP Community — OAuth for Joule Agents: Step-by-Step Developer Guide (Aug 2026)
  11. Anthropic — Introducing the Model Context Protocol (original announcement, November 2024)
  12. Model Context Protocol — Specification 2026-07-28 (base specification)

Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.

Open in the app →