<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Projects on Marian Zeis Blog</title>
    <link>https://blog.zeis.de/categories/projects/</link>
    <description>Recent content in Projects on Marian Zeis Blog</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 12 Aug 2026 03:00:00 +0200</lastBuildDate>
    <atom:link href="https://blog.zeis.de/categories/projects/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Testing Joule Work Desktop with Microsoft 365, Local Files, and SAP</title>
      <link>https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/</link>
      <pubDate>Wed, 12 Aug 2026 03:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/</guid>
      <description>&lt;p&gt;You have probably seen Joule Work Desktop on LinkedIn by now. &lt;a href=&#34;https://www.linkedin.com/posts/sebastian-steinhaeuser_prepare-me-for-my-meeting-with-thats-ugcPost-7490314981784154112-QCE4/&#34;&gt;Sebastian Steinhaeuser&lt;/a&gt; showed how it prepares him for a customer meeting. &lt;a href=&#34;https://www.linkedin.com/posts/philipp-herzig_im-excited-to-present-the-new-sap-gui-ugcPost-7488584210123837440-TuTW/&#34;&gt;Philipp Herzig&lt;/a&gt; called it the new SAP GUI, with a smile, and demonstrated a workflow across email, a spreadsheet, a Space, and PowerPoint.&lt;/p&gt;&#xA;&lt;p&gt;Joule Work Desktop is now available to SAP employees after a test with more than 6,000 colleagues. Selected customers can also use it through the Early Adopter Care program on macOS and Windows.&lt;/p&gt;&#xA;&lt;p&gt;The idea is simple: one desktop application that can combine local files, Microsoft 365, SAP knowledge, business systems, MCP connectors, and skills. That is much more interesting than another small Joule chat window inside one SAP application.&lt;/p&gt;&#xA;&lt;p&gt;I already built similar setups with &lt;a href=&#34;https://blog.zeis.de/posts/2026-02-16-librechat-enterprise-gpt/&#34;&gt;LibreChat&lt;/a&gt; and &lt;a href=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/&#34;&gt;Microsoft Copilot Studio&lt;/a&gt;. A native application adds direct access to the files and applications people use every day.&lt;/p&gt;&#xA;&lt;p&gt;Luckily, I was one of the few people who got access to the application and could test the currently available features. So here is my first hands-on experience with what I am allowed to show.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Joule Work Desktop with Conversations, the composer, and the available work sources.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/joule-work-desktop-overview.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;If you prefer to see the complete flow first, here is the &lt;a href=&#34;joule-work-desktop-demo.mp4&#34;&gt;58-second demo video&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The application starts with Conversations. I can add files and select work sources or an external connector from the composer. Tool calls remain visible, and generated files open in their normal desktop application.&lt;/p&gt;&#xA;&lt;h2 id=&#34;email-and-calendar-integration&#34;&gt;Email and calendar integration&lt;/h2&gt;&#xA;&lt;p&gt;I asked the application to prepare me for a meeting. It found the calendar entry, read related email messages, and created a brief with logistics, open points, risks, and questions. The calendar and email steps remained visible, and the answer included source references. For me, this is more useful than a general inbox summary because the message becomes the start of a task.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Meeting brief created from Work Calendar and Work Email, including open commitments, risks, questions, and source references.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/meeting-preparation.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;local-files-onedrive-and-real-documents&#34;&gt;Local files, OneDrive, and real documents&lt;/h2&gt;&#xA;&lt;p&gt;I can attach Office documents, structured data, text, and images. Files synchronized through OneDrive are also available, so they can be combined with email, calendar, web research, or an external connector.&lt;/p&gt;&#xA;&lt;p&gt;For the meeting-preparation example, I attached an existing Word template. The application filled the relevant sections and created a new document instead of giving me text to copy manually.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;The generated meeting brief opened as a normal Microsoft Word document.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/generated-meeting-brief-word.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The files still need review, but reviewing a prepared document is often faster than starting with an empty one.&lt;/p&gt;&#xA;&lt;h2 id=&#34;spaces-are-more-useful-than-i-expected&#34;&gt;Spaces are more useful than I expected&lt;/h2&gt;&#xA;&lt;p&gt;SAP calls the generated work areas Spaces. They are persistent views that can be reopened without finding the original conversation. The most useful one in my test was a transport backlog based on data from my SAP system. It shows open and empty transports, their owners, and the biggest requests by object count.&lt;/p&gt;&#xA;&lt;p&gt;This does not replace a proper application or reporting solution. But not every temporary question needs a new Fiori application, and a Space is more useful than a long chat answer.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Transport backlog Space with live metrics from A4H client 001, an owner breakdown, and the biggest transports by object count.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/transport-backlog-space.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;connecting-the-sap-system&#34;&gt;Connecting the SAP system&lt;/h2&gt;&#xA;&lt;p&gt;The SAP system integration is what can make Joule Work Desktop more than a general desktop agent.&lt;/p&gt;&#xA;&lt;p&gt;At the moment, the direct SAP business system integration available to me is for SAP S/4HANA Cloud Public Edition. I do not have such a system. My test system is SAP S/4HANA 2023 on-premise.&lt;/p&gt;&#xA;&lt;p&gt;I therefore added &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt;, my open-source ADT MCP server. ARC-1 can run locally or as a remote MCP server with OAuth, for example on SAP BTP Cloud Foundry.&lt;/p&gt;&#xA;&lt;p&gt;I could then read transports, inspect ABAP objects, analyze custom code, check ATC findings, or compare a specification with what actually exists in the system.&lt;/p&gt;&#xA;&lt;p&gt;The connector still needs valid authentication, and SAP user authorizations still apply. I would start with a development system and read-only access.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;ARC-1 selected in the composer with a completed read from A4H client 001 and the returned transport request IDs.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/arc-1-sap-access.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;connectors-and-one-click-skills&#34;&gt;Connectors and one-click skills&lt;/h2&gt;&#xA;&lt;p&gt;Joule Work Desktop supports MCP connectors and skills, so SAP does not have to build every integration and workflow itself. The &lt;a href=&#34;https://skills.cloud.sap/&#34;&gt;SAP AI Skills Library&lt;/a&gt; contains reusable skills that can be imported into Joule Work Desktop with one click.&lt;/p&gt;&#xA;&lt;p&gt;The skill page shows the repository, license, trust level, and checks before installation. The SAP Fiori Guidelines skill, for example, can be added through the &lt;strong&gt;Add to Joule Work Desktop&lt;/strong&gt; button.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;SAP Fiori Guidelines in the SAP AI Skills Library with the Add to Joule Work Desktop button.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/sap-ai-skills-library.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;MCP servers provide tools, while skills describe how the agent should use them and what it should verify. This keeps the application extendable without adding every possible SAP feature to the desktop client.&lt;/p&gt;&#xA;&lt;p&gt;The open questions are broader SAP system support, connector governance, and pricing. Anything about future announcements or TechEd is still only speculation.&lt;/p&gt;&#xA;&lt;h2 id=&#34;something-is-strange&#34;&gt;Something is strange&lt;/h2&gt;&#xA;&lt;p&gt;Anyone who already works with Joule Work Desktop may have noticed something by now.&lt;/p&gt;&#xA;&lt;p&gt;Some details in my video and screenshots do not look exactly like the application SAP installed. The interface is very close, the workflows work, and the features are there, but a few things are just slightly different.&lt;/p&gt;&#xA;&lt;p&gt;There is a simple reason for that.&lt;/p&gt;&#xA;&lt;p&gt;I do not have access to Joule Work Desktop.&lt;/p&gt;&#xA;&lt;p&gt;The screenshots and video in this post do not show an SAP application. They show an application I built myself.&lt;/p&gt;&#xA;&lt;p&gt;After watching the public demos, I wanted to see how difficult it would be to rebuild the same core idea with open-source components. I spent roughly a day or two vibe coding it with Codex. The result is called &lt;a href=&#34;https://getwerkbank.com/&#34;&gt;&lt;strong&gt;Werkbank&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Werkbank is the German word for workbench, a place where different tools come together to get work done.&lt;/p&gt;&#xA;&lt;p&gt;The current interface follows the public Joule Work Desktop videos closely because I wanted to reproduce the workflows shown there. But there is no internal SAP code behind it, I had no access to a Joule Work Desktop build, and I have no additional product information beyond public posts and videos.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-is-actually-inside-werkbank&#34;&gt;What is actually inside Werkbank&lt;/h2&gt;&#xA;&lt;p&gt;Werkbank is a working MVP, not a static mock or a prerecorded animation. It can hold real streaming conversations, call tools, ask for permissions, and stop a running task. The agent behind it is &lt;a href=&#34;https://github.com/aaif-goose/goose&#34;&gt;goose&lt;/a&gt;, an open-source AI agent hosted by the Agentic AI Foundation. Werkbank communicates with Goose through the Agent Client Protocol.&lt;/p&gt;&#xA;&lt;p&gt;The implemented features currently include:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Local active and archived conversations.&lt;/li&gt;&#xA;&lt;li&gt;Word, PowerPoint, text, CSV, JSON, and image attachments, including files synchronized through OneDrive.&lt;/li&gt;&#xA;&lt;li&gt;Generated Word and PowerPoint files that can be opened in the normal desktop application.&lt;/li&gt;&#xA;&lt;li&gt;Persistent Spaces stored as sandboxed HTML views.&lt;/li&gt;&#xA;&lt;li&gt;Live read-only Microsoft 365 email and calendar access.&lt;/li&gt;&#xA;&lt;li&gt;Session-scoped MCP connectors, remote MCP OAuth through Goose, and reusable skills selected with &lt;code&gt;/&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The demo uses these features rather than special video fixtures. The meeting brief comes from live calendar and email calls, the Word output is a real file, ARC-1 reads my SAP system, and the transport Space is generated from those results. The shipment-defect workflow uses an attached synthetic CSV file and creates a real Space and PowerPoint presentation.&lt;/p&gt;&#xA;&lt;p&gt;For SAP, Werkbank uses the same MCP servers I can use from Claude Desktop, Codex, VS Code, LibreChat, or Copilot Studio. ARC-1 connects to the ABAP system. Connector secrets are stored through the operating system&amp;rsquo;s secure storage instead of being written into the normal configuration.&lt;/p&gt;&#xA;&lt;p&gt;The project website is &lt;a href=&#34;https://getwerkbank.com/&#34;&gt;getwerkbank.com&lt;/a&gt;, and the source is in the public &lt;a href=&#34;https://github.com/marianfoo/werkbank&#34;&gt;Werkbank repository&lt;/a&gt;. Development currently targets macOS, and there is no signed installer yet.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;The live Werkbank website with the product overview and link to the App Store.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/werkbank-website.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-werkbank-app-store&#34;&gt;The Werkbank App Store&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://getwerkbank.com/#store&#34;&gt;getwerkbank.com&lt;/a&gt; is not only a landing page. Its App Store already works with the desktop application, and I can use it to add both &lt;a href=&#34;https://getwerkbank.com/#store&#34;&gt;MCP servers&lt;/a&gt; and &lt;a href=&#34;https://getwerkbank.com/#store&#34;&gt;skills&lt;/a&gt; to Werkbank.&lt;/p&gt;&#xA;&lt;p&gt;The small curated catalog currently contains nine entries: three MCP servers and six SAP development skills. I can search it, filter by type, inspect the original source, and then click &lt;strong&gt;Add to Werkbank&lt;/strong&gt; or &lt;strong&gt;Add skill&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Werkbank App Store for MCP servers and SAP skills.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/werkbank-app-store.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The website validates the request and opens the local application through a &lt;code&gt;werkbank://&lt;/code&gt; link. Werkbank then shows the connector command and configuration fields, or the skill repository and name. Nothing is installed until I confirm it inside the desktop application. After that, a connector is restarted and becomes available to the conversation, while an installed skill appears in the &lt;code&gt;/&lt;/code&gt; picker.&lt;/p&gt;&#xA;&lt;p&gt;The same flow can be linked from any project README with an &lt;strong&gt;Add to Werkbank&lt;/strong&gt; button. Here is the skill used in the video:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://getwerkbank.com/install-skill/?repository=https%3A%2F%2Fgithub.com%2FSAP%2Fai-skills-library&amp;amp;name=sap-fiori-guidelines&amp;amp;title=SAP+Fiori+Guidelines&#34;&gt;Add the SAP Fiori Guidelines skill to Werkbank&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Werkbank showing the repository, skill name, and source before confirming installation of the SAP Fiori Guidelines skill.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-08-11-joule-work-desktop/images/skill-install-confirmation.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;To try it, clone the repository, run &lt;code&gt;npm install&lt;/code&gt;, copy &lt;code&gt;.env.example&lt;/code&gt; to &lt;code&gt;.env&lt;/code&gt;, add the model configuration, and start it with &lt;code&gt;npm run dev&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-this-little-experiment-shows&#34;&gt;What this little experiment shows&lt;/h2&gt;&#xA;&lt;p&gt;Werkbank is not a replacement for Joule Work Desktop. It is a small MVP built in roughly two days, with bugs and much narrower workflows. But it is already a usable desktop application: I can chat with it, attach files, connect tools, install skills, and return to earlier conversations and Spaces.&lt;/p&gt;&#xA;&lt;p&gt;SAP also has to solve the difficult enterprise parts: identity, authorizations, data protection, auditing, deployment, updates, model governance, and reliable operation for many users and systems. A local MVP does not solve these problems just because the demo looks similar. With more time, I could add SSO, authentication against IAS, a release pipeline with signed builds, automatic updates, and more enterprise controls. That was not the main point of this experiment.&lt;/p&gt;&#xA;&lt;p&gt;But the experiment still shows something useful. The core workflows SAP currently demonstrates are already possible with open-source components:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Read email and calendar context.&lt;/li&gt;&#xA;&lt;li&gt;Work with local files and OneDrive-synchronized files.&lt;/li&gt;&#xA;&lt;li&gt;Analyze structured data.&lt;/li&gt;&#xA;&lt;li&gt;Create persistent dashboards.&lt;/li&gt;&#xA;&lt;li&gt;Generate real Word and PowerPoint files.&lt;/li&gt;&#xA;&lt;li&gt;Connect SAP documentation and SAP systems through MCP.&lt;/li&gt;&#xA;&lt;li&gt;Add reusable skills and new connectors.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Goose is only one possible base. LibreChat can provide a similar experience in the browser. Microsoft Copilot Studio can combine Microsoft 365 connectors and MCP servers. Claude Desktop can also work with local files, connectors, and skills. The individual building blocks already exist.&lt;/p&gt;&#xA;&lt;p&gt;The real value of Joule Work Desktop will therefore not come only from having these features. It will come from how well SAP connects them to business context, SAP authorizations, supported applications, and real processes. It will also depend on how accessible it is. Are Signavio, LeanIX, or SAP S/4HANA Cloud Public Edition required? Can a customer use it with only on-premise systems? And what will it cost?&lt;/p&gt;&#xA;&lt;p&gt;For now, I am impressed by the direction. I just could not test the real application yet, so I built the part I wanted to test myself.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Disclosure:&lt;/strong&gt; Werkbank is an independent open-source project and is not affiliated with or endorsed by SAP. SAP, Joule, ABAP, SAP Fiori, SAP S/4HANA, and other SAP products and services mentioned herein are trademarks or registered trademarks of SAP SE or its affiliates in Germany and other countries.&lt;/p&gt;&#xA;&lt;h2 id=&#34;references-and-links&#34;&gt;References and links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.sap.com/products/artificial-intelligence/joule-work.html&#34;&gt;Joule Work product page&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://news.sap.com/2026/05/sap-sapphire-keynote-business-ai-platform-power-autonomous-enterprise/&#34;&gt;SAP Sapphire 2026 announcement&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/posts/philipp-herzig_im-excited-to-present-the-new-sap-gui-ugcPost-7488584210123837440-TuTW/&#34;&gt;Philipp Herzig&amp;rsquo;s Joule Work Desktop post&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/posts/sebastian-steinhaeuser_prepare-me-for-my-meeting-with-thats-ugcPost-7490314981784154112-QCE4/&#34;&gt;Sebastian Steinhaeuser&amp;rsquo;s meeting-preparation post&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/pulse/sap-developer-news-july-16th-2026-thomas-jung-socjf/&#34;&gt;SAP Developer News: importing skills into Joule Work Desktop&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://skills.cloud.sap/&#34;&gt;SAP AI Skills Library&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://getwerkbank.com/&#34;&gt;Werkbank website and App Store&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/werkbank&#34;&gt;Werkbank source repository&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/aaif-goose/goose&#34;&gt;goose&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>Introducing open-rfc: Calling SAP RFC from Node.js Without the SDK</title>
      <link>https://blog.zeis.de/posts/2026-08-10-open-rfc/</link>
      <pubDate>Mon, 10 Aug 2026 09:30:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-08-10-open-rfc/</guid>
      <description>&lt;p&gt;If you ever wanted to call a remote-enabled ABAP function module from JavaScript or Node.js, you probably discovered quite quickly that this is not as easy as it sounds.&lt;/p&gt;&#xA;&lt;p&gt;There is an RFC protocol. There are remote-enabled function modules. There is an npm package called &lt;a href=&#34;https://github.com/SAP-archive/node-rfc&#34;&gt;&lt;code&gt;node-rfc&lt;/code&gt;&lt;/a&gt;. So you would expect to install the package, add the connection details, and make the call.&lt;/p&gt;&#xA;&lt;p&gt;But &lt;code&gt;npm install node-rfc&lt;/code&gt; was never the complete setup.&lt;/p&gt;&#xA;&lt;p&gt;You also need the SAP NetWeaver RFC SDK. You need the right authorization to download it from the SAP Support Portal, the correct build for your operating system and architecture, and the current supported patch level. The native libraries must be installed where the runtime can find them. On Linux that usually means configuring &lt;code&gt;SAPNWRFC_HOME&lt;/code&gt; and the library search path. If no suitable prebuilt addon exists, you also need the C++ build toolchain, Python, &lt;code&gt;node-gyp&lt;/code&gt;, and headers to compile the Node.js addon.&lt;/p&gt;&#xA;&lt;p&gt;Then this has to work again in Docker, CI/CD, Cloud Foundry, Kyma, or wherever the application is deployed. The SDK cannot simply be bundled into a public npm package because SAP is its distribution channel. Even SAP&amp;rsquo;s own &lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/abap-rfc-connectivity-from-btp-node-js-buildpack-and-kyma/ba-p/13573993&#34;&gt;BTP and Kyma example&lt;/a&gt; has to copy the SDK into the buildpack application, rebuild the native module, and configure the library path for runtime.&lt;/p&gt;&#xA;&lt;p&gt;This is all possible. Many projects have done it successfully for years. But it is quite a lot of setup for what starts as: I only want to call one function module.&lt;/p&gt;&#xA;&lt;h2 id=&#34;a-short-history-of-rfc-outside-abap&#34;&gt;A short history of RFC outside ABAP&lt;/h2&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://support.sap.com/en/product/connectors/nwrfcsdk.html&#34;&gt;SAP NetWeaver RFC SDK&lt;/a&gt; is the native C and C++ foundation for RFC clients and servers. Projects such as &lt;a href=&#34;https://github.com/SAP-archive/PyRFC&#34;&gt;PyRFC&lt;/a&gt; and &lt;a href=&#34;https://github.com/SAP-archive/node-rfc&#34;&gt;&lt;code&gt;node-rfc&lt;/code&gt;&lt;/a&gt; made it usable from Python and Node.js, but both remained language bindings around this separately installed SDK.&lt;/p&gt;&#xA;&lt;p&gt;These projects were valuable and gave both ecosystems practical APIs. Their shared problem was the native dependency, followed by the end of maintenance. The last &lt;code&gt;node-rfc&lt;/code&gt; release was published in November 2023, followed by PyRFC 3.3.1 in January 2024. In July 2024 SAP published the same announcement for &lt;a href=&#34;https://github.com/SAP-archive/node-rfc/issues/329&#34;&gt;&lt;code&gt;node-rfc&lt;/code&gt;&lt;/a&gt; and &lt;a href=&#34;https://github.com/SAP-archive/PyRFC/issues/372&#34;&gt;PyRFC&lt;/a&gt;: changed priorities meant it could no longer maintain the projects. The bindings used an SDK patch no longer supported by SAP, with no planned update. After ownership could not be transferred to new maintainers, as explained in the final updates for &lt;a href=&#34;https://github.com/SAP-archive/node-rfc/issues/329#issuecomment-2541486229&#34;&gt;&lt;code&gt;node-rfc&lt;/code&gt;&lt;/a&gt; and &lt;a href=&#34;https://github.com/SAP-archive/PyRFC/issues/372#issuecomment-2541490558&#34;&gt;PyRFC&lt;/a&gt;, both repositories were eventually archived on May 28, 2026. The &lt;code&gt;node-rfc&lt;/code&gt; package on npm is deprecated too.&lt;/p&gt;&#xA;&lt;p&gt;There are forks, but they keep the same basic architecture. You still need the native SDK, platform-specific binaries, and somebody able to follow SDK changes.&lt;/p&gt;&#xA;&lt;p&gt;There is also a newer SAP path for CAP. The public &lt;a href=&#34;https://www.npmjs.com/package/@sap/cds-rfc&#34;&gt;&lt;code&gt;@sap/cds-rfc&lt;/code&gt;&lt;/a&gt; plugin uses &lt;code&gt;@sap-rfc/node-rfc-library&lt;/code&gt; for low-level RFC communication. That connector is not available on the standard npm registry. According to the plugin documentation, it is available only for Linux and Windows, and SAP customers need an S-user, an SAP Build Code license, and credentials for SAP&amp;rsquo;s Repository-Based Shipment Channel. macOS users have to use a container.&lt;/p&gt;&#xA;&lt;p&gt;So the old open-source binding is archived, while the newer supported connector adds an entitlement, a private registry, and platform-specific deployment requirements. I would expect an easier answer from SAP for such a fundamental integration protocol.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-conversation-that-started-open-rfc&#34;&gt;The conversation that started open-rfc&lt;/h2&gt;&#xA;&lt;p&gt;For a long time I was not very concerned about this. Most of my RFC contact is inside ABAP, not outside it. When I had a small Node.js use case, the setup was complicated enough that I simply did not continue. With AI it may be a bit easier to fight through native build errors and deployment files, but the underlying dependencies are still there.&lt;/p&gt;&#xA;&lt;p&gt;Then the topic came up during the evening events at &lt;a href=&#34;https://code-connect.dev/&#34;&gt;Code Connect 2026&lt;/a&gt;. Even SAP employees were annoyed by the current situation. The discussion was more or less: this should be rewritten without those dependencies, and in the world of AI it cannot be that hard.&lt;/p&gt;&#xA;&lt;p&gt;I started an AI coding session the same night.&lt;/p&gt;&#xA;&lt;p&gt;Spoiler: even with AI, it is hard.&lt;/p&gt;&#xA;&lt;p&gt;I have been working on it since that evening, with AI helping across research, implementation, tests, and review. The deeper I went, the clearer it became that writing something that works once is not the hard part. The hard part is proving that it behaves correctly across SAP releases and also in failures.&lt;/p&gt;&#xA;&lt;p&gt;Once you go deeper into RFC, a much larger world opens up. The client first has to log on, understand the function module and its parameters, translate JavaScript values into ABAP values, send and receive sometimes large structures and tables, and keep the connection in a safe state when something fails. Timeouts are especially tricky: the application may not know whether SAP already executed the call. Retrying a write automatically could therefore execute it twice.&lt;/p&gt;&#xA;&lt;p&gt;The good news is that RFC is documented better than I first expected. I used the official &lt;a href=&#34;https://support.sap.com/content/dam/support/en_us/library/ssp/products/connectors/nwrfcsdk/NW_RFC_750_ProgrammingGuide.pdf&#34;&gt;SAP NW RFC SDK 7.50 Programming Guide&lt;/a&gt;, the current SDK Doxygen documentation, the ABAP Keyword Documentation for the &lt;a href=&#34;https://help.sap.com/doc/abapdocu_latest_index_htm/latest/en-US/ABENRFC_PROTOCOL.html&#34;&gt;RFC protocol&lt;/a&gt;, interfaces, restrictions, and session context, plus SAP&amp;rsquo;s Network Interface documentation and relevant SAP Notes. The archived &lt;code&gt;node-rfc&lt;/code&gt; and PyRFC APIs and tests are also important compatibility references.&lt;/p&gt;&#xA;&lt;p&gt;I also used &lt;a href=&#34;https://github.com/OWASP/pysap&#34;&gt;OWASP pysap&lt;/a&gt; and its &lt;a href=&#34;https://pysap.readthedocs.io/en/latest/&#34;&gt;documentation&lt;/a&gt; as a low-level reference for SAP network protocols. pysap, initially designed and developed by Martin Gallo, is a Python and Scapy packet-crafting and protocol-research toolkit, while open-rfc is an application-facing Node.js RFC client. Thank you to Martin and all pysap contributors for making this research available.&lt;/p&gt;&#xA;&lt;p&gt;Most importantly, I do not only test against mocks. Because of &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt;, I already have three ABAP trial systems for SAP NetWeaver 7.50, SAP S/4HANA 2023, and SAP S/4HANA 2025. Development tests run against all three. The formal first-beta support contract is intentionally smaller and qualifies NetWeaver 7.50 and S/4HANA 2023 with the exact packaged artifact.&lt;/p&gt;&#xA;&lt;p&gt;I keep offline protocol, property, fault, resource, and compatibility tests separate from live SAP evidence. The supported &lt;code&gt;node-rfc&lt;/code&gt; facade is exercised against a pinned corpus from the archived project. For a beta release, the same exact tarball must pass as a standalone dependency, as the &lt;code&gt;node-rfc&lt;/code&gt; npm alias, and below unchanged &lt;code&gt;@sap/cds-rfc&lt;/code&gt;. A green test from some earlier source checkout does not promote a different package.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-the-first-beta-includes&#34;&gt;What the first beta includes&lt;/h2&gt;&#xA;&lt;p&gt;The result is &lt;a href=&#34;https://github.com/marianfoo/open-rfc&#34;&gt;open-rfc&lt;/a&gt;, an SDK-free TypeScript and JavaScript RFC client for Node.js. The current beta is &lt;a href=&#34;https://www.npmjs.com/package/open-rfc&#34;&gt;open-rfc on npm&lt;/a&gt;, licensed under Apache 2.0.&lt;/p&gt;&#xA;&lt;p&gt;The installed package has zero runtime dependencies. It contains portable JavaScript and TypeScript declarations, with no native addon, no SAP NW RFC SDK, no post-install download, and no runtime framework. It supports ESM and CommonJS and the same package is used in three ways:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;directly through the &lt;code&gt;open-rfc&lt;/code&gt; API;&lt;/li&gt;&#xA;&lt;li&gt;as an npm alias for existing &lt;code&gt;node-rfc&lt;/code&gt; client and pool consumers; and&lt;/li&gt;&#xA;&lt;li&gt;as the low-level connector below an unchanged &lt;code&gt;@sap/cds-rfc&lt;/code&gt; installation.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The first beta focuses on direct application-server connections with password authentication and classic Unicode RFC. It includes metadata lookup and caching, synchronous function calls, common scalar values, exact decimals, date and time values, binary data, STRING and XSTRING, structures, tables, timeouts, cancellation, reset, bounded connection pooling, and representative commit and rollback paths.&lt;/p&gt;&#xA;&lt;p&gt;It also includes &lt;code&gt;Client&lt;/code&gt; and &lt;code&gt;Pool&lt;/code&gt; facades for the common archived &lt;code&gt;node-rfc&lt;/code&gt; API and the modern &lt;code&gt;RFCClient&lt;/code&gt; and &lt;code&gt;RFCConnection&lt;/code&gt; facade expected by SAP&amp;rsquo;s CAP connector. Unsupported security or serializer options fail before business I/O. A timeout, cancellation, malformed response, or uncertain send retires the physical connection, and open-rfc never automatically replays the call.&lt;/p&gt;&#xA;&lt;p&gt;The official 0.2.3 release matrix currently qualifies Ubuntu 24.04 x64 with Node.js 22.14 or newer, or Node.js 24. Because the package is portable JavaScript with no native addon, it is expected to work on other Node.js platforms too. macOS, Windows, and other Linux versions are not official release claims yet, so I especially want users to report what they try there.&lt;/p&gt;&#xA;&lt;p&gt;The 0.x line has no production SLA. Direct classic RFC also has no transport encryption or peer authentication by itself. It belongs on a trusted private network or inside a separately managed protected tunnel, not openly across the internet.&lt;/p&gt;&#xA;&lt;h2 id=&#34;btp-cloud-connector-and-an-arc-1-extension&#34;&gt;BTP, Cloud Connector, and an ARC-1 extension&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;open-rfc&lt;/code&gt; 0.2.3 also makes it possible to call an on-premise SAP system from BTP Cloud Foundry through SAP Cloud Connector. The &lt;a href=&#34;https://marianfoo.github.io/open-rfc/routes/&#34;&gt;documented route&lt;/a&gt; uses the BTP Connectivity service and Cloud Connector to reach the SAP system. I tested the exact published package end to end from Cloud Foundry to SAP S/4HANA 2023. This proves the path works, but it has not yet been tested broadly enough to be part of the release&amp;rsquo;s qualified scope.&lt;/p&gt;&#xA;&lt;p&gt;I added the same setup to the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-extension-sample&#34;&gt;ARC-1 extension sample&lt;/a&gt;. Its &lt;code&gt;Custom_RfcSystemInfo&lt;/code&gt; tool calls the read-only &lt;code&gt;RFC_SYSTEM_INFO&lt;/code&gt; function, accepts no user input, is off by default, uses a dedicated RFC user, and only returns selected fields. It shows how an ARC-1 extension can add an RFC tool beside ADT and OData without installing the SDK.&lt;/p&gt;&#xA;&lt;p&gt;My tested setup uses a dedicated technical SAP user. Cloud Connector protects the connection between BTP and the company network. Inside the company network, RFC still needs a trusted network, and the technical user should only be allowed to call the exact function modules needed.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-beta-does-not-mean-almost-10&#34;&gt;Why beta does not mean almost 1.0&lt;/h2&gt;&#xA;&lt;p&gt;This first beta is not a release candidate for 1.0. RFC has too many paths for that claim.&lt;/p&gt;&#xA;&lt;p&gt;The default target for 1.0 is intentionally smaller: direct application-server RFC with password authentication, the standalone API, the &lt;code&gt;node-rfc&lt;/code&gt; compatibility layer, and unchanged &lt;code&gt;@sap/cds-rfc&lt;/code&gt; through the npm override. Before 1.0, this still needs deeper testing of failures, isolation, large values, transactions, pool contention, repeated runs, and long-running use. It also needs a frozen API and support policy, real adopters, operational readiness, and another independent security and correctness review.&lt;/p&gt;&#xA;&lt;p&gt;Message-server load balancing, SAProuter, WebSocket RFC, and passing individual user identities through Cloud Connector are conditional candidates. They enter 1.0 only if the scope decision includes them and live tests can prove them. Otherwise they remain later work.&lt;/p&gt;&#xA;&lt;p&gt;Other features are later work, not promises for 1.0: registered RFC server mode and ABAP callbacks, tRFC, qRFC, bgRFC, Throughput APIs, SNC, X.509, non-Unicode and MDMP systems, basXML, and complete SAP NW RFC SDK parity.&lt;/p&gt;&#xA;&lt;p&gt;I prefer to make this boundary explicit. A package that accepts every option and silently ignores half of them looks compatible until the day it causes a production problem.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-cap-replacement-i-wanted-from-the-beginning&#34;&gt;The CAP replacement I wanted from the beginning&lt;/h2&gt;&#xA;&lt;p&gt;One especially important goal was a drop-in replacement for &lt;code&gt;@sap-rfc/node-rfc-library&lt;/code&gt; below SAP&amp;rsquo;s &lt;code&gt;@sap/cds-rfc&lt;/code&gt; CAP plugin. I do not want to fork or rebuild the CAP layer. SAP&amp;rsquo;s unchanged package should continue to own RFC imports, destination lookup, Cloud SDK integration, multitenancy, and the CAP lifecycle. open-rfc should replace only the low-level connector.&lt;/p&gt;&#xA;&lt;p&gt;With npm 11, the application can declare a nested override:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-json&#34; data-lang=&#34;json&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nt&#34;&gt;&amp;#34;dependencies&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nt&#34;&gt;&amp;#34;@sap/cds-rfc&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;2.2.1&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nt&#34;&gt;&amp;#34;open-rfc&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;0.2.3&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;},&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nt&#34;&gt;&amp;#34;overrides&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nt&#34;&gt;&amp;#34;@sap/cds-rfc&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;      &lt;span class=&#34;nt&#34;&gt;&amp;#34;@sap-rfc/node-rfc-library&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;$open-rfc&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Your CAP service code stays unchanged. The normal &lt;code&gt;cds import --from rfc&lt;/code&gt; flow stays with &lt;code&gt;@sap/cds-rfc&lt;/code&gt;, and existing &lt;code&gt;cds.connect.to()&lt;/code&gt; calls still go through the SAP plugin. After installation, &lt;code&gt;npm explain @sap-rfc/node-rfc-library&lt;/code&gt; shows whether the override resolved to open-rfc.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://marianfoo.github.io/open-rfc/cap/&#34;&gt;dedicated CAP guide&lt;/a&gt; explains the full setup, importer boundary, local credentials, destination boundary, transactions, and shutdown behavior. This should make local development and CI/CD much simpler because the application installs an ordinary npm artifact. There is no SDK archive to copy, no native addon to compile, and no extra SAP npm registry credential for this connector.&lt;/p&gt;&#xA;&lt;p&gt;The qualified beta scope still covers only the direct application-server route with password authentication. An easier installation does not magically qualify every destination and authentication mode, so please read the &lt;a href=&#34;https://marianfoo.github.io/open-rfc/status/&#34;&gt;release status&lt;/a&gt; for the exact version you install.&lt;/p&gt;&#xA;&lt;h2 id=&#34;i-need-your-help&#34;&gt;I need your help&lt;/h2&gt;&#xA;&lt;p&gt;Now comes the most important part. I can build a lot and I am willing to put in the work, but I cannot reproduce every SAP system, function module, network route, value shape, and deployment environment alone.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://marianfoo.github.io/open-rfc/&#34;&gt;documentation&lt;/a&gt; is also part of the project, not a finished manual that users can only consume. It already covers the quick start, standalone and &lt;code&gt;node-rfc&lt;/code&gt; use, CAP, Cloud Connector, configuration, safety, operations, troubleshooting, release status, and the road to 1.0. The sources live in the public &lt;a href=&#34;https://github.com/marianfoo/open-rfc/tree/main/docs_page&#34;&gt;&lt;code&gt;docs_page&lt;/code&gt; folder&lt;/a&gt;. If something is unclear, wrong for your environment, or missing a useful example, please open an issue or improve the page. A clearer explanation or a correction from a real setup can be as valuable as a code change.&lt;/p&gt;&#xA;&lt;p&gt;The public repository now also contains a broad offline test suite, and its documentation links and examples are checked automatically. The &lt;a href=&#34;https://github.com/marianfoo/open-rfc/blob/main/CONTRIBUTING.md&#34;&gt;contribution guide&lt;/a&gt; explains how to prepare code and documentation changes safely.&lt;/p&gt;&#xA;&lt;p&gt;Please test the beta with your real use cases, starting with a read-only function on a non-production system. Try the data types your application really uses. Test errors, cancellation, pools, and transactions, not only one successful &lt;code&gt;RFC_PING&lt;/code&gt;. If you find a problem, open an issue with the open-rfc version, Node.js version, operating system, SAP release family, route type, function interface shape, and the smallest safe reproducer you can create.&lt;/p&gt;&#xA;&lt;p&gt;Do not attach credentials, endpoints, system identities, business data, returned tables, raw traces, or packet captures to a public issue. If the problem needs private information, first describe the redacted shape so we can find a safe way to reproduce it.&lt;/p&gt;&#xA;&lt;p&gt;If you prefer to throw tokens at the problem, do that as well. The repository ships a prompt written for exactly this situation: &lt;a href=&#34;https://github.com/marianfoo/open-rfc/blob/main/.claude/commands/report-rfc-failure.md&#34;&gt;report an RFC failure&lt;/a&gt;. You do not need a checkout of the repository to use it. It has an agent first check whether your case is inside the documented boundary, then reduce the failure to a synthetic reproducer that keeps the real ABAP types and invents everything else, and finally fill in every field of the bug template. The redaction rules are part of the prompt, so an agent following it will not put your system identities, credentials, or business data into a public issue.&lt;/p&gt;&#xA;&lt;p&gt;If you want to go further than reporting, the &lt;a href=&#34;https://github.com/marianfoo/open-rfc/blob/main/.claude/commands/deep-bug.md&#34;&gt;deep bug workflow&lt;/a&gt; picks up from there: root cause before any change, then a test that was seen to fail without the fix, then a focused pull request. External contributors will not have my private live-system evidence, so give the agent only a synthetic reproducer and public information. I can run the necessary SAP checks after the issue is reduced safely.&lt;/p&gt;&#xA;&lt;p&gt;And of course, contributions are welcome. This project should not become one person&amp;rsquo;s private RFC implementation with a public repository around it. I want it to become truly open, understandable, testable, and useful for different scenarios.&lt;/p&gt;&#xA;&lt;p&gt;That takes more work. I am ready to do it, but I need your systems, your use cases, your bug reports, and your review.&lt;/p&gt;&#xA;&lt;p&gt;Let&amp;rsquo;s make this work.&lt;/p&gt;&#xA;&lt;h2 id=&#34;references-and-links&#34;&gt;References and links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/open-rfc&#34;&gt;open-rfc repository&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://marianfoo.github.io/open-rfc/&#34;&gt;open-rfc documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://marianfoo.github.io/open-rfc/cap/&#34;&gt;open-rfc CAP integration guide&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://marianfoo.github.io/open-rfc/status/&#34;&gt;open-rfc release status&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/open-rfc/blob/main/CONTRIBUTING.md&#34;&gt;open-rfc contribution guide&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://marianfoo.github.io/open-rfc/roadmap/&#34;&gt;open-rfc road to 1.0&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/open-rfc/releases/tag/v0.2.3&#34;&gt;open-rfc 0.2.3 release&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-extension-sample&#34;&gt;ARC-1 extension sample&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://support.sap.com/en/product/connectors/nwrfcsdk.html&#34;&gt;SAP NetWeaver RFC SDK&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://support.sap.com/content/dam/support/en_us/library/ssp/products/connectors/nwrfcsdk/NW_RFC_750_ProgrammingGuide.pdf&#34;&gt;SAP NW RFC SDK 7.50 Programming Guide&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP-archive/node-rfc&#34;&gt;Archived SAP node-rfc project&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP-archive/node-rfc/issues/329&#34;&gt;node-rfc maintenance announcement&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP-archive/PyRFC&#34;&gt;Archived SAP PyRFC project&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP-archive/PyRFC/issues/372&#34;&gt;PyRFC maintenance announcement&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/OWASP/pysap&#34;&gt;OWASP pysap&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.npmjs.com/package/@sap/cds-rfc&#34;&gt;SAP CAP RFC plugin&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://code-connect.dev/&#34;&gt;Code Connect 2026&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>ARC-1 1.0: One Deployment, Multiple SAP Systems</title>
      <link>https://blog.zeis.de/posts/2026-08-03-arc-1-update/</link>
      <pubDate>Mon, 03 Aug 2026 07:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-08-03-arc-1-update/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1/releases/tag/v1.0.0&#34;&gt;ARC-1 1.0 is here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;When I published the &lt;a href=&#34;https://blog.zeis.de/posts/2026-04-27-arc-1/&#34;&gt;first ARC-1 post&lt;/a&gt;, I explained why I built an MCP server for ABAP development and why security has to be part of it from the beginning. This post is not another deep dive into every tool. The &lt;a href=&#34;https://docs.arc-1-mcp.com/release-notes/&#34;&gt;release notes&lt;/a&gt; already do that.&lt;/p&gt;&#xA;&lt;p&gt;For version 1.0 I want to focus on what really changed: ARC-1 became more stable, it can serve multiple SAP systems from one BTP deployment, the BTP and security setup is much better documented, and the project is no longer only one repository.&lt;/p&gt;&#xA;&lt;p&gt;Most of this happened because people used ARC-1, asked difficult questions, reported problems, opened issues and pull requests, sent me private messages, and invited me to Teams meetings about their plans and experiences. That is the most important part of this release.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-version-10-means&#34;&gt;What version 1.0 means&lt;/h2&gt;&#xA;&lt;p&gt;Version 1.0 does not mean ARC-1 is finished. It means there is now a stable base.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 now has a clearer scope. It is a controlled connection between AI assistants and ABAP systems. It can run locally for one developer or centrally on SAP BTP for a team. It supports classic on-premise ABAP, S/4HANA, BTP ABAP Environment, and S/4HANA Cloud Public Edition.&lt;/p&gt;&#xA;&lt;p&gt;It stays read-only by default. Changing code, reading business data, running SQL, changing transports, or using Git has to be enabled separately. This makes it possible to start small and only allow more when a team is ready.&lt;/p&gt;&#xA;&lt;p&gt;The new multi-system mode is still marked as experimental because parts of the setup and behavior may change. But it can already be used and is running in productive BTP environments, not only in my own setup.&lt;/p&gt;&#xA;&lt;p&gt;That is what 1.0 means to me: not that every possible ADT feature exists, but that the foundation, operating model, and safety boundaries are clear enough to build on.&lt;/p&gt;&#xA;&lt;h2 id=&#34;this-release-was-built-through-feedback&#34;&gt;This release was built through feedback&lt;/h2&gt;&#xA;&lt;p&gt;The first versions were mostly based on my own systems and workflows. That changed quickly. SAP systems, releases, login setups, networks, and transport processes are too different to understand from one landscape.&lt;/p&gt;&#xA;&lt;p&gt;Public issues and pull requests brought real system shapes into the project. A few examples:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/97&#34;&gt;Wouter Lemaire added the first BTP Cloud Foundry deployment&lt;/a&gt;, followed it with &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/107&#34;&gt;deployment and write fixes&lt;/a&gt;, and continued to give very practical guidance on BTP, destinations, and how a shared ARC-1 service should be operated.&lt;/li&gt;&#xA;&lt;li&gt;Sami Bouguerra contributed &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/170&#34;&gt;NetWeaver 7.50 probe fixtures and cookie handling&lt;/a&gt;, then fixed cases where activation looked successful although SAP had not activated the object in &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/179&#34;&gt;PR #179&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;Clément Ringot made BTP login more reliable across deployments in &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/212&#34;&gt;PR #212&lt;/a&gt; and &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/267&#34;&gt;PR #267&lt;/a&gt;, and fixed Cloud Connector response handling in &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/440&#34;&gt;PR #440&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/524&#34;&gt;Geert-Jan Klaps added S/4HANA Public Cloud support&lt;/a&gt;. I do not have access to such a system myself, so his contribution made it possible to add and verify this landscape in ARC-1.&lt;/li&gt;&#xA;&lt;li&gt;Community pull requests added table queries, newer package creation, safer transport handling, better BTP login, configurable server names, and cookie rotation. You can find them in the repository&amp;rsquo;s &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pulls?q=is%3Apr+is%3Amerged&#34;&gt;pull requests&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Not every useful contribution was code. Issues such as &lt;a href=&#34;https://github.com/arc-mcp/arc-1/issues/531&#34;&gt;multi-system connections&lt;/a&gt; and &lt;a href=&#34;https://github.com/arc-mcp/arc-1/issues/377&#34;&gt;how to structure several systems on BTP&lt;/a&gt; changed the architecture and documentation. Reports from older systems improved release detection and fallbacks. Questions from Basis and security people forced me to make assumptions explicit instead of hiding them in configuration examples.&lt;/p&gt;&#xA;&lt;p&gt;I also received many private messages and joined Teams meetings about ARC-1. Some people explained how their teams want to deploy it on BTP and walked me through their real landscape and requirements. Others pointed out security issues, unclear documentation, or places where the safety boundaries were not strong enough. These conversations directly improved login, error handling, audit information, package restrictions, user identity, and the deployment guides.&lt;/p&gt;&#xA;&lt;p&gt;Thank you especially to everyone who reported a security concern privately. That is exactly how an open-source security process should work. ARC-1 now has a public &lt;a href=&#34;https://github.com/arc-mcp/arc-1/blob/main/SECURITY.md&#34;&gt;security policy&lt;/a&gt;, private vulnerability reporting, automated checks for code and dependencies, container checks, and an inventory of the software included in each release.&lt;/p&gt;&#xA;&lt;h2 id=&#34;one-arc-1-instance-multiple-sap-systems&#34;&gt;One ARC-1 instance, multiple SAP systems&lt;/h2&gt;&#xA;&lt;p&gt;The biggest addition in version 1.0 is the experimental &lt;a href=&#34;https://docs.arc-1-mcp.com/multi-target-setup/&#34;&gt;multi-system mode&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;You can now deploy one ARC-1 application on SAP BTP Cloud Foundry and attach several SAP systems or clients through destinations in the same subaccount. An administrator chooses which destinations belong to ARC-1. It does not connect to every destination by accident.&lt;/p&gt;&#xA;&lt;p&gt;This is already used in productive BTP environments. Experimental in this case means that configuration and behavior can still change as more landscapes use it. It does not mean that the feature is only a local proof of concept or that people cannot use it today.&lt;/p&gt;&#xA;&lt;p&gt;Each system and client gets its own MCP address. There is also an optional combined connection for tasks that really need several systems. A system-specific address is the safer choice for normal work because the conversation is already connected to the correct target.&lt;/p&gt;&#xA;&lt;p&gt;Keeping the real user identity is the recommended setup. A user logs in on BTP and the identity is forwarded to SAP. SAP then checks the same authorizations the person already has. A shared technical user is possible for special cases, but it gives less clear responsibility and needs more care.&lt;/p&gt;&#xA;&lt;p&gt;This feature started with community requests and Wouter&amp;rsquo;s &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/543&#34;&gt;first multi-backend implementation&lt;/a&gt;. His code and BTP experience gave the final design important groundwork. The production-focused design, security review, tests, and administrator documentation then landed in &lt;a href=&#34;https://github.com/arc-mcp/arc-1/pull/579&#34;&gt;PR #579&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-biggest-changes-in-short&#34;&gt;The biggest changes in short&lt;/h2&gt;&#xA;&lt;p&gt;I do not want to explain every feature here. These are the areas that matter most for 1.0:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Safer operation:&lt;/strong&gt; ARC-1 starts read-only. Higher-risk actions are separate choices, SAP still decides what the user may do, and teams get limits and audit information for shared use.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;More SAP compatibility:&lt;/strong&gt; testing and fixes now cover older NetWeaver systems, several S/4HANA releases, ABAP Platform 2025, BTP ABAP Environment, and S/4HANA Cloud Public Edition.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Better BTP guidance:&lt;/strong&gt; the &lt;a href=&#34;https://docs.arc-1-mcp.com/btp-overview/&#34;&gt;BTP overview&lt;/a&gt;, &lt;a href=&#34;https://docs.arc-1-mcp.com/btp-cloud-foundry-deployment/&#34;&gt;Cloud Foundry guide&lt;/a&gt;, &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;user identity guide&lt;/a&gt;, updates, rollback, destinations, roles, and multi-system operation are now documented as one path.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Reusable workflows:&lt;/strong&gt; 22 included skills cover RAP, tests, migrations, Clean Core analysis, transport reviews, system documentation, and more.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;More checks before a release:&lt;/strong&gt; ARC-1 runs automated tests against the code and real SAP systems, checks dependencies and containers, and publishes information about what is included in a release.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the exact technical list, including fixes for transport state, ABAP object types, BTP token exchange, tracing, and protocol compatibility, use the &lt;a href=&#34;https://docs.arc-1-mcp.com/release-notes/&#34;&gt;release notes&lt;/a&gt; and the &lt;a href=&#34;https://github.com/arc-mcp/arc-1/releases/tag/v1.0.0&#34;&gt;GitHub v1.0.0 release&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;skills-for-complete-sap-tasks&#34;&gt;Skills for complete SAP tasks&lt;/h2&gt;&#xA;&lt;p&gt;ARC-1 1.0 includes 22 skills. A skill is a reusable workflow for an AI assistant. It gives the assistant a tested way to approach a larger task instead of relying on one large prompt.&lt;/p&gt;&#xA;&lt;p&gt;The included skills cover creating RAP services and logic, ABAP and CDS tests, analytical models and queries, explaining and documenting existing code, finding slow SQL, Clean Core and S/4HANA migration work, unused-code checks, transport overviews and reviews, and modernizing legacy UI5 applications. There are also helpers to understand a system first, create a local ABAP mirror, and review an AI session. The &lt;a href=&#34;https://docs.arc-1-mcp.com/skills/&#34;&gt;full skills catalog&lt;/a&gt; has the complete list and installation options for Claude Code, GitHub Copilot, Cursor, Codex, and other assistants.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/arc-mcp/arc-1/tree/main/skills/migrate-segw-to-rap&#34;&gt;SEGW-to-RAP skill&lt;/a&gt; deserves a special mention. It reads an existing SEGW OData V2 service, including its model and custom code, and guides the move to a modern RAP V4 service. My &lt;a href=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/&#34;&gt;SEGW-to-RAP post&lt;/a&gt; got one of the biggest responses of the whole ARC-1 series. That was a clear signal that many teams are not only interested in creating something new. They also need practical help to modernize the large amount of existing SAP applications.&lt;/p&gt;&#xA;&lt;h2 id=&#34;extensions-for-your-own-sap-apis&#34;&gt;Extensions for your own SAP APIs&lt;/h2&gt;&#xA;&lt;p&gt;ARC-1 will never include every custom API or company-specific endpoint. Forking the complete server for one internal tool is also difficult to maintain.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://docs.arc-1-mcp.com/extensions/&#34;&gt;extension framework&lt;/a&gt; gives you another option. It lets you add your own tools and reuse the SAP connection, safety checks, and audit path of the ARC-1 instance. This can be useful for an internal service or any API that is not part of the standard ARC-1 tools.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/arc-mcp/arc-1-extension-sample&#34;&gt;extension sample&lt;/a&gt; shows a simple configuration option and a code option. It also shows the safety limits. An extension cannot give itself more access than the ARC-1 instance already has, and changes still need to be enabled explicitly. Code extensions run inside ARC-1, so they should be reviewed like any other dependency.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/ClementRingot/LISA&#34;&gt;LISA&lt;/a&gt; is already a useful real example. It provides SAP translation tools as a standalone MCP server and as an ARC-1 extension. This proves both paths can work: build a separate focused service, or attach the capability to an existing ARC-1 deployment.&lt;/p&gt;&#xA;&lt;h2 id=&#34;reusing-the-btp-authentication-stack&#34;&gt;Reusing the BTP authentication stack&lt;/h2&gt;&#xA;&lt;p&gt;Login and keeping the correct SAP user were some of the hardest parts of ARC-1. Other SAP MCP servers need the same foundations, so this code is now available as the separate &lt;a href=&#34;https://www.npmjs.com/package/@arc-mcp/xsuaa-auth&#34;&gt;@arc-mcp/xsuaa-auth&lt;/a&gt; package.&lt;/p&gt;&#xA;&lt;p&gt;It provides the core pieces for deploying an MCP server to SAP BTP Cloud Foundry: login through XSUAA, reuse of BTP destinations, connections through Cloud Connector, and forwarding the real user to SAP. A project can reuse this setup and keep its own focused SAP API instead of copying the full ARC-1 server.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 uses the package itself. &lt;a href=&#34;https://github.com/ClementRingot/LISA&#34;&gt;LISA&lt;/a&gt; and &lt;a href=&#34;https://github.com/ClementRingot/ROSA&#34;&gt;ROSA&lt;/a&gt; use it as well, and &lt;a href=&#34;https://github.com/dnic-dev/bw-modeling-mcp&#34;&gt;BW Modeling MCP&lt;/a&gt; now uses it for its central SAP BTP Cloud Foundry setup. For me this is an important part of the release. The value of ARC-1 is not only the number of ABAP tools. The deployment and security principles can now help other projects too.&lt;/p&gt;&#xA;&lt;h2 id=&#34;a-new-home-for-the-project&#34;&gt;A new home for the project&lt;/h2&gt;&#xA;&lt;p&gt;ARC-1 moved from my personal GitHub account to the &lt;a href=&#34;https://github.com/arc-mcp&#34;&gt;arc-mcp organization&lt;/a&gt;. There is also a dedicated &lt;a href=&#34;https://arc-1-mcp.com/&#34;&gt;landing page&lt;/a&gt;, full documentation at &lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;docs.arc-1-mcp.com&lt;/a&gt;, and a &lt;a href=&#34;https://live-arc-1.arc-1-mcp.com/&#34;&gt;live replay demo&lt;/a&gt; that works without a SAP system, credentials, or a live LLM.&lt;/p&gt;&#xA;&lt;p&gt;The organization now contains the main product, reusable components, experiments, and demos that are still active:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;arc-1&lt;/a&gt;: the main SAP ADT MCP server.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/xsuaa-auth&#34;&gt;xsuaa-auth&lt;/a&gt;: reusable XSUAA, OAuth, and BTP Principal Propagation.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-extension-sample&#34;&gt;arc-1-extension-sample&lt;/a&gt;: examples for custom ARC-1 tools.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/adt-ls&#34;&gt;adt-ls&lt;/a&gt;: a TypeScript SDK for SAP&amp;rsquo;s headless ADT language server.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-lsp&#34;&gt;arc-1-lsp&lt;/a&gt;: an experimental MCP server built on that language-server path.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc1-adt-abap-mcp-ext&#34;&gt;arc1-adt-abap-mcp-ext&lt;/a&gt;: an Eclipse extension adding read-only tools to SAP&amp;rsquo;s ADT MCP server.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review&#34;&gt;arc-1-abap-cicd-review&lt;/a&gt;: an ABAP review workflow with GitHub Actions, abaplint, AI review, and live SAP checks.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc1-transport-review-poc&#34;&gt;arc1-transport-review-poc&lt;/a&gt;: a proof of concept for reviewing SAP transports through pull requests.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap&#34;&gt;arc-1-segw-to-rap&lt;/a&gt;: the SEGW, RAP, UI5, and Fiori elements modernization demo.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-mcp.com&#34;&gt;arc-1-mcp.com&lt;/a&gt;: the source of the landing page.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/live-arc-1&#34;&gt;live-arc-1&lt;/a&gt;: the source of the interactive replay demo.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Not every repository has the same maturity. ARC-1 is the stable core. Some projects are reusable packages, some are beta, and some are intentionally proofs of concept. Keeping them separate makes this more visible and lets each idea develop without making the main server bigger.&lt;/p&gt;&#xA;&lt;h2 id=&#34;where-to-start&#34;&gt;Where to start&lt;/h2&gt;&#xA;&lt;p&gt;If you are new to ARC-1, use the &lt;a href=&#34;https://docs.arc-1-mcp.com/quickstart/&#34;&gt;quickstart&lt;/a&gt; with a development or sandbox system and start read-only. The live demo is useful if you first want to see how the workflows and tool calls look.&lt;/p&gt;&#xA;&lt;p&gt;For a team deployment, start with the &lt;a href=&#34;https://docs.arc-1-mcp.com/btp-overview/&#34;&gt;BTP overview&lt;/a&gt;. Decide the topology, identity model, destinations, and responsibilities before enabling more capabilities. Principal Propagation should be the normal choice when SAP needs to see the human user.&lt;/p&gt;&#xA;&lt;p&gt;If you already run ARC-1, follow the &lt;a href=&#34;https://docs.arc-1-mcp.com/updating/&#34;&gt;update guide&lt;/a&gt; and review the &lt;a href=&#34;https://docs.arc-1-mcp.com/release-notes/&#34;&gt;release notes&lt;/a&gt;. For production, pin a version instead of using &lt;code&gt;latest&lt;/code&gt;, keep the first acceptance test read-only, and review the current SAP API policy and your own agreements before enabling data preview or free SQL.&lt;/p&gt;&#xA;&lt;h2 id=&#34;arc-1-saps-mcp-server-and-the-api-policy&#34;&gt;ARC-1, SAP&amp;rsquo;s MCP server, and the API policy&lt;/h2&gt;&#xA;&lt;p&gt;SAP now also provides its own ABAP MCP server as part of the ABAP Development Tools. I do not see this as an either-or decision.&lt;/p&gt;&#xA;&lt;p&gt;SAP&amp;rsquo;s server is the natural choice for a developer who works inside VS Code or Eclipse and wants to reuse the existing IDE connection. ARC-1 has a different focus. It can run as a shared service on BTP, serve different AI clients and team workflows, cover classic and modern ABAP use cases, and give administrators one place for access rules and audit information. Many teams can use both.&lt;/p&gt;&#xA;&lt;p&gt;The detailed &lt;a href=&#34;https://docs.arc-1-mcp.com/arc-1-vs-sap-abap-mcp-server/&#34;&gt;ARC-1 and SAP ABAP MCP Server comparison&lt;/a&gt; explains where each option fits, where each one is stronger, and where each one has limits. It is meant as a decision guide, not as a sales comparison.&lt;/p&gt;&#xA;&lt;p&gt;More important for a wider rollout is the &lt;a href=&#34;https://docs.arc-1-mcp.com/sap-api-policy-and-architecture/&#34;&gt;SAP API Policy and architecture guide&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 uses the ADT interfaces behind SAP&amp;rsquo;s ABAP development tools. These interfaces have been used by SAP and third-party developer tools for many years, but the ADT web endpoints are not listed as published APIs in the SAP Business Accelerator Hub. SAP&amp;rsquo;s current API policy also talks directly about access by generative AI and autonomous agents.&lt;/p&gt;&#xA;&lt;p&gt;At the same time, SAP has published an architecture for third-party MCP servers. ARC-1 is close to this architecture, especially when it runs on SAP BTP Cloud Foundry with BTP login, destinations, Cloud Connector, the real SAP user identity, traffic limits, and audit logging. This is a good technical fit, but it is not by itself a legal approval for every customer and every landscape.&lt;/p&gt;&#xA;&lt;p&gt;My recommendation is simple. Start in development or test, start read-only, and keep SAP authorizations in control. Before a broader or production rollout, ask your SAP contact whether your agreement allows third-party tools to use the ADT endpoints in this way. The policy and SAP guidance can change, so check the current documents instead of relying only on this post.&lt;/p&gt;&#xA;&lt;h2 id=&#34;thank-you&#34;&gt;Thank you&lt;/h2&gt;&#xA;&lt;p&gt;ARC-1 1.0 is not the result of one large feature. It is the result of many small reports, tests, discussions, fixes, and reviews.&lt;/p&gt;&#xA;&lt;p&gt;Thank you to everyone who opened an issue or pull request, tested another SAP release, shared a BTP setup, challenged a security decision, built an extension, tried the documentation, or sent a private message. Even when I could not implement an idea directly, the feedback helped make the project clearer and safer.&lt;/p&gt;&#xA;&lt;p&gt;Feedback is still greatly appreciated. Open an &lt;a href=&#34;https://github.com/arc-mcp/arc-1/issues&#34;&gt;issue&lt;/a&gt; when something does not work or the documentation is unclear. Send a pull request when you have a fix or improvement. A private message is also welcome, especially when you want to share details about a real landscape or raise a security concern.&lt;/p&gt;&#xA;&lt;p&gt;Version 1.0 is a milestone, not the end. Now there is a stable base, public documentation, a clearer security process, and a growing set of reusable projects around it.&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>UI5 Has Entered the Chat: Building Interactive MCP Apps for SAP</title>
      <link>https://blog.zeis.de/posts/2026-07-13-ui5-mcp-apps/</link>
      <pubDate>Mon, 13 Jul 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-07-13-ui5-mcp-apps/</guid>
      <description>&lt;p&gt;AI can appear in a user interface in several ways. It can add a focused feature such as summarization to a traditional application. It can sit next to the application as a copilot. Or the AI conversation itself can become the main interface.&lt;/p&gt;&#xA;&lt;p&gt;That last case raises an interesting question: if the AI host owns the frame, how can an MCP server provide more than text and JSON?&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://modelcontextprotocol.io/extensions/apps/overview&#34;&gt;MCP Apps&lt;/a&gt; provide an answer. They let an MCP tool return an interactive web interface that a compatible host renders inside the conversation. For our UI5con session, &lt;a href=&#34;https://www.linkedin.com/in/mike-zaschka-7395949/&#34;&gt;Mike Zaschka&lt;/a&gt; and I explored how this model fits SAP user interfaces and built five samples, starting with plain HTML and ending with an ARC-1 transport review.&lt;/p&gt;&#xA;&lt;p&gt;This post focuses on the architecture and lessons from those samples. You can &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/blob/main/UI5con2026_MCPApps.pdf&#34;&gt;read the final presentation&lt;/a&gt; or follow the code in the &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps&#34;&gt;sample repository&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-mcp-apps-add-to-mcp&#34;&gt;What MCP Apps add to MCP&lt;/h2&gt;&#xA;&lt;p&gt;A normal MCP tool already gives a model a structured way to call backend capabilities. For a small result, a text response is often the best interface. A dedicated UI becomes useful when people need to filter findings, inspect a hierarchy, compare options, or confirm an action with more context.&lt;/p&gt;&#xA;&lt;p&gt;An MCP App combines a tool result with a web resource:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;A tool declares a &lt;code&gt;ui://&lt;/code&gt; resource URI in &lt;code&gt;_meta.ui.resourceUri&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;The model calls the tool through the host.&lt;/li&gt;&#xA;&lt;li&gt;The host reads the referenced resource from the MCP server.&lt;/li&gt;&#xA;&lt;li&gt;A compatible host renders the returned HTML in a sandboxed iframe.&lt;/li&gt;&#xA;&lt;li&gt;The host passes the tool result to the app through the MCP Apps bridge.&lt;/li&gt;&#xA;&lt;li&gt;The app can request supported host operations, including calls to tools on its MCP server.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;In our samples, the model selects the tool but does not generate the interface. Each UI is prebuilt application code supplied by the MCP server. Communication between the iframe and host uses the MCP Apps protocol over a &lt;code&gt;postMessage&lt;/code&gt; transport.&lt;/p&gt;&#xA;&lt;p&gt;Host support still differs, so the &lt;a href=&#34;https://modelcontextprotocol.io/extensions/client-matrix&#34;&gt;official client support matrix&lt;/a&gt; is more reliable than a static list here.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-minimum-html-sample&#34;&gt;The minimum HTML sample&lt;/h2&gt;&#xA;&lt;p&gt;The updated presentation explains the server side in three parts: register a UI resource, link it from a tool, and return the tool result. The repository&amp;rsquo;s &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/tree/main/packages/00-html-time&#34;&gt;plain HTML time sample&lt;/a&gt; implements exactly that pattern with two tools and one UI resource.&lt;/p&gt;&#xA;&lt;h3 id=&#34;1-register-the-ui-resource&#34;&gt;1. Register the UI resource&lt;/h3&gt;&#xA;&lt;p&gt;The server registers the built HTML under a &lt;code&gt;ui://&lt;/code&gt; URI. &lt;code&gt;RESOURCE_MIME_TYPE&lt;/code&gt; from the MCP Apps server package resolves to the HTML profile expected by compatible hosts.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-ts&#34; data-lang=&#34;ts&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;kr&#34;&gt;const&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;resourceUri&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;ui://html-time/index.html&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nx&#34;&gt;registerAppResource&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;server&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;s2&#34;&gt;&amp;#34;HTML Time Demo&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;resourceUri&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;title&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;HTML Time Demo&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;description&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;A minimal MCP App.&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;},&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;kr&#34;&gt;async&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;uri&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;readBuiltAppResource&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;00-html-time&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;uri&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The sample bundles the browser code and styles into one HTML file for convenient delivery. A single-file bundle is optional, not a protocol requirement. An app can use external assets when its resource metadata declares an appropriate content security policy.&lt;/p&gt;&#xA;&lt;h3 id=&#34;2-link-the-resource-from-a-tool&#34;&gt;2. Link the resource from a tool&lt;/h3&gt;&#xA;&lt;p&gt;The &lt;code&gt;show_time&lt;/code&gt; tool points to that resource in its metadata:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-ts&#34; data-lang=&#34;ts&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nx&#34;&gt;registerAppTool&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;server&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;show_time&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;title&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;Show Time&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;description&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;Open the basic MCP Apps time demo.&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;inputSchema&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;offsetHours&lt;/span&gt;: &lt;span class=&#34;kt&#34;&gt;z.number&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;().&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;int&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;().&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;min&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;24&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;).&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;max&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;24&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;).&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;optional&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;()&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;},&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;_meta&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;ui&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;resourceUri&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;},&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;handler&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The URI must match the registered resource exactly. This association tells an MCP Apps host that the tool has a visual companion.&lt;/p&gt;&#xA;&lt;h3 id=&#34;3-return-text-and-structured-data&#34;&gt;3. Return text and structured data&lt;/h3&gt;&#xA;&lt;p&gt;The tool calculates a timestamp and returns two representations of the outcome:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-ts&#34; data-lang=&#34;ts&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;content&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;kr&#34;&gt;type&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;text&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;text&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;sb&#34;&gt;`Current server time: &lt;/span&gt;&lt;span class=&#34;si&#34;&gt;${&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;isoTime&lt;/span&gt;&lt;span class=&#34;si&#34;&gt;}&lt;/span&gt;&lt;span class=&#34;sb&#34;&gt;`&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;}],&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;structuredContent&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;isoTime&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;offsetHours&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;formattedTime&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;};&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;content&lt;/code&gt; gives the model and non-UI clients a concise fallback. &lt;code&gt;structuredContent&lt;/code&gt; is the stable data contract the app renders without parsing prose. The complete server implementation is in &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/blob/main/packages/00-html-time/src/register.ts&#34;&gt;&lt;code&gt;register.ts&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h3 id=&#34;run-the-app-inside-the-host&#34;&gt;Run the app inside the host&lt;/h3&gt;&#xA;&lt;p&gt;Inside the iframe, the app connects to the host and listens for the tool result:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-ts&#34; data-lang=&#34;ts&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;kr&#34;&gt;const&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;app&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;new&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;App&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;({&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;name&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;HTML Time Demo&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;version&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;0.1.0&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;});&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nx&#34;&gt;app&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;addEventListener&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;toolresult&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;result&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;renderTime&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;result&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;structuredContent&lt;/span&gt; &lt;span class=&#34;kr&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;TimePayload&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;});&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;await&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;app&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;connect&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;();&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The interface shows the time and an &lt;strong&gt;Add 1 hour&lt;/strong&gt; button. That button calls a second tool through the bridge:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-ts&#34; data-lang=&#34;ts&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;kr&#34;&gt;const&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;result&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;await&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;app&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;callServerTool&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;({&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;name&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;add_hour&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;arguments&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;isoTime&lt;/span&gt;: &lt;span class=&#34;kt&#34;&gt;currentIsoTime&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nx&#34;&gt;hours&lt;/span&gt;: &lt;span class=&#34;kt&#34;&gt;1&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;});&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nx&#34;&gt;renderTime&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;result&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;structuredContent&lt;/span&gt; &lt;span class=&#34;kr&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;TimePayload&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The host routes the request to the server and returns the result to the existing iframe. The app updates without asking the model to generate another interface. See the full browser code in &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/blob/main/packages/00-html-time/app/src/main.ts&#34;&gt;&lt;code&gt;main.ts&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This small example captures the important separation of responsibilities:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The model chooses the initial tool based on the user&amp;rsquo;s request.&lt;/li&gt;&#xA;&lt;li&gt;The MCP server executes backend logic and returns text plus structured data.&lt;/li&gt;&#xA;&lt;li&gt;The host controls whether and how the UI is rendered.&lt;/li&gt;&#xA;&lt;li&gt;The app renders the data and handles local interaction.&lt;/li&gt;&#xA;&lt;li&gt;Further tool calls still travel through the host-controlled bridge.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;That is the core concept. UI5 changes the presentation layer, not the MCP Apps lifecycle. It also explains why debugging has two layers: a successful tool call does not prove that the UI resource loaded, and a loaded iframe does not prove that its scripts passed the host&amp;rsquo;s content security policy.&lt;/p&gt;&#xA;&lt;h2 id=&#34;when-a-tool-result-should-become-an-app&#34;&gt;When a tool result should become an app&lt;/h2&gt;&#xA;&lt;p&gt;MCP Apps are useful, but they should not turn every tool call into a miniature application. Text is still the fastest interface for a status, identifier, confirmation, or short explanation. A table in prose may also be enough when the user only needs to read it once.&lt;/p&gt;&#xA;&lt;p&gt;I would add an app when at least one of these is true:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The user needs to explore or filter a result without repeatedly calling the model.&lt;/li&gt;&#xA;&lt;li&gt;The structure is easier to understand visually, such as a transport hierarchy or findings grouped by file.&lt;/li&gt;&#xA;&lt;li&gt;The next action benefits from seeing context first, such as choosing a task after reviewing its objects.&lt;/li&gt;&#xA;&lt;li&gt;A long-running or multi-step workflow benefits from visible progress and guided decisions.&lt;/li&gt;&#xA;&lt;li&gt;The interaction has temporary presentation state that does not belong in the conversation.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The UI should stay focused on the result and its immediate actions. It should not recreate the host&amp;rsquo;s chat controls or hide backend behavior behind ordinary-looking buttons. If an action writes data, changes source files, or releases a transport, its effect should be clear before the request reaches the server.&lt;/p&gt;&#xA;&lt;p&gt;Because the tool still returns normal &lt;code&gt;content&lt;/code&gt;, a host without MCP Apps support can show a useful text result. The interface enhances the tool contract instead of replacing it.&lt;/p&gt;&#xA;&lt;h2 id=&#34;bringing-ui5-into-the-iframe&#34;&gt;Bringing UI5 into the iframe&lt;/h2&gt;&#xA;&lt;p&gt;An MCP App is a web application, so it can use plain JavaScript or frameworks such as React, Vue, Svelte, or UI5 technologies.&lt;/p&gt;&#xA;&lt;p&gt;For focused SAP-oriented interfaces, &lt;a href=&#34;https://ui5.github.io/webcomponents/&#34;&gt;UI5 Web Components&lt;/a&gt; are my preferred default. They provide SAP-styled, themeable and accessible controls while remaining based on web standards and usable with different frameworks. In the final sample, the app listens for the host&amp;rsquo;s light or dark context and maps it to &lt;code&gt;sap_horizon&lt;/code&gt; or &lt;code&gt;sap_horizon_dark&lt;/code&gt;. An MCP App can use familiar controls without adopting the full SAPUI5 application model.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://ui5.sap.com/test-resources/sap/ui/integration/demokit/cardExplorer/index.html&#34;&gt;UI Integration Cards&lt;/a&gt; are attractive when the result is naturally a summary, list, or compact dashboard. Their declarative manifests reduce custom rendering code. Our card sample loads the Integration Cards runtime from &lt;code&gt;ui5.sap.com&lt;/code&gt;, so its resource declares that domain in its content security policy. An allowlist cannot override a host&amp;rsquo;s sandbox, however. The repository therefore uses portable Object and List Cards rather than an Analytical Card whose &lt;code&gt;sap.viz&lt;/code&gt; runtime may require blocked execution features.&lt;/p&gt;&#xA;&lt;p&gt;A full SAPUI5 application can also be served as an MCP App, but I would use it selectively. Fiori Elements&amp;rsquo; OData-driven page model, routing, and shell integration can be excessive inside a small conversation frame. That is a design tradeoff, not a protocol restriction.&lt;/p&gt;&#xA;&lt;p&gt;This is not an SAP-specific extension to MCP. It is the normal MCP Apps model combined with UI5. It nevertheless fits the direction described by SAP&amp;rsquo;s &lt;a href=&#34;https://architecture.learning.sap.com/docs/ai-native-north-star-architecture/user-experience-layer&#34;&gt;AI-native North Star user experience layer&lt;/a&gt;, where users express intent and the system brings relevant information and actions into context.&lt;/p&gt;&#xA;&lt;p&gt;The distinction between MCP and MCP Apps matters here. &lt;a href=&#34;https://help.sap.com/docs/joule-studio-classic/joule-studio-classic-edition/add-mcp-servers-to-your-joule-agent&#34;&gt;Joule Studio documents how to add MCP servers to a Joule agent&lt;/a&gt;, using Streamable HTTP endpoints configured through SAP BTP destinations. That allows Joule agents to use server tools, but it does not by itself mean the host renders MCP App resources. At the time of writing, I could not verify documented Joule support for the MCP Apps extension in the official client matrix.&lt;/p&gt;&#xA;&lt;h2 id=&#34;from-the-minimum-sample-to-sap-workflows&#34;&gt;From the minimum sample to SAP workflows&lt;/h2&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps&#34;&gt;sample repository&lt;/a&gt; contains five steps and a repository-wide &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/blob/main/LEARNING.md&#34;&gt;learning guide&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/tree/main/packages/00-html-time&#34;&gt;Plain HTML time&lt;/a&gt;:&lt;/strong&gt; Demonstrates the tool, resource, result, iframe, and app-triggered tool call with minimal code.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/tree/main/packages/01-ui5-webc-project-overview&#34;&gt;UI5 Web Components project overview&lt;/a&gt;:&lt;/strong&gt; Renders project metadata, libraries, and checks, synchronizes the host&amp;rsquo;s light or dark theme, and requires no external CSP domains.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/tree/main/packages/02-ui5-card-project-overview&#34;&gt;UI Integration Cards project overview&lt;/a&gt;:&lt;/strong&gt; Renders the same dataset as declarative Object and List Cards. Its external &lt;code&gt;ui5.sap.com&lt;/code&gt; runtime is explicitly declared in the resource CSP.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/tree/main/packages/03-ui5-lint-findings&#34;&gt;UI5 lint findings&lt;/a&gt;:&lt;/strong&gt; Opens the UI first, then calls back through the bridge to run the official UI5 MCP server as a child client, with a local &lt;code&gt;ui5lint&lt;/code&gt; fallback. Filtering stays local. Ignoring one line, one rule in a file, or a whole file invokes an explicit write tool, after which the app can rerun the linter.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/tree/main/packages/04-arc1-transport&#34;&gt;ARC-1 transport review&lt;/a&gt;:&lt;/strong&gt; Provides separate list and detail tools for live, host-orchestrated ARC-1 data. Clearly labelled offline fixtures are included for rehearsals when ARC-1 or SAP is unavailable.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;MCP Apps host rendering the UI5 linter demo with active findings grouped by rule and file, plus rerun and ignore actions.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-07-13-ui5-mcp-apps/images/ui5-lint-findings.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The ARC-1 example introduces an important boundary. The UI belongs to one MCP server, while ARC-1 is another. The app therefore does not secretly call an ARC-1 tool. When someone confirms a release in the UI, the app sends a message to the host asking the agent to continue the workflow. The host can then select the connected ARC-1 tool and apply its normal authorization and confirmation behavior.&lt;/p&gt;&#xA;&lt;p&gt;My rule of thumb is simple:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Use &lt;code&gt;callServerTool()&lt;/code&gt; for a known tool exposed by the server that owns the app.&lt;/li&gt;&#xA;&lt;li&gt;Send a message to the host when the agent must coordinate another server or decide the next step.&lt;/li&gt;&#xA;&lt;li&gt;Keep consequential operations visible to the host&amp;rsquo;s approval model.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;host-ux-state-and-security&#34;&gt;Host UX, state, and security&lt;/h2&gt;&#xA;&lt;p&gt;The host owns the frame around an MCP App, which creates a few UX constraints that are easy to miss:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Display mode:&lt;/strong&gt; an app may request &lt;code&gt;inline&lt;/code&gt;, &lt;code&gt;fullscreen&lt;/code&gt;, or picture-in-picture, but the host declares which modes it supports and returns the mode it actually selected.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Theme:&lt;/strong&gt; the host can provide a light or dark preference and optional style variables. The UI5 Web Components sample maps that preference to &lt;code&gt;sap_horizon&lt;/code&gt; or &lt;code&gt;sap_horizon_dark&lt;/code&gt; and reacts when it changes.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Size:&lt;/strong&gt; the host can provide fixed or maximum container dimensions. The SDK reports content-size changes automatically by default, but the interface should still be responsive within the space the host grants it.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;An app-triggered &lt;code&gt;callServerTool()&lt;/code&gt; can update the existing iframe, as the time sample demonstrates. A host may nevertheless recreate the iframe for a new UI-producing call or when its lifecycle requires it. Therefore, filters and selected rows can stay local, while important results belong in structured tool output or the backend. Durable changes, such as adding a linter ignore, belong in the project or backend. Refresh authoritative data after mutations instead of relying on iframe memory.&lt;/p&gt;&#xA;&lt;p&gt;The iframe sandbox is also not a complete security model. The host controls bridge capabilities, while the server must still validate inputs and authorize tool calls. External scripts and network destinations need to be declared in the MCP App&amp;rsquo;s UI content security policy. Backend writes should be explicit and should not be disguised as harmless UI interactions.&lt;/p&gt;&#xA;&lt;p&gt;Our samples use Vite and &lt;code&gt;vite-plugin-singlefile&lt;/code&gt; to produce one built &lt;code&gt;index.html&lt;/code&gt; for each &lt;code&gt;ui://&lt;/code&gt; resource. This simplifies delivery, although bundling UI5 Web Components increases the artifact size. The repository provides both stdio and Streamable HTTP launchers. These connect the MCP client and server; the app uses the separate iframe bridge.&lt;/p&gt;&#xA;&lt;h2 id=&#34;try-the-minimum-sample&#34;&gt;Try the minimum sample&lt;/h2&gt;&#xA;&lt;p&gt;The repository requires Node.js 22. The exact commands and client configuration live in the &lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/tree/main/packages/00-html-time&#34;&gt;minimum sample README&lt;/a&gt;. From the repository root:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;npm ci&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;npm run build&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;npm run start:00&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Connect an MCP Apps-compatible HTTP client to &lt;code&gt;http://127.0.0.1:3010/mcp&lt;/code&gt;, then ask it to call &lt;code&gt;show_time&lt;/code&gt;. The text result should remain useful even in a client that does not render the UI.&lt;/p&gt;&#xA;&lt;p&gt;For a protocol-level check, start the aggregate server with &lt;code&gt;npm run start&lt;/code&gt; and run &lt;code&gt;npm run test:mcpjam&lt;/code&gt; in another terminal.&lt;/p&gt;&#xA;&lt;!-- TODO before publication: add screenshots of the Web Components overview, Integration Cards comparison, and ARC-1 transport organizer. --&gt;&#xA;&lt;h2 id=&#34;references&#34;&gt;References&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/blob/main/UI5con2026_MCPApps.pdf&#34;&gt;Final UI5con presentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps&#34;&gt;UI5 MCP Apps sample repository&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/UI5con_2026_MCPApps/blob/main/LEARNING.md&#34;&gt;Step-by-step learning guide&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://modelcontextprotocol.io/extensions/apps/overview&#34;&gt;MCP Apps overview&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://modelcontextprotocol.io/extensions/apps/build&#34;&gt;Build an MCP App&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://modelcontextprotocol.io/extensions/client-matrix&#34;&gt;MCP Apps client support&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/modelcontextprotocol/ext-apps&#34;&gt;MCP Apps SDK and examples&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://ui5.github.io/webcomponents/&#34;&gt;UI5 Web Components&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://architecture.learning.sap.com/docs/ai-native-north-star-architecture/user-experience-layer&#34;&gt;SAP AI-native North Star user experience layer&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>Creating an ARC-1 BTP Diagram with Codex and a draw.io Skill</title>
      <link>https://blog.zeis.de/posts/2026-07-10-btp-drawio-skill/</link>
      <pubDate>Thu, 09 Jul 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-07-10-btp-drawio-skill/</guid>
      <description>&lt;p&gt;I wanted one practical thing: an editable draw.io diagram for ARC-1 on SAP BTP that looks like it belongs in the SAP Architecture Center.&lt;/p&gt;&#xA;&lt;p&gt;My first attempts with generic diagram prompts were not really useful. They often had dark backgrounds, icons that were too large, and arrows running through boxes. I wanted something closer to the SAP examples: a white canvas, the right BTP areas and service icons, understandable flows, and an editable draw.io file that I could still correct by hand.&lt;/p&gt;&#xA;&lt;p&gt;That became &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill&#34;&gt;&lt;code&gt;marianfoo/btp-drawio-skill&lt;/code&gt;&lt;/a&gt;, a skill for creating SAP Architecture Center-style &lt;code&gt;.drawio&lt;/code&gt; files from plain text.&lt;/p&gt;&#xA;&lt;h2 id=&#34;where-this-started&#34;&gt;Where this started&lt;/h2&gt;&#xA;&lt;p&gt;I did not start this from zero. The main source was SAP itself, and there are two related projects that are easy to mix up:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The &lt;a href=&#34;https://sap.github.io/btp-solution-diagrams/&#34;&gt;SAP BTP Solution Diagram Guidelines&lt;/a&gt; define how these diagrams should look: levels, areas, colors, icons, connectors, labels, and legends. The complete guideline and editable examples are in &lt;a href=&#34;https://github.com/SAP/btp-solution-diagrams&#34;&gt;&lt;code&gt;SAP/btp-solution-diagrams&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;The &lt;a href=&#34;https://architecture.learning.sap.com/&#34;&gt;SAP Architecture Center&lt;/a&gt; publishes real reference architectures for topics such as integration, identity, data, AI, and resiliency. Their source, including many editable &lt;code&gt;.drawio&lt;/code&gt; files, is in &lt;a href=&#34;https://github.com/SAP/architecture-center&#34;&gt;&lt;code&gt;SAP/architecture-center&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The skill bundles selected diagrams and assets from these official sources. This gives the model both parts it needs: the visual rules and real SAP-authored examples.&lt;/p&gt;&#xA;&lt;p&gt;Two community projects also appeared almost at the same time.&lt;/p&gt;&#xA;&lt;p&gt;Wouter Lemaire published &lt;a href=&#34;https://github.com/lemaiwo/btp-drawio-skill&#34;&gt;&lt;code&gt;lemaiwo/btp-drawio-skill&lt;/code&gt;&lt;/a&gt; on April 17. I took inspiration from its Claude marketplace structure and the idea of bundling the SAP icon XML libraries directly with the skill.&lt;/p&gt;&#xA;&lt;p&gt;One day later, &lt;a href=&#34;https://github.com/miyasuta/claude-drawio-btp-diagram&#34;&gt;&lt;code&gt;miyasuta/claude-drawio-btp-diagram&lt;/code&gt;&lt;/a&gt; appeared. I liked its separation between official guidelines, conventions, and concrete draw.io styles. Its center-alignment rule for straight connectors also became an important detail in my implementation.&lt;/p&gt;&#xA;&lt;p&gt;I started my repository on April 22 because I needed the ARC-1 diagram. From there I added a larger SAP Architecture Center corpus, template ranking, asset extraction, built-in fallback layouts, validation, scoring, visual comparison, and the nudge loop.&lt;/p&gt;&#xA;&lt;p&gt;The main lesson stayed simple: do not generate SAP diagrams from scratch when SAP already published the visual language and many real examples.&lt;/p&gt;&#xA;&lt;p&gt;Before the example, it helps to understand what the skill actually does.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-the-skill-works&#34;&gt;How the skill works&lt;/h2&gt;&#xA;&lt;p&gt;Without the skill, the model starts with an empty canvas and has to invent the layout. With the skill, it first decides what kind of diagram is needed and then looks for the closest SAP example.&lt;/p&gt;&#xA;&lt;p&gt;SAP defines three diagram levels based on the audience and required detail:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;L0&lt;/code&gt; is a business overview. It uses only a few blocks and simple neutral arrows. Technical details are left out.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;L1&lt;/code&gt; is a conceptual architecture. It shows named SAP services, the main zones such as BTP and on-premise, and the important flows between them.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;L2&lt;/code&gt; is a logical or technical architecture. It adds protocols, identity and trust flows, connector labels, and a legend. The ARC-1 example in this post is an L2 diagram.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The complete workflow looks like this:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Your architecture description&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            |&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            v&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Choose the level and closest SAP example&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            |&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            v&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Copy and adapt the example&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            |&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            v&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Validate -&amp;gt; render -&amp;gt; inspect -&amp;gt; correct&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            |&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;            v&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Editable .drawio file and PNG&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The repository currently bundles 71 reference templates, 100 SAP BTP service icons, and 448 indexed draw.io assets. Most templates come from the two official SAP repositories above, with a few additional public SAP examples.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;Find a starting point.&lt;/strong&gt; &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/scaffold_diagram.py&#34;&gt;&lt;code&gt;scaffold_diagram.py&lt;/code&gt;&lt;/a&gt; ranks the templates and copies the closest one. This copy is the scaffold.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Adapt only what changed.&lt;/strong&gt; The model keeps the SAP layout and uses helpers such as &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/relabel.py&#34;&gt;&lt;code&gt;relabel.py&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/extract_icon.py&#34;&gt;&lt;code&gt;extract_icon.py&lt;/code&gt;&lt;/a&gt;, and &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/extract_asset.py&#34;&gt;&lt;code&gt;extract_asset.py&lt;/code&gt;&lt;/a&gt; to change labels and assets.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Use a smaller fallback when needed.&lt;/strong&gt; If the closest template is much larger than the requested diagram, &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/render_semantic.py&#34;&gt;&lt;code&gt;render_semantic.py&lt;/code&gt;&lt;/a&gt; can create a smaller layout for a few known patterns while keeping the SAP visual rules.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the result and look at it.&lt;/strong&gt; &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/autofix.py&#34;&gt;&lt;code&gt;autofix.py&lt;/code&gt;&lt;/a&gt; repairs known mechanical problems. &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/validate.py&#34;&gt;&lt;code&gt;validate.py&lt;/code&gt;&lt;/a&gt; checks colors, fonts, icons, labels, and arrow routing. &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/score_corpus.py&#34;&gt;&lt;code&gt;score_corpus.py&lt;/code&gt;&lt;/a&gt; compares the result with the SAP examples. Then &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/iterate.py&#34;&gt;&lt;code&gt;iterate.py&lt;/code&gt;&lt;/a&gt; and &lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill/blob/main/plugins/sap-architecture/skills/sap-architecture/scripts/render_compare.py&#34;&gt;&lt;code&gt;render_compare.py&lt;/code&gt;&lt;/a&gt; render the diagram so the model can inspect and correct it.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The important limit is that these checks only understand the file and its visual structure. They do not know if the architecture itself is correct.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-sample-use-case-in-codex&#34;&gt;The sample use case in Codex&lt;/h2&gt;&#xA;&lt;p&gt;For the sample, I used the exact problem that started this project: a developer in VS Code asks an AI assistant to inspect an ABAP class through ARC-1.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Developer and AI assistant in VS Code&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;                |&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;               MCP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;                v&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ARC-1 on SAP BTP Cloud Foundry&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;                |&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Destination + Connectivity + Cloud Connector&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;                v&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;On-premise SAP ABAP system&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;XSUAA authenticates the client. Destination Service and Connectivity Service route the request through SAP Cloud Connector. Principal Propagation keeps the developer&amp;rsquo;s identity for the ABAP call.&lt;/p&gt;&#xA;&lt;p&gt;The diagram should make this complete path understandable for an SAP platform or development team. I used Codex to create it and kept the first result, the correction, and all validation output for the example below.&lt;/p&gt;&#xA;&lt;p&gt;The skill started as a Claude Code plugin, but the important part is portable. It is a folder with Markdown instructions, SAP templates, local assets, and Python scripts.&lt;/p&gt;&#xA;&lt;p&gt;For Codex I cloned the repository and pointed an &lt;code&gt;AGENTS.md&lt;/code&gt; file at the skill:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;git clone https://github.com/marianfoo/btp-drawio-skill.git&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-markdown&#34; data-lang=&#34;markdown&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;For SAP architecture diagrams, use the sap-architecture skill at&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&amp;lt;path&amp;gt;/btp-drawio-skill/plugins/sap-architecture/skills/sap-architecture.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Read SKILL.md completely. Always scaffold before editing. Run autofix,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;validate, score, render, and inspect the image before finishing.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Never write the draw.io XML from scratch.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Codex reads the project instructions and can call the scripts directly. Python 3.8 or newer and shell access are required. The draw.io desktop app is only needed for PNG, SVG, or PDF export.&lt;/p&gt;&#xA;&lt;p&gt;For the example I described one focused L2 architecture:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Create an L2 SAP Architecture Center-style diagram.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;A developer uses an MCP-capable AI assistant in VS Code to inspect an ABAP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;class through ARC-1. ARC-1 runs on SAP BTP Cloud Foundry and exposes /mcp&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;over Streamable HTTP. The client authenticates through XSUAA. ARC-1 resolves&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;a PrincipalPropagation destination, uses Connectivity Service and SAP Cloud&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Connector, and reads the on-premise SAP ABAP system through ADT REST.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Zones: Developer Workstation, SAP BTP Cloud Foundry,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Customer On-Premise Network.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Output an editable .drawio, PNG, validation and score results,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;and the numbered flow narration.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The &lt;a href=&#34;artifacts/codex-prompt.txt&#34;&gt;complete prompt&lt;/a&gt; and a &lt;a href=&#34;artifacts/codex-agents.txt&#34;&gt;sanitized copy of the &lt;code&gt;AGENTS.md&lt;/code&gt; used for the run&lt;/a&gt; are attached to this post.&lt;/p&gt;&#xA;&lt;p&gt;Codex worked for 6 minutes and 42 seconds. It read the skill, ran the template selector, created a first pass, validated and rendered it, inspected the image, made one correction, and ran the checks again.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Codex run summary showing the selected templates, fallback decision, validator result, final score, and generated artifacts.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-07-10-btp-drawio-skill/images/codex-run-summary.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The selector correctly ranked &lt;code&gt;ac_RA0001_E2B_CloudConnector.drawio&lt;/code&gt; first. But this SAP reference has 24 cards and a much larger scope. Removing enough cards for my focused ARC-1 flow would remove more than one third of the template.&lt;/p&gt;&#xA;&lt;p&gt;Codex therefore switched to the skill&amp;rsquo;s built-in &lt;code&gt;on-prem-connectivity&lt;/code&gt; renderer. This was one of the improvements I added: start with the closest SAP example, but do not force a large template into a much smaller use case. The renderer still uses the same SAP palette, dimensions, assets, and validation rules.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-first-pass-scored-100-but-was-wrong&#34;&gt;The first pass scored 100, but was wrong&lt;/h2&gt;&#xA;&lt;p&gt;This was the first complete diagram:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;First generated ARC-1 connectivity diagram. It still contains generic HTTPS, OData/REST, and SAP S/4HANA labels.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-07-10-btp-drawio-skill/images/arc-1-btp-cf-onprem-first-pass.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The validator returned &lt;code&gt;OK&lt;/code&gt;, and the reference-free SAP-likeness score was &lt;code&gt;100.0/100&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;That sounds good, but it was still wrong for my use case.&lt;/p&gt;&#xA;&lt;p&gt;The title was generic. The VS Code flow used &lt;code&gt;HTTPS&lt;/code&gt; instead of &lt;code&gt;MCP&lt;/code&gt;. The backend connection said &lt;code&gt;OData/REST&lt;/code&gt;, although ARC-1 uses the ADT REST API. It also named SAP S/4HANA even though I wanted a generic on-premise SAP ABAP system.&lt;/p&gt;&#xA;&lt;p&gt;This is the part I find most useful. A score can tell me that the file follows the expected visual rules. It cannot prove that the architecture says the right thing.&lt;/p&gt;&#xA;&lt;p&gt;Codex inspected the rendered PNG and made one focused correction. It kept the layout and corrected the labels and colors: MCP in teal, XSUAA and Principal Propagation in green, ARC-1 as the purple focus application, and ADT REST for the backend call.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Final ARC-1 on SAP BTP Cloud Foundry diagram after one visual and semantic correction.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-07-10-btp-drawio-skill/images/arc-1-btp-cf-onprem-final.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The final result passed validation without errors or warnings. Its SAP-likeness score was &lt;code&gt;96.7/100&lt;/code&gt;, slightly lower than the first pass, but the diagram was now correct for ARC-1. The scorer still reported two vocabulary advisories for &lt;code&gt;OAUTH JWT&lt;/code&gt; and &lt;code&gt;mTLS PP&lt;/code&gt;. I kept them because they explain the exact identity flow and are already part of the skill&amp;rsquo;s L2 layout guidance.&lt;/p&gt;&#xA;&lt;p&gt;While preparing this post, I found one more export problem. The draw.io file did not store the white page background explicitly, and one PNG export came out black. I set the page background to white in both attached &lt;code&gt;.drawio&lt;/code&gt; files and exported them again. The validator had accepted the missing value as the default background. This was another useful reminder that I still need to look at the final image.&lt;/p&gt;&#xA;&lt;p&gt;That is also why I would use a strong reasoning model for this task. The skill removes a lot of guessing, but the model still has to read the workflow, choose between a template and fallback, understand the architecture, inspect an image, and notice when a high-scoring result is semantically wrong. I did not compare several Codex models in this run, so this is not a model benchmark.&lt;/p&gt;&#xA;&lt;p&gt;The artifacts from the run are available here:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;artifacts/run-report.txt&#34;&gt;Full Codex run report&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;artifacts/arc-1-btp-cf-onprem-first-pass.drawio&#34;&gt;First-pass editable draw.io&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;artifacts/arc-1-btp-cf-onprem-final.drawio&#34;&gt;Final editable draw.io&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;artifacts/arc-1-btp-cf-onprem-flow.txt&#34;&gt;Numbered flow narration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;artifacts/first-pass-validation.txt&#34;&gt;First-pass validation&lt;/a&gt; and &lt;a href=&#34;artifacts/first-pass-score.txt&#34;&gt;score&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;artifacts/final-validation.txt&#34;&gt;Final validation&lt;/a&gt; and &lt;a href=&#34;artifacts/final-score.txt&#34;&gt;score&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;how-to-prompt-it&#34;&gt;How to prompt it&lt;/h2&gt;&#xA;&lt;p&gt;The skill works best when the prompt describes an architecture, not only a product list. Include:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Level: &lt;code&gt;L0&lt;/code&gt;, &lt;code&gt;L1&lt;/code&gt;, or &lt;code&gt;L2&lt;/code&gt;, based on the audience and required detail.&lt;/li&gt;&#xA;&lt;li&gt;Audience: business overview, solution architecture, or implementation team.&lt;/li&gt;&#xA;&lt;li&gt;Zones: client, SAP BTP, SAP cloud applications, on-premise, or third party.&lt;/li&gt;&#xA;&lt;li&gt;Exact services: this improves SAP icon and asset selection.&lt;/li&gt;&#xA;&lt;li&gt;Backend systems: for example SAP S/4HANA, ECC, BW/4HANA, or a generic ABAP system.&lt;/li&gt;&#xA;&lt;li&gt;Identity: IAS, XSUAA, OAuth, SAML, Principal Propagation, trust, and authorization.&lt;/li&gt;&#xA;&lt;li&gt;Numbered flow steps and protocols such as MCP, HTTPS, ADT REST, OData, A2A, or SAML2/OIDC.&lt;/li&gt;&#xA;&lt;li&gt;Constraints and exclusions: what must be shown and what should stay out.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;A weak prompt is:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Draw ARC-1 with BTP and SAP.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That leaves the model guessing about the level, zones, identity, backend protocol, and even the purpose of the diagram.&lt;/p&gt;&#xA;&lt;p&gt;The skill is also an authoring assistant, not a one-shot generator. Give visual feedback such as:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&amp;ldquo;The icons overlap the text. Use the normal SAP icon size.&amp;rdquo;&lt;/li&gt;&#xA;&lt;li&gt;&amp;ldquo;The MCP flow should be teal.&amp;rdquo;&lt;/li&gt;&#xA;&lt;li&gt;&amp;ldquo;Cloud Connector belongs in the on-premise network.&amp;rdquo;&lt;/li&gt;&#xA;&lt;li&gt;&amp;ldquo;The backend call is ADT REST, not OData.&amp;rdquo;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Specific feedback maps to a concrete edit. &amp;ldquo;Make it better&amp;rdquo; usually does not.&lt;/p&gt;&#xA;&lt;h2 id=&#34;where-it-works-and-where-it-stops&#34;&gt;Where it works and where it stops&lt;/h2&gt;&#xA;&lt;p&gt;It works best for a focused L1 or L2 diagram with explicit zones and flows, especially when a reference from the same architecture family exists.&lt;/p&gt;&#xA;&lt;p&gt;Sometimes no close template exists. Then another model retry does not solve the problem. The skill can use a deterministic fallback for a few known patterns, but other diagrams still need manual draw.io work or another reference template.&lt;/p&gt;&#xA;&lt;p&gt;The validator also cannot prove semantic correctness. The Codex run above showed that clearly. A diagram can be valid, visually SAP-like, and still use the wrong protocol or product name.&lt;/p&gt;&#xA;&lt;p&gt;For me, the value is not a perfect architecture from one sentence. The value is a much better editable first draft, a repeatable way to check it, and a clear loop for the last correction.&lt;/p&gt;&#xA;&lt;h2 id=&#34;links&#34;&gt;Links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/btp-drawio-skill&#34;&gt;&lt;code&gt;marianfoo/btp-drawio-skill&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/miyasuta/claude-drawio-btp-diagram&#34;&gt;&lt;code&gt;miyasuta/claude-drawio-btp-diagram&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/lemaiwo/btp-drawio-skill&#34;&gt;&lt;code&gt;lemaiwo/btp-drawio-skill&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://sap.github.io/btp-solution-diagrams/&#34;&gt;SAP BTP Solution Diagram Guidelines&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP/btp-solution-diagrams&#34;&gt;&lt;code&gt;SAP/btp-solution-diagrams&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP/architecture-center&#34;&gt;&lt;code&gt;SAP/architecture-center&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1 on GitHub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.zeis.de/posts/2026-04-27-arc-1/&#34;&gt;Introducing ARC-1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.zeis.de/posts/2026-04-29-arc-1-btp/&#34;&gt;ARC-1 on SAP BTP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>A Clearer View of Your SAP Integrations Under the New API Policy</title>
      <link>https://blog.zeis.de/posts/2026-06-01-mcp-api-policy/</link>
      <pubDate>Tue, 02 Jun 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-06-01-mcp-api-policy/</guid>
      <description>&lt;p&gt;In April, SAP published a new &lt;a href=&#34;https://help.sap.com/doc/sap-api-policy/latest/en-US/API_Policy_latest.pdf&#34;&gt;&lt;strong&gt;API Policy (v.4.2026a)&lt;/strong&gt;&lt;/a&gt;. If you run SAP integrations of any kind, like middleware, custom extensions, analytics pipelines, RPA, or anything with &amp;ldquo;AI agent&amp;rdquo; in the name, you have probably already had the uncomfortable conversation. Are we still allowed to do that, and can we safely start the next project this way?&lt;/p&gt;&#xA;&lt;p&gt;The honest answer is that nobody can fully answer that for you. That is the real problem.&lt;/p&gt;&#xA;&lt;p&gt;When DSAG reacted to the policy, the loudest complaint was not the rules. It was the lack of clarity. Chairman Jens Hungershausen put it simply: &lt;em&gt;&amp;ldquo;The question is which interfaces are used in the partner solutions.&amp;rdquo;&lt;/em&gt; Board member Michael Bloch called the undefined contractual status of the SAP Business Accelerator Hub &lt;em&gt;&amp;ldquo;unacceptable&amp;rdquo;&lt;/em&gt; (&lt;a href=&#34;https://www.cio.com/article/4166172/dsag-criticizes-saps-new-api-policy.html&#34;&gt;CIO&lt;/a&gt;). SAP says existing integrations are not affected, but it has not written that down in a way customers can rely on. Analysts went further. Forrester told CIOs to &lt;a href=&#34;https://www.forrester.com/blogs/sap-is-attempting-to-become-the-gatekeeper-of-enterprise-ai-cios-should-push-back/&#34;&gt;push back&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;That missing pre-project clarity is exactly the gap I built this for: a practical evidence workflow that helps you look at one real interface or automation approach at a time before you invest more time in it. It is not a replacement for SAP, not legal advice, and not a magic compliance stamp.&lt;/p&gt;&#xA;&lt;p&gt;I have been following this closely. I am one of the consultants quoted in &lt;a href=&#34;https://www.theregister.com/2026/04/29/new_sap_api_policy_provokes/&#34;&gt;The Register&lt;/a&gt; on the AI clause. But commentary only goes so far. So I built something practical instead. It gives you an evidence-based view of your own interfaces against the policy, with sources and a confidence level.&lt;/p&gt;&#xA;&lt;p&gt;It does not give you a verdict. That is on purpose. Here is why, and how it works.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-nobody-can-give-you-a-clean-yes-or-no&#34;&gt;Why nobody can give you a clean yes or no&lt;/h2&gt;&#xA;&lt;p&gt;The policy is only two pages, but it is broad. You may use &lt;strong&gt;Published APIs&lt;/strong&gt;, the ones listed on the SAP Business Accelerator Hub or named in product documentation, for their &lt;strong&gt;Documented Use&lt;/strong&gt;. It then restricts non-published or internal APIs (§1.2), specific and general controls like rate limits and bulk-extraction preconditions (§2), and the clause everyone worries about, §2.2.2: interaction with autonomous or generative AI that plans, selects, or executes sequences of API calls, plus large-scale extraction, unless you go through an SAP-endorsed pathway. At Sapphire 2026, SAP CTO Philipp Herzig &lt;a href=&#34;https://diginomica.com/sap-sapphire-2026-sap-cto-philipp-herzig-saps-api-policy-changes-and-why-organizational-memory&#34;&gt;spoke to the direction&lt;/a&gt;. The policy is about routing agentic access through governed, reliable pathways.&lt;/p&gt;&#xA;&lt;p&gt;But here is the part that matters for a tool. In its own FAQ, SAP was asked the exact question customers and partners now care about: will there be a binding decision matrix or concrete examples that let them assess, before starting a project, whether an integration or automation approach is compliant and future-proof? SAP said no (FAQ Q49). Only SAP, your contract, or SAP support can give a binding answer for your landscape.&lt;/p&gt;&#xA;&lt;p&gt;So any tool that prints &amp;ldquo;COMPLIANT&amp;rdquo; or &amp;ldquo;NOT COMPLIANT&amp;rdquo; would lie to you. The best you can honestly do is well-sourced, confidence-rated evidence, plus the right questions for SAP. That is what I aimed for, and it turns out to be more useful than a fake verdict.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-i-built&#34;&gt;What I built&lt;/h2&gt;&#xA;&lt;p&gt;The project has two parts: the skill itself, plus a monorepo for the SAP MCP servers it depends on.&lt;/p&gt;&#xA;&lt;p&gt;The skill is &lt;strong&gt;&lt;a href=&#34;https://github.com/marianfoo/sap-api-policy-skill&#34;&gt;&lt;code&gt;sap-api-policy-evidence&lt;/code&gt;&lt;/a&gt;&lt;/strong&gt;. You install it in Claude Code, Cursor, or Codex with &lt;a href=&#34;https://github.com/vercel-labs/skills&#34;&gt;&lt;code&gt;npx skills&lt;/code&gt;&lt;/a&gt;. It does the reasoning. It frames your scenario into facts, classifies it against the policy clauses, gathers evidence, and writes the assessment.&lt;/p&gt;&#xA;&lt;p&gt;The skill reads its evidence from five SAP MCP servers. Three of them I put into one npm-workspaces monorepo, &lt;strong&gt;&lt;a href=&#34;https://github.com/marianfoo/sap-mcp-servers&#34;&gt;&lt;code&gt;sap-mcp-servers&lt;/code&gt;&lt;/a&gt;&lt;/strong&gt;, with a shared SAP login module: the &lt;strong&gt;Business Accelerator Hub&lt;/strong&gt; server (is this a Published API?), &lt;strong&gt;SAP Notes&lt;/strong&gt; (is it explicitly not permitted?), and the &lt;strong&gt;Road Map Explorer&lt;/strong&gt; (future plans only, never current permission).&lt;/p&gt;&#xA;&lt;p&gt;The other two are separate servers I already had. One is my &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;&lt;strong&gt;SAP Docs MCP server&lt;/strong&gt;&lt;/a&gt;, for SAP Help and the Architecture Center, including released-object status and endorsed pathways. It also has a hosted URL, so you do not have to run it yourself. The other is &lt;a href=&#34;https://blog.zeis.de/posts/2026-04-27-arc-1/&#34;&gt;&lt;strong&gt;ARC-1&lt;/strong&gt;&lt;/a&gt;, my ADT MCP server, used read-only here for checks against a live SAP system.&lt;/p&gt;&#xA;&lt;p&gt;The skill does the thinking. The MCP servers bring the evidence. You can wire up all of them for the best picture, or just a few. If a source is missing, the skill says so and lowers its confidence.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-an-assessment-contains&#34;&gt;What an assessment contains&lt;/h2&gt;&#xA;&lt;p&gt;Every result has the same shape, so you can compare them and file them.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A fixed &lt;strong&gt;assessment label&lt;/strong&gt;: &lt;code&gt;Likely aligned&lt;/code&gt;, &lt;code&gt;Likely not aligned&lt;/code&gt;, &lt;code&gt;Needs SAP confirmation&lt;/code&gt;, or &lt;code&gt;Not assessable from provided facts&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;One &lt;strong&gt;confidence level&lt;/strong&gt;: &lt;code&gt;high&lt;/code&gt;, &lt;code&gt;medium&lt;/code&gt;, or &lt;code&gt;low&lt;/code&gt;. It only reaches &lt;code&gt;high&lt;/code&gt; when strong sources back the finding, like API Hub and an authenticated SAP Notes session.&lt;/li&gt;&#xA;&lt;li&gt;An &lt;strong&gt;evidence table&lt;/strong&gt; that lists every source, what it said, how authoritative it is, and when it was retrieved.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Residual risk&lt;/strong&gt;, the &lt;strong&gt;missing facts&lt;/strong&gt; that would most improve confidence, and &lt;strong&gt;questions for SAP&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;A disclaimer at the top and the bottom that this is not legal advice. This is not boilerplate. It is the main idea.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;four-examples&#34;&gt;Four examples&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;1. The ODP-RFC pipeline you should check before June 9.&lt;/strong&gt; Extracting BW/4HANA data into a lake or warehouse over ODP-RFC through a third-party tool is the classic case. It is also urgent, because the enforcement patch lands on &lt;a href=&#34;https://theobald-software.com/en/blog/sap-note-3255746&#34;&gt;June 9, 2026&lt;/a&gt;, based on SAP Note 3255746. Here is the short version of a real run, with the &lt;a href=&#34;https://github.com/marianfoo/sap-api-policy-skill/blob/main/examples/01-odp-rfc-extraction.md&#34;&gt;full report&lt;/a&gt; in the repo:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Assessment:** Likely not aligned&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Confidence:** high&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Date:** 2026-06-02&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Why: ODP-RFC for customer or third-party access to ABAP systems that contain&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;PI_BASIS, SAP BW, or SAP BW/4HANA (on-premise or private cloud) is prohibited&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;per SAP Note 3255746. SAP Note 3439624 ships a self-assessment tool, and a&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;June 2026 security patch blocks unpermitted calls. The API Hub returned no&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;published artifact for ODP-RFC or RODPS_REPL.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Endorsed alternatives: SAP Business Data Cloud with Delta Sharing (including&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;BDC Connect for Snowflake), ODP-OData, or SLT where licensed.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Questions for SAP: confirm the migration target for this data scope, and the&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;deadline relative to the June 2026 blocking patch.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That is more useful than &amp;ldquo;not allowed&amp;rdquo;. It cites the Note, points to SAP&amp;rsquo;s own self-assessment, names real alternatives, and gives you the questions to ask.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;2. A third-party AI agent reaching into SAP.&lt;/strong&gt; This is the §2.2.2 worry. It is the clause that touches tools like Agentforce, Copilot, ServiceNow, Workday Illuminate, and Celonis. The skill does not flag every agent as forbidden. A read-only developer assistant is fine. A deterministic RPA bot is out of scope (FAQ Q40). But an autonomous agent that plans business-API call sequences through a custom gateway lands on &lt;code&gt;Likely not aligned&lt;/code&gt;, and the report points to the endorsed pathway, like the MCP Gateway on SAP Integration Suite, or Joule with the Agent Gateway. Here is the short version of a real run, with the &lt;a href=&#34;https://github.com/marianfoo/sap-api-policy-skill/blob/main/examples/02-third-party-ai-agent.md&#34;&gt;full report&lt;/a&gt; in the repo:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Assessment:** Likely not aligned&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Confidence:** high&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Date:** 2026-06-02&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Why: API_SALES_ORDER_SRV itself is published and active, but an autonomous&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;third-party AI agent that plans and executes read and create calls through a&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;custom-only MCP gateway triggers the agentic-AI control in section 2.2.2(a).&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;No SAP-endorsed path or written authorization was provided.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Endorsed path: expose the API through the MCP Gateway on SAP Integration Suite,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;or A2A with Joule and the Agent Gateway, instead of a custom gateway.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The point is the nuance, not a blanket yes or no.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;3. &amp;ldquo;Which of these are we even allowed to use?&amp;rdquo;&lt;/strong&gt; This is the DSAG complaint turned into a workflow. You give the skill a list of interfaces, for example &lt;code&gt;API_SALES_ORDER_SRV&lt;/code&gt;, &lt;code&gt;RFC_READ_TABLE&lt;/code&gt;, &lt;code&gt;SD_SALESDOCUMENT_CREATE&lt;/code&gt;, ODP-RFC, and &lt;code&gt;I_SalesDocument&lt;/code&gt;. It returns one timestamped table: status per interface, the evidence behind it, the documented alternative, and which rows still need a full assessment. Here is the short version of a real run, with the &lt;a href=&#34;https://github.com/marianfoo/sap-api-policy-skill/blob/main/examples/03-inventory-scan.md&#34;&gt;full report&lt;/a&gt; in the repo:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Assessment:** Likely not aligned   **Confidence:** high&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Portfolio: 1 prohibited, 1 discouraged, 1 not-found, 2 released or published.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ODP-RFC              Prohibited    SAP Note 3255746&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;RFC_READ_TABLE       Discouraged   SAP Note 382318 (not a released API)&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SD_SALESDOCUMENT_*   Not found     no released or published evidence&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;API_SALES_ORDER_SRV  Published     SAP Business Accelerator Hub&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;I_SalesDocument      Released (A)  released-object data, Clean Core A&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;There is no SAP-published master list, so this is the closest thing you can build yourself. It is clearly marked as evidence captured on a date, not an SAP-approved allowlist.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;4. The same API, but a normal integration.&lt;/strong&gt; This is the positive case, and a good contrast to example 2. We sync about 500 sales orders per day from Salesforce into S/4HANA Cloud using Boomi, calling the standard Sales Order OData API (&lt;code&gt;API_SALES_ORDER_SRV&lt;/code&gt;) with OAuth 2.0. It is the same API as in example 2, but a deterministic middleware flow instead of an autonomous AI agent. Here is the short version of a real run, with the &lt;a href=&#34;https://github.com/marianfoo/sap-api-policy-skill/blob/main/examples/04-published-api-ipaas.md&#34;&gt;full report&lt;/a&gt; in the repo:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Assessment:** Likely aligned&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Confidence:** medium&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;**Date:** 2026-06-02&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Why: API_SALES_ORDER_SRV is active and published on the SAP Business&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Accelerator Hub for S/4HANA Cloud (OData V2, OAuth 2.0, not deprecated). The&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;~500 orders/day is bounded operational use, not bulk extraction, and there is&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;no AI agent planning the calls. So the SAP-facing API and the usage pattern&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;both look documented.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Confidence is medium, not high, because tenant-specific rate limits, the&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;communication arrangement, and quotas are not visible in public sources. SAP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;or tenant operations would confirm those and move it to high.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The contrast is the point. Example 2 and this one call the exact same Sales Order API. The assessment changes because the usage pattern is different, not the API. That is the whole idea of the policy. The question is the API surface and how you use it, not the tool.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-real-value-evidence-you-can-take-to-sap&#34;&gt;The real value: evidence you can take to SAP&lt;/h2&gt;&#xA;&lt;p&gt;This is the part I care about most. It is also why a non-definitive tool beats a fake-confident one.&lt;/p&gt;&#xA;&lt;p&gt;SAP&amp;rsquo;s own enforcement posture is dialogue first, not penalties. For existing integrations, SAP says it wants to make contact before it throttles anything (FAQ Q11, Q19). So the conversation is coming. The only question is whether you walk into it prepared or guessing.&lt;/p&gt;&#xA;&lt;p&gt;An evidence report changes your position.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;You know your own exposure before SAP does. You can inventory your interfaces and classify them now, instead of finding out which ones matter when a pipe breaks.&lt;/li&gt;&#xA;&lt;li&gt;You can have a specific conversation. &amp;ldquo;Here is interface X, here is its API Hub status on this date, here is the relevant Note, here is our usage pattern and volume, please confirm.&amp;rdquo; That is a very different meeting than &amp;ldquo;we think we are probably fine.&amp;rdquo;&lt;/li&gt;&#xA;&lt;li&gt;You can push back where the evidence is on your side. If something is a Published API used within Documented Use, you have the sourced proof in hand. That helps when a partner solution or your own extension gets questioned.&lt;/li&gt;&#xA;&lt;li&gt;You can escalate the real gaps. Where no documented API exists, the report says so and points you to the SAP Customer Influence portal, instead of quietly relying on an undocumented interface.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;It also works next to SAP&amp;rsquo;s own tools, not against them. SAP Note 3439624 self-assesses ODP-RFC. The ABAP Test Cockpit Cloud Readiness Check finds non-released dependencies. The skill goes wider. It can cover any interface, the policy reasoning around it, and the endorsed alternative, and it gives you something you can put in front of your account team.&lt;/p&gt;&#xA;&lt;h2 id=&#34;it-knows-its-limits&#34;&gt;It knows its limits&lt;/h2&gt;&#xA;&lt;p&gt;That honesty is built in, not just promised. The skill sends legal, commercial, and roadmap questions to SAP instead of guessing. It lowers its confidence when strong sources are not connected. It never asks for or stores credentials or business data. ARC-1 stays read-only. If you ask for a plain yes or no, you get the disclaimer, not a number. I tested all of this across 22 evaluation scenarios that cover every branch of the policy, including cases built to make it over-flag or under-flag.&lt;/p&gt;&#xA;&lt;h2 id=&#34;try-it&#34;&gt;Try it&lt;/h2&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;npx skills add marianfoo/sap-api-policy-skill --skill sap-api-policy-evidence&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Then wire up the MCP servers. Most run with &lt;code&gt;npx -y&lt;/code&gt;, SAP Docs has a hosted URL, and the three authenticated servers share one SAP login. The full setup, including auth, MFA, and the single-login flow, is in &lt;a href=&#34;https://github.com/marianfoo/sap-api-policy-skill/blob/main/MCP_SETUP.md&#34;&gt;MCP_SETUP.md&lt;/a&gt;. The SAP API Hub and an authenticated SAP Notes session are what unlock &lt;code&gt;high&lt;/code&gt;-confidence assessments. With fewer servers it still works, and it tells you what was missing.&lt;/p&gt;&#xA;&lt;p&gt;One honest warning before you start: this is not a simple setup, and some of the servers read SAP sites through a browser login, not through official public APIs. The SAP Notes and Business Accelerator Hub servers work this way. So use them at your own risk, and check first that this is fine for you and your organization.&lt;/p&gt;&#xA;&lt;p&gt;Then ask in plain language, for example: &amp;ldquo;Is it OK under the API policy to extract our BW/4HANA data into Snowflake nightly via ODP-RFC?&amp;rdquo; Then read the evidence.&lt;/p&gt;&#xA;&lt;h2 id=&#34;open-source-and-honest-about-what-it-is&#34;&gt;Open source, and honest about what it is&lt;/h2&gt;&#xA;&lt;p&gt;Both repos are public and use permissive licenses. The skill is MIT, the servers are Apache-2.0. The servers are published to npm with build provenance, and you can self-host everything if you need data residency. Issues and contributions are welcome.&lt;/p&gt;&#xA;&lt;p&gt;To be honest, I would rather not need this at all. If SAP gave clear guidance on which interfaces are affected, we would not be left in this state of uncertainty. Until that changes, this is the best I have found. At least it gathers the sources for you, automatically and in one place, so you can decide from there.&lt;/p&gt;&#xA;&lt;p&gt;You still cannot get a binding compliance verdict from a tool, and you should be careful with anyone who promises one. But you can replace hallway guesswork with current, sourced evidence and a clear list of what to confirm with SAP. Getting that clarity across your whole landscape, in minutes, is the real win. It is also a much stronger position to argue from.&lt;/p&gt;&#xA;&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/doc/sap-api-policy/latest/en-US/API_Policy_latest.pdf&#34;&gt;SAP API Policy v.4.2026a (PDF)&lt;/a&gt;: the policy itself, plus the FAQ it references.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://theobald-software.com/en/blog/sap-note-3255746&#34;&gt;SAP Note 3255746: data integration without ODP-RFC&lt;/a&gt;: the ODP-RFC prohibition and the June 9, 2026 enforcement date, with SAP Note 3439624 as the self-assessment tool.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.cio.com/article/4166172/dsag-criticizes-saps-new-api-policy.html&#34;&gt;CIO: DSAG criticizes SAP&amp;rsquo;s new API policy&lt;/a&gt;: the transparency and &amp;ldquo;which interfaces are affected?&amp;rdquo; concerns.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.theregister.com/2026/04/29/new_sap_api_policy_provokes/&#34;&gt;The Register: AI clause in new SAP API policy provokes lock-in concern&lt;/a&gt;: §2.2.2, lock-in, and SAP&amp;rsquo;s response.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.forrester.com/blogs/sap-is-attempting-to-become-the-gatekeeper-of-enterprise-ai-cios-should-push-back/&#34;&gt;Forrester: SAP is attempting to become the gatekeeper of enterprise AI, CIOs should push back&lt;/a&gt;: the analyst pushback.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://diginomica.com/sap-sapphire-2026-sap-cto-philipp-herzig-saps-api-policy-changes-and-why-organizational-memory&#34;&gt;diginomica: Sapphire 2026, SAP CTO Philipp Herzig on the API policy changes&lt;/a&gt;: SAP&amp;rsquo;s framing.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;Project:&lt;/strong&gt; &lt;a href=&#34;https://github.com/marianfoo/sap-api-policy-skill&#34;&gt;&lt;code&gt;sap-api-policy-evidence&lt;/code&gt; skill&lt;/a&gt; · &lt;a href=&#34;https://github.com/marianfoo/sap-mcp-servers&#34;&gt;&lt;code&gt;sap-mcp-servers&lt;/code&gt; (MCP servers)&lt;/a&gt; · &lt;a href=&#34;https://github.com/vercel-labs/skills&#34;&gt;&lt;code&gt;npx skills&lt;/code&gt; CLI&lt;/a&gt;&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>Before You Upgrade S/4HANA: Static UI5 Checks with MCP</title>
      <link>https://blog.zeis.de/posts/2026-05-20-ui5-upgrade-mcp/</link>
      <pubDate>Wed, 20 May 2026 23:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-05-20-ui5-upgrade-mcp/</guid>
      <description>&lt;p&gt;Series note: This post is part of my &lt;a href=&#34;https://blog.zeis.de/tags/ai-abap-development-series/&#34;&gt;AI ABAP development series&lt;/a&gt;. It reuses the legacy UI5 app from the &lt;a href=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/&#34;&gt;SEGW to RAP migration demo&lt;/a&gt;, but this time the focus is only on the UI5 version upgrade problem.&lt;/p&gt;&#xA;&lt;p&gt;In the SEGW to RAP post I used a deliberately old freestyle UI5 app as migration material. It runs on SAPUI5 1.84.59 and contains many patterns that were normal in older projects: &lt;code&gt;jQuery.sap.require&lt;/code&gt;, global formatters, synchronous bootstrap, Belize theme, older manifest versions, and a few small controller workarounds.&lt;/p&gt;&#xA;&lt;p&gt;That is a useful demo app because it is close to the kind of thing you find during S/4HANA upgrades. The backend migration is one problem, but the UI5 version jump is another one.&lt;/p&gt;&#xA;&lt;p&gt;The process should look something like this: First, you identify the old and new UI5 versions. Then you read through the changelogs and What&amp;rsquo;s New pages to see what has changed. Next check which APIs have been deprecated or which themes have been removed, and search the documentation for possible replacements. Then you apply those findings to the app and start the app to see if the fixes work.&lt;br&gt;&#xA;But usually you start the app with the new version and hope for the best and fix things you find there.&lt;/p&gt;&#xA;&lt;p&gt;That works, but it is a lot of manual context switching. The release notes are broad, the app only uses a small part of UI5, and the important question is not &amp;ldquo;what changed in UI5?&amp;rdquo;. The useful question is:&lt;/p&gt;&#xA;&lt;p&gt;What changed in UI5 that matters for this app?&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Before You Upgrade S/4HANA static UI5 checks with MCP.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-20-ui5-upgrade-mcp/images/linkedin-post.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-changed&#34;&gt;What Changed&lt;/h2&gt;&#xA;&lt;p&gt;I added a new &lt;code&gt;ui5_version_diff&lt;/code&gt; tool to my &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;SAP Docs MCP server&lt;/a&gt; in &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs/pull/47&#34;&gt;mcp-sap-docs PR #47&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The tool is backed by &lt;a href=&#34;https://github.com/marianfoo/ui5-lib-diff&#34;&gt;ui5-lib-diff&lt;/a&gt;. A small change in &lt;a href=&#34;https://github.com/marianfoo/ui5-lib-diff/pull/11&#34;&gt;ui5-lib-diff PR #11&lt;/a&gt; now publishes a static JSON API for tools.&lt;/p&gt;&#xA;&lt;p&gt;The important part is that the MCP server does not send HTTP requests at runtime. During setup it downloads the &lt;code&gt;all-changes.json&lt;/code&gt; bundle once. At runtime the tool reads the local bundle and filters it by version range, change type, UI5 library, or query text.&lt;/p&gt;&#xA;&lt;p&gt;That makes it much more useful for agents. The UI5 Lib Diff app is still great for humans, because you can visually compare versions at &lt;a href=&#34;https://ui5-lib-diff.marianzeis.de/&#34;&gt;ui5-lib-diff.marianzeis.de&lt;/a&gt;. But an agent needs structured data it can filter without opening a client-rendered UI route.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;UI5 version diff, project info, and version info tool calls in the upgrade run.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-20-ui5-upgrade-mcp/images/tool-calls-project-info.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The second part is the official &lt;a href=&#34;https://github.com/UI5/mcp-server&#34;&gt;UI5 MCP server&lt;/a&gt; from SAP. That server can inspect a local UI5 project and run UI5-specific checks.&lt;/p&gt;&#xA;&lt;p&gt;This is important: these checks run against the app source code in a local checkout, for example the version cloned from your Git server. They are not executed against the deployed app in the SAP system or against a running launchpad tile. The deployed app still needs runtime testing later, but the first evidence can come from the local project before that.&lt;/p&gt;&#xA;&lt;p&gt;In this run the useful tools were:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;get_project_info&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;get_version_info&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;run_ui5_linter&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;run_manifest_validation&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;optionally &lt;code&gt;get_api_reference&lt;/code&gt; and &lt;code&gt;get_guidelines&lt;/code&gt; for follow-up details&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;So the split is clear:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;SAP Docs MCP says what changed between UI5 versions.&lt;/li&gt;&#xA;&lt;li&gt;UI5 MCP says what the local app actually uses and what fails.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;That combination is the interesting part.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-run&#34;&gt;The Run&lt;/h2&gt;&#xA;&lt;p&gt;For the showcase I used a local clone of the same &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/legacy-ui5-app&#34;&gt;legacy UI5 app&lt;/a&gt; from the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap&#34;&gt;arc-1-segw-to-rap repo&lt;/a&gt;. I also used the workflow in &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/skills/ui5-versions-upgrade.md&#34;&gt;&lt;code&gt;ui5-versions-upgrade.md&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The prompt was basically:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;i want to upgrade the legacy-ui5-app from version&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;use ui5-versions-upgrade.md to produce a good markdown&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The skill tells the agent to first establish the scope, then inspect the project, then cross-check deprecations with the linter and code, then look for fixes and relevant features. It also tells the agent not to dump the full changelog into the report.&lt;/p&gt;&#xA;&lt;p&gt;For the demo app the report found:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;current version: SAPUI5 1.84.59&lt;/li&gt;&#xA;&lt;li&gt;target version: SAPUI5 1.147.2&lt;/li&gt;&#xA;&lt;li&gt;resolved diff range in the local bundle: 1.84.56 to 1.147.0&lt;/li&gt;&#xA;&lt;li&gt;339 versions in range&lt;/li&gt;&#xA;&lt;li&gt;3,540 features&lt;/li&gt;&#xA;&lt;li&gt;15,249 fixes&lt;/li&gt;&#xA;&lt;li&gt;985 deprecations&lt;/li&gt;&#xA;&lt;li&gt;961 SAPUI5 What&amp;rsquo;s New entries&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;That sounds like too much information, and it is. The point of the workflow is to reduce it.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;UI5 linter and manifest validation results from the upgrade run.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-20-ui5-upgrade-mcp/images/linter-manifest-validation.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The UI5 linter and manifest validation made the report concrete. It did not just say that some API somewhere is deprecated. It found issues in this app:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;jQuery.sap.require&lt;/code&gt; and &lt;code&gt;jQuery.sap.declare&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;global &lt;code&gt;sap.*&lt;/code&gt; usage&lt;/li&gt;&#xA;&lt;li&gt;synchronous bootstrap&lt;/li&gt;&#xA;&lt;li&gt;missing async component configuration&lt;/li&gt;&#xA;&lt;li&gt;old &lt;code&gt;sap_belize&lt;/code&gt; theme and &lt;code&gt;themelib_sap_belize&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;sap.m.MessagePage&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;manifest &lt;code&gt;_version&lt;/code&gt; 1.40.0&lt;/li&gt;&#xA;&lt;li&gt;old &lt;code&gt;minUI5Version&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;ambiguous XML event handlers&lt;/li&gt;&#xA;&lt;li&gt;old UI5 Tooling setup&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;That is exactly the kind of list I want before I start the live browser test. It does not replace testing the deployed app, but it removes a lot of blind work before testers touch the running application.&lt;/p&gt;&#xA;&lt;h2 id=&#34;narrowing-the-changelog&#34;&gt;Narrowing the Changelog&lt;/h2&gt;&#xA;&lt;p&gt;The broad range query is only the starting point. After that the agent used narrower calls:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;types=[&amp;quot;DEPRECATED&amp;quot;]&lt;/code&gt; to focus on migration blockers&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;types=[&amp;quot;FEATURE&amp;quot;]&lt;/code&gt; with &lt;code&gt;ui5_library=&amp;quot;sap.m&amp;quot;&lt;/code&gt; or &lt;code&gt;sap.f&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;query=&amp;quot;jQuery.sap&amp;quot;&lt;/code&gt; to inspect relevant deprecations&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;query=&amp;quot;setTimeout&amp;quot;&lt;/code&gt; to see if a local workaround matches a framework fix&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Filtered UI5 version diff calls for features and deprecations.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-20-ui5-upgrade-mcp/images/filtered-version-diff.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;That last point is the more interesting long-term use case. During upgrades we often carry workarounds forward because nobody knows if the original UI5 bug still exists. With a searchable version diff, an agent can look for a symptom or API and then check whether a fix landed between the old and new version.&lt;/p&gt;&#xA;&lt;p&gt;It still has to verify the local code. A changelog entry is not proof that a workaround can be deleted. But it gives the agent a much better starting point than asking it to guess from memory.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;UI5 version info and a filtered fix query for the legacy app upgrade.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-20-ui5-upgrade-mcp/images/version-info-and-fix-query.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The generated report is here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/legacy-ui5-app-upgrade.md&#34;&gt;legacy-ui5-app-upgrade.md&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The report is not a replacement for a real migration. It is the first step: concrete evidence for what may need to change. For this demo it already produced a useful edit plan: update tooling, switch theme, migrate the manifest, enable async loading, clean module usage, replace deprecated controls, then rerun linter and manifest validation.&lt;/p&gt;&#xA;&lt;p&gt;The next step can use the same MCP tools again, but now for implementation. You do not have to apply every finding at once. You can ask the agent to fix only the theme and manifest issues, only the &lt;code&gt;jQuery.sap.*&lt;/code&gt; usage, or the full list. That is basically the same pattern I showed in the SEGW to RAP post when the legacy freestyle UI5 app was converted into a &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/modern-ui5-ts-app&#34;&gt;modern UI5 TypeScript app&lt;/a&gt;: inspect first, use UI5-specific tools, implement, then rerun linting, manifest validation, type checks, and browser checks.&lt;/p&gt;&#xA;&lt;p&gt;If a finding needs more explanation, the same SAP Docs MCP server can still search SAPUI5 documentation and fetch more detail. For API-level replacement details, the UI5 MCP server can also use &lt;code&gt;get_api_reference&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-i-like-this-pattern&#34;&gt;Why I Like This Pattern&lt;/h2&gt;&#xA;&lt;p&gt;The useful shift is that the model is no longer asked to &amp;ldquo;know UI5 upgrades&amp;rdquo;. It is given tools that expose the right context:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;the version diff tells it what changed&lt;/li&gt;&#xA;&lt;li&gt;the project info tells it what the app uses&lt;/li&gt;&#xA;&lt;li&gt;the linter tells it what is actually wrong&lt;/li&gt;&#xA;&lt;li&gt;the manifest validator tells it what the framework accepts&lt;/li&gt;&#xA;&lt;li&gt;the docs tools can fill gaps when a finding needs detail&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;That is a much better workflow than manually reading release notes until you hope you found everything.&lt;/p&gt;&#xA;&lt;p&gt;It is especially useful for larger version jumps, for example during S/4HANA upgrades where the UI5 version changes a lot. But I think it also helps for smaller minor upgrades. Even then, you want to know if a workaround is still needed, if a deprecation starts to matter, or if a newer UI5 feature lets you simplify code.&lt;/p&gt;&#xA;&lt;p&gt;The important boundary is still the same: the report is a first pass, not the final migration. You still need to edit, run the app, test the flows, and check the actual behavior. But the first pass can now be app-specific evidence instead of a generic changelog review, and the same tools can then help with the actual changes.&lt;/p&gt;&#xA;&lt;p&gt;For me that is the real value of MCP in SAP development. Not magic. Better context at the point where the model needs to reason.&lt;/p&gt;&#xA;&lt;h2 id=&#34;references-and-links&#34;&gt;References and Links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/&#34;&gt;From SEGW and Legacy UI5 to RAP with ARC-1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap&#34;&gt;arc-1-segw-to-rap repo&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/legacy-ui5-app&#34;&gt;legacy UI5 app&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/skills/ui5-versions-upgrade.md&#34;&gt;ui5-versions-upgrade.md skill&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/legacy-ui5-app-upgrade.md&#34;&gt;generated legacy UI5 upgrade report&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;mcp-sap-docs repo&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs/pull/47&#34;&gt;mcp-sap-docs PR #47: load UI5 diffs from local bundle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/ui5-lib-diff&#34;&gt;ui5-lib-diff repo&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/ui5-lib-diff/pull/11&#34;&gt;ui5-lib-diff PR #11: publish static UI5 diff bundle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://ui5-lib-diff.marianzeis.de/&#34;&gt;UI5 Lib Diff app&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://ui5-lib-diff.marianzeis.de/api/v1/manifest.json&#34;&gt;UI5 Lib Diff static API manifest&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/UI5/mcp-server&#34;&gt;UI5 MCP server GitHub repo&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.npmjs.com/package/%40ui5/mcp-server&#34;&gt;@ui5/mcp-server on npm&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/give-your-ai-agent-some-tools-introducing-the-ui5-mcp-server/ba-p/14200825&#34;&gt;SAP Community: Introducing the UI5 MCP Server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://ui5.sap.com/#/releasenotes.html&#34;&gt;SAPUI5 release notes&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/whats-new/67f60363b57f4ac0b23efd17fa192d60?locale=en-US&#34;&gt;SAPUI5 What&amp;rsquo;s New Viewer&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>ABAP Development Automation with ARC-1 and GitHub Workflows</title>
      <link>https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/</link>
      <pubDate>Tue, 12 May 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/</guid>
      <description>&lt;p&gt;Series note: This post is part of my &lt;a href=&#34;https://blog.zeis.de/tags/ai-abap-development-series/&#34;&gt;AI ABAP development series&lt;/a&gt;. In the previous posts I introduced &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt;, then used it from BTP, Copilot Studio, Joule Studio, and a SEGW to RAP migration.&lt;/p&gt;&#xA;&lt;p&gt;This post is about GitHub workflows as an ARC-1 development automation surface.&lt;/p&gt;&#xA;&lt;p&gt;ABAP teams already have strong SAP-side tooling: ATC, Code Inspector, ST22, ADT, and the activated source in the SAP system. GitHub has a different strength: pull requests, review comments, checks, labels, issues, and automation.&lt;/p&gt;&#xA;&lt;p&gt;The problem is that those worlds usually do not meet cleanly. &lt;a href=&#34;https://abapgit.org/&#34;&gt;abapGit&lt;/a&gt; can push ABAP source to GitHub, &lt;a href=&#34;https://abaplint.org/&#34;&gt;abaplint&lt;/a&gt; can run static checks, and Copilot or Claude can review a diff. But without access to the SAP system, the automation only sees text. It cannot run ABAP Unit, call ATC, compare against the activated object, inspect ST22, or verify what the SAP system actually knows.&lt;/p&gt;&#xA;&lt;p&gt;The underlying idea comes from the &lt;a href=&#34;https://docs.heliconialabs.com/patterns-for-using-llms-in-abap-development.pdf&#34;&gt;Patterns for using LLMs in ABAP development&lt;/a&gt; document by Lars Hvam from Heliconia Labs. The relevant pattern is section 2.7, Git / Off-Stack with read-only MCP. ABAP source lives in Git. Pull requests, CI/CD, static analysis, and human review stay in the Git workflow. The MCP server gives the LLM read-only context from the SAP system, but does not let it write directly into the system.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Heliconia Labs Git / Off-Stack with read-only MCP pattern showing Git, CI/CD, SAP, and a read-only ADT MCP server.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/patterns-git-offstack-mcp.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;So I created a small sample repository for this pattern: &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review&#34;&gt;github.com/arc-mcp/arc-1-abap-cicd-review&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This is my ARC-1 implementation of the idea. GitHub is the workflow surface. abapGit connects the repository and the SAP system. ARC-1 is the SAP automation gateway that lets GitHub workflows execute SAP-side checks and gives AI reviewers read-only SAP context through MCP.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-the-sample-shows&#34;&gt;What The Sample Shows&lt;/h2&gt;&#xA;&lt;p&gt;The sample repository contains a small ABAP package &lt;code&gt;ZARC1_DEMO&lt;/code&gt; in abapGit format. The package is deliberately small. The interesting part is what can be automated around it when GitHub can reach SAP through ARC-1.&lt;/p&gt;&#xA;&lt;p&gt;It covers three development automation scenarios:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;PR checks for ABAP code: abaplint, ABAP Unit, and ATC.&lt;/li&gt;&#xA;&lt;li&gt;PR review with SAP context: Copilot and Claude can review with live SAP reads instead of only the diff.&lt;/li&gt;&#xA;&lt;li&gt;Operational follow-up: ARC-1 can check ST22 dumps on a schedule, create GitHub issues for new dumps, and trigger a deeper investigation from a label.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The repo has six small workflow files: &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/pr.yml&#34;&gt;&lt;code&gt;pr.yml&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/sap-tests.yml&#34;&gt;&lt;code&gt;sap-tests.yml&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/copilot-review-trigger.yml&#34;&gt;&lt;code&gt;copilot-review-trigger.yml&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/claude-review-trigger.yml&#34;&gt;&lt;code&gt;claude-review-trigger.yml&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/sap-dump-triage.yml&#34;&gt;&lt;code&gt;sap-dump-triage.yml&lt;/code&gt;&lt;/a&gt;, and &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/sap-dump-deep-dive.yml&#34;&gt;&lt;code&gt;sap-dump-deep-dive.yml&lt;/code&gt;&lt;/a&gt;. ARC-1 is the common backend. GitHub Actions is only the automation surface.&lt;/p&gt;&#xA;&lt;h2 id=&#34;architecture-and-setup&#34;&gt;Architecture And Setup&lt;/h2&gt;&#xA;&lt;p&gt;The architecture follows the Git / Off-Stack with read-only MCP pattern:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Developer / IDE / LLM&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; local ABAP files&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; GitHub repository&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; pull requests, code reviews, CI/CD&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; abapGit&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; SAP system&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;GitHub Actions / review automation&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; ARC-1 MCP endpoint on SAP BTP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; read-only ADT context from the SAP system&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The Git repository is the collaboration surface. It contains source files, pull requests, review comments, labels, and CI/CD checks. That is where the AI can propose changes and where a human keeps the gate.&lt;/p&gt;&#xA;&lt;p&gt;The SAP system remains the source of truth for activated ABAP source, syntax checks, dumps, package content, and system-specific context. GitHub has the PR diff, but GitHub is not the runtime.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 sits between GitHub and SAP. In my setup it runs on SAP BTP Cloud Foundry. GitHub Actions calls the ARC-1 &lt;code&gt;/mcp&lt;/code&gt; endpoint over HTTPS with an API key. ARC-1 validates the key profile and then connects to the SAP system through the BTP destination. The technical SAP user is configured in that destination, not in GitHub.&lt;/p&gt;&#xA;&lt;p&gt;GitHub runners and AI tools do not get SAP credentials. They only get the ARC-1 URL and a scoped API key. The SAP system itself is not exposed to GitHub runners.&lt;/p&gt;&#xA;&lt;p&gt;The API key used in the demo has a &lt;code&gt;viewer-sql&lt;/code&gt; profile. That means read access, SQL/table preview where needed, diagnostics, navigation, and linting. It does not expose write tools like &lt;code&gt;SAPWrite&lt;/code&gt;, &lt;code&gt;SAPActivate&lt;/code&gt;, &lt;code&gt;SAPManage&lt;/code&gt;, &lt;code&gt;SAPTransport&lt;/code&gt;, or &lt;code&gt;SAPGit&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;That last point matters. I do not want the first version of this pattern to be &amp;ldquo;AI writes ABAP from a PR comment&amp;rdquo;. The safer and more useful first version is:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;AI can read the real SAP system.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;AI can explain what it found.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;AI can propose changes in a PR review.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Humans still decide what gets applied.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The setup has five parts.&lt;/p&gt;&#xA;&lt;p&gt;First, get the ABAP source into GitHub with abapGit. The exact setup depends on the system and repository authentication. The important point is that ABAP objects are available as normal files in GitHub, and approved changes can later be pulled back into SAP through the normal abapGit process.&lt;/p&gt;&#xA;&lt;p&gt;Second, deploy ARC-1. For this sample I use the BTP Cloud Foundry deployment because it gives GitHub Actions a public HTTPS endpoint while the SAP backend remains behind BTP connectivity. ARC-1 needs a destination to the ABAP system. The technical user is configured there and should only have the permissions needed for the checks you want to run. ARC-1 then adds the API key profile on top.&lt;/p&gt;&#xA;&lt;p&gt;Third, configure GitHub Actions secrets and variables:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ARC1_URL&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ARC1_API_KEY&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ANTHROPIC_API_KEY&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;COPILOT_TRIGGER_PAT&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;ARC1_URL&lt;/code&gt; points to the ARC-1 endpoint. &lt;code&gt;ARC1_API_KEY&lt;/code&gt; is used by the SAP test gate and the Claude workflows. &lt;code&gt;ANTHROPIC_API_KEY&lt;/code&gt; is needed for Claude Code Action. &lt;code&gt;COPILOT_TRIGGER_PAT&lt;/code&gt; is needed for the Copilot trigger workflow because comments posted by the default &lt;code&gt;GITHUB_TOKEN&lt;/code&gt; do not trigger &lt;code&gt;@copilot&lt;/code&gt; mentions.&lt;/p&gt;&#xA;&lt;p&gt;Fourth, configure Copilot Coding Agent. In the repository settings, the Copilot Cloud Agent gets an MCP configuration for ARC-1. The important detail is the tool allowlist: Copilot should see the read-side tools it needs for review, not the write-side tools.&lt;/p&gt;&#xA;&lt;p&gt;Fifth, decide which workflows you actually want. For a first rollout I would start with abaplint, the SAP test gate, and one AI review path. The scheduled dump check is useful because it helps you see new runtime problems before someone reports them manually, but it is a separate operational pattern. You do not need to enable everything on day one.&lt;/p&gt;&#xA;&lt;h2 id=&#34;pr-automation-layers&#34;&gt;PR Automation Layers&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Layer 1: abaplint&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The static layer is intentionally boring.&lt;/p&gt;&#xA;&lt;p&gt;Every pull request runs &lt;a href=&#34;https://abaplint.org/&#34;&gt;abaplint&lt;/a&gt; through &lt;a href=&#34;https://github.com/reviewdog/reviewdog&#34;&gt;reviewdog&lt;/a&gt;. Findings appear as check annotations, inline comments where GitHub allows it, and a sticky summary comment. The workflow gates only on findings introduced by the PR diff. Existing findings stay visible, but they do not block a PR that did not create them.&lt;/p&gt;&#xA;&lt;p&gt;If abaplint can catch it, abaplint should catch it. It is fast, deterministic, and basically free apart from GitHub Actions minutes.&lt;/p&gt;&#xA;&lt;p&gt;In the sample PR, abaplint found existing issues in the class and test class. That is useful, but it did not catch the main semantic issue in the PR: a direct &lt;code&gt;SELECT&lt;/code&gt; from &lt;code&gt;MARA&lt;/code&gt; added inside a task service method. The code is syntactically valid. The problem is architectural and Clean Core related.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Layer 2: ABAP Unit and ATC&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The next layer is still not AI. Here ARC-1 is simply the gateway connector from GitHub Actions into SAP.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/sap-tests.yml&#34;&gt;&lt;code&gt;sap-tests.yml&lt;/code&gt;&lt;/a&gt; runs on every PR that touches &lt;code&gt;src/&lt;/code&gt;. It parses the abapGit filenames, maps them back to ABAP object types, and then calls ARC-1 directly from Bash. There is no model involved in this part.&lt;/p&gt;&#xA;&lt;p&gt;For changed classes it runs ABAP Unit through &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/#sapdiagnose&#34;&gt;&lt;code&gt;SAPDiagnose&lt;/code&gt;&lt;/a&gt; with &lt;code&gt;action=&amp;quot;unittest&amp;quot;&lt;/code&gt;. For changed classes, interfaces, programs, and function groups it runs ATC through &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/#sapdiagnose&#34;&gt;&lt;code&gt;SAPDiagnose&lt;/code&gt;&lt;/a&gt; with &lt;code&gt;action=&amp;quot;atc&amp;quot;&lt;/code&gt;. The result is posted as a sticky PR comment, and line-specific ATC findings are posted inline on the Files Changed tab when GitHub can attach them to the diff.&lt;/p&gt;&#xA;&lt;p&gt;The gate is simple: failing or erroring unit tests fail the job, and P1/P2 ATC findings fail the job. P3 findings are visible but do not block.&lt;/p&gt;&#xA;&lt;p&gt;The clean demo is &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/20&#34;&gt;PR #20&lt;/a&gt;. It adds one more unit test to &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/src/zcl_arc1_test_helpers.clas.abap&#34;&gt;&lt;code&gt;ZCL_ARC1_TEST_HELPERS&lt;/code&gt;&lt;/a&gt;. The workflow &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/20#issuecomment-4432679538&#34;&gt;reports 7 of 7 ABAP Unit tests passing&lt;/a&gt; and one non-blocking P3 ATC warning.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;GitHub PR comment showing the SAP test gate with 7 of 7 ABAP Unit tests passing and one non-blocking ATC P3 finding.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/untitest-atc-report.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;There is one important assumption here. The test workflow runs against activated objects in SAP. That matches the normal abapGit loop I use: edit, activate, push. If your team pushes before activation, you need a PR sandbox system or a pre-step that pulls and activates before this workflow runs.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Layer 3: AI review without MCP&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;GitHub&amp;rsquo;s built-in Copilot Code Review can be assigned from the PR sidebar. That is already useful. It reads the diff and can catch common problems from the text alone.&lt;/p&gt;&#xA;&lt;p&gt;In the sample &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14&#34;&gt;PR #14&lt;/a&gt;, Copilot Code Review did catch the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14#discussion_r3226642123&#34;&gt;direct &lt;code&gt;SELECT&lt;/code&gt; from &lt;code&gt;MARA&lt;/code&gt;&lt;/a&gt; as a Clean Core hotspot. That is a good result.&lt;/p&gt;&#xA;&lt;p&gt;But this review has an important limitation: it is still a diff-only review. It cannot know whether the object is already activated in SAP. It cannot ask the system for callers. It cannot inspect ST22. It cannot prove that a claim is backed by the current SAP system.&lt;/p&gt;&#xA;&lt;p&gt;That does not make it useless. It just means it is one layer.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Layer 4: AI review with ARC-1&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The MCP-backed review is the more interesting part.&lt;/p&gt;&#xA;&lt;p&gt;In the repo, applying the &lt;code&gt;copilot:review&lt;/code&gt; label posts a canonical &lt;code&gt;@copilot review ...&lt;/code&gt; prompt to the PR. Copilot Coding Agent then uses the ARC-1 MCP server configured in the repository settings.&lt;/p&gt;&#xA;&lt;p&gt;Applying the &lt;code&gt;claude:review&lt;/code&gt; label starts &lt;a href=&#34;https://github.com/anthropics/claude-code-action&#34;&gt;&lt;code&gt;anthropics/claude-code-action&lt;/code&gt;&lt;/a&gt; in GitHub Actions. The workflow writes an MCP config file, allows only selected ARC-1 tools, loads the prompt from &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/claude-review-prompt.md&#34;&gt;&lt;code&gt;claude-review-prompt.md&lt;/code&gt;&lt;/a&gt;, and asks Claude to post one pull request review.&lt;/p&gt;&#xA;&lt;p&gt;The prompt is deliberately concrete:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Use 2 to 5 ARC-1 tool calls.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Read the changed ABAP object from SAP.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Check for GitHub to SAP drift.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Only navigate references when the public contract changed.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Do not repeat abaplint or SAP test gate findings.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Post inline comments on changed lines.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Use GitHub suggestion blocks when the fix is concrete.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This makes the review auditable. The model still reasons, but important claims can point back to tool results.&lt;/p&gt;&#xA;&lt;p&gt;In PR #14, the decisive ARC-1 call was a &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/#sapread&#34;&gt;&lt;code&gt;SAPRead&lt;/code&gt;&lt;/a&gt; of the activated &lt;code&gt;ZCL_ARC1_TASK_SERVICE~LIST_TASKS&lt;/code&gt; method from SAP. Claude then posted the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14#discussion_r3228270334&#34;&gt;key finding&lt;/a&gt;: the &lt;code&gt;MARA&lt;/code&gt; block is not only a direct SAP table access, it also changes the meaning of &lt;code&gt;list_tasks&lt;/code&gt;. A task service should not silently return no tasks because the material master has no finished product.&lt;/p&gt;&#xA;&lt;p&gt;It also did the useful drift check:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;The activated ZCL_ARC1_TASK_SERVICE~LIST_TASKS in SAP matches the pre-PR source.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;The MARA block is not yet activated, as expected for an open PR.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;No unexpected drift.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That is the small sentence that justifies the whole architecture. A diff-only reviewer cannot know that. ARC-1 can.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Claude review on PR #14 showing SAPRead-backed drift information and the MARA finding on the changed ABAP method.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/claude-review-pr14.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;demo-prs&#34;&gt;Demo PRs&lt;/h2&gt;&#xA;&lt;p&gt;The main demo is &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14&#34;&gt;PR #14&lt;/a&gt;. It contains one harmless refactoring and one deliberately bad preflight inside &lt;code&gt;ZCL_ARC1_TASK_SERVICE~LIST_TASKS&lt;/code&gt;:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-abap&#34; data-lang=&#34;abap&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;select&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;single&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;matnr&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;from&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;mara&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;k&#34;&gt;into&lt;/span&gt; &lt;span class=&#34;err&#34;&gt;@&lt;/span&gt;&lt;span class=&#34;nv&#34;&gt;data&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nv&#34;&gt;lv_dummy_matnr&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;k&#34;&gt;where&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;mtart&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;FERT&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;if&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;sy&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;nv&#34;&gt;subrc&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;&amp;lt;&amp;gt;&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;0&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;endif&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This is deliberately wrong for the demo. It creates a hard dependency from a task service to the MM material master and reads a SAP-standard table directly. If product validation is needed, it should go through a released API or CDS view, and the service should not hide the reason by returning an empty list.&lt;/p&gt;&#xA;&lt;p&gt;That PR is useful because it shows several review surfaces on the same diff:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;abaplint finds static issues, but not the &lt;code&gt;MARA&lt;/code&gt; problem.&lt;/li&gt;&#xA;&lt;li&gt;the SAP test gate adds live ABAP Unit and ATC results for changed objects.&lt;/li&gt;&#xA;&lt;li&gt;Copilot Code Review sees the diff and flags the &lt;code&gt;MARA&lt;/code&gt; access, but cannot verify SAP state.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14#issuecomment-4430841521&#34;&gt;Copilot Coding Agent with ARC-1&lt;/a&gt; can combine diff review with live SAP reads, syntax, navigation, and release checks.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14#discussion_r3228270334&#34;&gt;Claude with ARC-1&lt;/a&gt; posts a focused review with inline comments, suggestion blocks, and the SAP drift check.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The separate SAP test gate example is &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/20&#34;&gt;PR #20&lt;/a&gt;: one extra test method, 7 of 7 ABAP Unit tests green, and a single non-blocking P3 ATC finding.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;One-click suggestions&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Both Copilot and Claude can post GitHub review comments with suggestion blocks. That means the PR shows the same &amp;ldquo;Apply suggestion&amp;rdquo; button a human reviewer would get.&lt;/p&gt;&#xA;&lt;p&gt;This is now verified in PR #14. &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14#discussion_r3226642123&#34;&gt;Copilot Code Review&lt;/a&gt; and &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14#discussion_r3228270334&#34;&gt;Claude&lt;/a&gt; both suggested deleting the &lt;code&gt;MARA&lt;/code&gt; preflight block. Claude&amp;rsquo;s version adds the SAP-side evidence on top: &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/#sapread&#34;&gt;&lt;code&gt;SAPRead&lt;/code&gt;&lt;/a&gt; confirmed that this block is not part of the currently activated method, so the review can separate &amp;ldquo;new in this PR&amp;rdquo; from &amp;ldquo;already active in SAP&amp;rdquo;.&lt;/p&gt;&#xA;&lt;p&gt;The two screenshots below are from the same lines in PR #14. Copilot shows the diff-only version of the review. Claude shows the same GitHub suggestion UX, but with the SAP-side drift evidence from ARC-1.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Claude review comment on PR #14 showing the MARA preflight deletion suggestion with SAPRead drift evidence and an Apply suggestion button.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/pr14-mara-claude.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Code Review comment on PR #14 showing the MARA preflight deletion suggestion with an Apply suggestion button.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/pr14-mara-copilot.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The prompt asks for suggestion blocks only when the fix is concrete. A wrong suggestion block is worse than a normal comment because it invites the reviewer to apply it without thinking.&lt;/p&gt;&#xA;&lt;p&gt;This is not a replacement for a proper feature branch. It is just a good review UX for small, local fixes.&lt;/p&gt;&#xA;&lt;h2 id=&#34;operations-automation&#34;&gt;Operations Automation&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Autonomous dump triage&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The repo also has an operations pattern for staying ahead of runtime issues.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/sap-dump-triage.yml&#34;&gt;&lt;code&gt;sap-dump-triage.yml&lt;/code&gt;&lt;/a&gt; workflow asks ARC-1 for recent ST22 dumps through &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/#sapdiagnose&#34;&gt;&lt;code&gt;SAPDiagnose&lt;/code&gt;&lt;/a&gt;. It can run on a schedule, deduplicates dumps against existing GitHub issues by storing the dump ID in an HTML comment marker, and creates one issue for each new dump with metadata, a short Claude triage, and an urgency label.&lt;/p&gt;&#xA;&lt;p&gt;For the sample repo, the cron is disabled so the issue list stays stable. In a real setup, I would turn it on so GitHub becomes a lightweight watch list for new dumps instead of waiting until someone reports the same runtime error again. The current examples are visible through the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/issues?q=is%3Aissue+label%3Asap%3Adump&#34;&gt;&lt;code&gt;sap:dump&lt;/code&gt; label&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This is the part I like most conceptually:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cheap shallow triage for everything&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;expensive deep investigation only when needed&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That is a much better cost model than asking the LLM to deeply inspect every dump forever.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Deep dive on demand&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The second stage is the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/blob/main/.github/workflows/sap-dump-deep-dive.yml&#34;&gt;&lt;code&gt;sap-dump-deep-dive.yml&lt;/code&gt;&lt;/a&gt; workflow. A human applies the &lt;code&gt;dump:investigate&lt;/code&gt; label to a dump issue. The workflow extracts the dump ID, reads the full dump through ARC-1, reads the failing ABAP source, and posts one investigation comment.&lt;/p&gt;&#xA;&lt;p&gt;The best demo is &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/issues/15&#34;&gt;issue #15&lt;/a&gt;, an &lt;code&gt;OBJECTS_OBJREF_NOT_ASSIGNED_NO&lt;/code&gt; dump in &lt;code&gt;CL_ENH_ADT_ENHO_OBJ_PERSIST&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Claude found a very concrete root cause. In &lt;code&gt;GET_DATA_FROM_TOOL&lt;/code&gt;, the first &lt;code&gt;CASE l_enhtooltype&lt;/code&gt; block creates &lt;code&gt;r_object_data&lt;/code&gt;, but it handles only BAdI and hook enhancement tool types. The dump variables showed &lt;code&gt;I_ENHO_TOOL&lt;/code&gt; as &lt;code&gt;CL_ENH_TOOL_WDY&lt;/code&gt;, a Web Dynpro enhancement tool. Because that tool type is not handled, &lt;code&gt;r_object_data&lt;/code&gt; stays initial. The next dereference at line 30 raises &lt;code&gt;CX_SY_REF_IS_INITIAL&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The interesting detail is that there is a second &lt;code&gt;CASE&lt;/code&gt; block later in the same method with a &lt;code&gt;WHEN OTHERS&lt;/code&gt; guard, but execution never reaches it because the null dereference happens earlier.&lt;/p&gt;&#xA;&lt;p&gt;That is the kind of analysis I want from this setup. It used the dump, selected variables, call stack, and source code. It did not just say &amp;ldquo;probably a null reference&amp;rdquo;. It explained why the reference was null and where the missing guard belongs.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/issues/15#issuecomment-4431477985&#34;&gt;deep-dive comment&lt;/a&gt; then updates the labels from &lt;code&gt;needs-triage&lt;/code&gt; to &lt;code&gt;dump:investigated&lt;/code&gt;. So GitHub becomes the lightweight operations board, while SAP remains the source of truth.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;GitHub issue #15 showing a Claude deep-dive analysis for an SAP short dump with root cause and labels.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-12-arc-1-abap-cicd-review/issue-15-claude.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-i-would-use-this&#34;&gt;How I Would Use This&lt;/h2&gt;&#xA;&lt;p&gt;For a small ABAP team, I would start with this sequence:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Push ABAP source to GitHub with abapGit.&lt;/li&gt;&#xA;&lt;li&gt;Run abaplint on every PR.&lt;/li&gt;&#xA;&lt;li&gt;Run ABAP Unit and ATC through ARC-1 on every PR.&lt;/li&gt;&#xA;&lt;li&gt;Use Copilot Code Review as a cheap, generic first AI review if you already have Copilot.&lt;/li&gt;&#xA;&lt;li&gt;Add &lt;code&gt;claude:review&lt;/code&gt; or &lt;code&gt;copilot:review&lt;/code&gt; only when the PR needs deeper SAP context.&lt;/li&gt;&#xA;&lt;li&gt;Enable dump triage manually first.&lt;/li&gt;&#xA;&lt;li&gt;Turn on the scheduled dump check once the issue noise level is understood.&lt;/li&gt;&#xA;&lt;li&gt;Use &lt;code&gt;dump:investigate&lt;/code&gt; only for dumps that are recurring, high urgency, or unclear.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;This keeps the workflow understandable. Not every PR needs a deep AI review, and not every dump needs full investigation. Static and deterministic checks should do the boring work first.&lt;/p&gt;&#xA;&lt;p&gt;The label interface is intentionally simple:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;copilot:review&lt;/code&gt; triggers Copilot Coding Agent with ARC-1.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;claude:review&lt;/code&gt; triggers Claude Code Action with ARC-1.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;sap:dump&lt;/code&gt; marks a dump tracker issue.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;needs-triage&lt;/code&gt; means the shallow workflow created the issue.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;dump:investigate&lt;/code&gt; triggers the deep-dive workflow.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;dump:investigated&lt;/code&gt; means the deep dive has already posted its analysis.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;urgency:high&lt;/code&gt;, &lt;code&gt;urgency:medium&lt;/code&gt;, and &lt;code&gt;urgency:low&lt;/code&gt; make the issue list sortable.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The labels are the UI. That keeps the pattern easy to teach and easy to extend.&lt;/p&gt;&#xA;&lt;h2 id=&#34;boundaries-and-next-steps&#34;&gt;Boundaries And Next Steps&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Limitations&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Copilot Code Review and Copilot Coding Agent are not the same thing. The sidebar review is useful, but it does not use the MCP server. For MCP context, this repo uses label-triggered workflows.&lt;/p&gt;&#xA;&lt;p&gt;GitHub-hosted runners must reach the ARC-1 endpoint. That is why BTP Cloud Foundry is a good demo topology. If ARC-1 is only available inside a private network, use self-hosted runners or another controlled network path.&lt;/p&gt;&#xA;&lt;p&gt;The SAP user behind the BTP destination still matters. Even with a read-only ARC-1 key, the workflow can read what that technical user can read. In a real setup, scope both the SAP user and the ARC-1 API key deliberately.&lt;/p&gt;&#xA;&lt;p&gt;The SAP test gate runs against activated objects in SAP. That fits the edit, activate, push flow. If your team pushes before activation, use a PR sandbox system or add a controlled pull and activate step before the checks run.&lt;/p&gt;&#xA;&lt;p&gt;And AI review is still review. The goal is not to replace an ABAP developer. The goal is to catch useful things earlier, with enough evidence that a developer can decide quickly.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What else this pattern can do&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Once the plumbing exists, the same pattern can be used for more than PR review.&lt;/p&gt;&#xA;&lt;p&gt;A scheduled Clean Core audit could read a package through ARC-1, check released API usage, and open GitHub issues. A multi-system setup could expose &lt;code&gt;arc-1-dev&lt;/code&gt;, &lt;code&gt;arc-1-qa&lt;/code&gt;, and &lt;code&gt;arc-1-prod&lt;/code&gt; as separate MCP servers and compare what is active in each system.&lt;/p&gt;&#xA;&lt;p&gt;The SAP test gate can also grow beyond this small demo. Full ATC variants, Code Inspector checks, transport checks, and package-level baselines can all surface in the same PR interface developers already use.&lt;/p&gt;&#xA;&lt;p&gt;The next obvious step is the post-merge path. After a PR is merged to &lt;code&gt;main&lt;/code&gt;, a GitHub workflow could call ARC-1 with a separate git-scoped key and run an abapGit pull through &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/#sapgit&#34;&gt;&lt;code&gt;SAPGit&lt;/code&gt;&lt;/a&gt; for the package in the SAP system.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SAP -&amp;gt; abapGit -&amp;gt; GitHub -&amp;gt; AI review -&amp;gt; merge -&amp;gt; ARC-1 pull -&amp;gt; SAP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;I would keep that write path separate from the review key, gated by branch, labels, or environment approvals. If the pull has conflicts or activation problems, the workflow should report that back and stop.&lt;/p&gt;&#xA;&lt;p&gt;That is also where the operations loop becomes interesting: detect a dump, investigate it, propose a fix PR, review it, merge it, and pull it back into SAP. The client can change. The governed SAP access layer stays the same.&lt;/p&gt;&#xA;&lt;h2 id=&#34;takeaway&#34;&gt;Takeaway&lt;/h2&gt;&#xA;&lt;p&gt;This is the direction I find practical for ABAP development automation.&lt;/p&gt;&#xA;&lt;p&gt;Do not start with &amp;ldquo;AI should write all ABAP&amp;rdquo;. Start with a safer and more useful question:&lt;/p&gt;&#xA;&lt;p&gt;Can the development workflow become better if GitHub automation can safely use the actual SAP system?&lt;/p&gt;&#xA;&lt;p&gt;For me, the answer is clearly yes. Not because the model magically understands ABAP, but because ARC-1 brings missing SAP context into the workflow: activated source, ABAP Unit, ATC, references, dumps, syntax checks, and system-specific evidence.&lt;/p&gt;&#xA;&lt;p&gt;abapGit gets the code into GitHub. abaplint covers the static layer. ARC-1 runs ABAP Unit and ATC from GitHub Actions, and gives AI a read-only window into SAP. Copilot and Claude become more useful reviewers because they can stop guessing and start checking.&lt;/p&gt;&#xA;&lt;p&gt;That is the main thread of this sample: GitHub is the automation surface, ARC-1 is the SAP gateway, and humans still decide what gets merged.&lt;/p&gt;&#xA;&lt;h2 id=&#34;references-and-links&#34;&gt;References And Links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review&#34;&gt;Sample repository: arc-1-abap-cicd-review&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/14&#34;&gt;Demo PR #14: multi-engine review with suggestion blocks&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/pull/20&#34;&gt;Demo PR #20: SAP Unit and ATC gate&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/issues/15&#34;&gt;Dump issue #15: deep-dive investigation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-abap-cicd-review/issues?q=is%3Aissue+label%3Asap%3Adump&#34;&gt;Dump tracker issues&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1 on GitHub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;ARC-1 Documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.heliconialabs.com/patterns-for-using-llms-in-abap-development.pdf&#34;&gt;Patterns for using LLMs in ABAP development&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://abapgit.org/&#34;&gt;abapGit&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://abaplint.org/&#34;&gt;abaplint&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/reviewdog/reviewdog&#34;&gt;reviewdog&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/anthropics/claude-code-action&#34;&gt;Claude Code Action&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.github.com/en/copilot/concepts/agents/coding-agent/about-coding-agent&#34;&gt;GitHub Copilot cloud agent&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://modelcontextprotocol.io/&#34;&gt;Model Context Protocol&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.zeis.de/posts/2026-05-08-arc-1-joule-studio-clean-core/&#34;&gt;Joule Studio and ARC-1 Clean Core post&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>From SEGW and Legacy UI5 to RAP with ARC-1</title>
      <link>https://blog.zeis.de/posts/2026-05-11-segw-to-rap/</link>
      <pubDate>Mon, 11 May 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-05-11-segw-to-rap/</guid>
      <description>&lt;p&gt;Series note: This post is part of my &lt;a href=&#34;https://blog.zeis.de/tags/ai-abap-development-series/&#34;&gt;AI ABAP development series&lt;/a&gt;, where I go from AI development in general, to ABAP-specific problems, and then to ARC-1.&lt;/p&gt;&#xA;&lt;p&gt;In the last posts I introduced &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt;, explained why I built it, showed the BTP architecture, and then used it from Copilot Studio and Joule Studio. Those posts were mostly about architecture and possible use cases.&lt;/p&gt;&#xA;&lt;p&gt;This one is different. This is the use case ARC-1 was originally built for: making real SAP development easier.&lt;/p&gt;&#xA;&lt;p&gt;A lot of SAP customers are still somewhere between old ECC-style custom development and the S/4HANA world they actually want to reach. The uncomfortable part is that &amp;ldquo;moving to S/4&amp;rdquo; can easily become a technical lift and shift. The old custom code moves, the old OData services move, the old UI patterns move, and after the migration the landscape is still not really modern. It just runs somewhere newer.&lt;/p&gt;&#xA;&lt;p&gt;That is not the direction I find interesting. If we already touch those applications, then we should also ask where it makes sense to move them toward RAP, OData V4, Fiori elements, cleaner APIs, and a development model that fits the Clean Core direction much better.&lt;/p&gt;&#xA;&lt;p&gt;So I built a small but complete demo for that:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;a legacy SEGW OData V2 service&lt;/li&gt;&#xA;&lt;li&gt;a legacy freestyle UI5 JavaScript app&lt;/li&gt;&#xA;&lt;li&gt;a new RAP OData V4 service&lt;/li&gt;&#xA;&lt;li&gt;a modern UI5 TypeScript app&lt;/li&gt;&#xA;&lt;li&gt;a Fiori elements app on top of the RAP service&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The full workspace, generated code, ABAP sources, screenshots, and chat logs are published here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap&#34;&gt;github.com/arc-mcp/arc-1-segw-to-rap&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-starting-point&#34;&gt;The Starting Point&lt;/h2&gt;&#xA;&lt;p&gt;The demo starts with a small project management application on an S/4HANA 2023 trial system, ABAP Platform 7.58. The legacy backend sits in package &lt;code&gt;ZDEMO_MIG&lt;/code&gt; and uses three custom tables: &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zdm_project.tabl.xml&#34;&gt;&lt;code&gt;ZDM_PROJECT&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zdm_task.tabl.xml&#34;&gt;&lt;code&gt;ZDM_TASK&lt;/code&gt;&lt;/a&gt;, and &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zdm_timeentry.tabl.xml&#34;&gt;&lt;code&gt;ZDM_TIMEENTRY&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;On top of that sits the SEGW service &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zdemo_mig_projects_srv_0001.iwsg.xml&#34;&gt;&lt;code&gt;ZDEMO_MIG_PROJECTS_SRV&lt;/code&gt;&lt;/a&gt;. It exposes &lt;code&gt;ProjectSet&lt;/code&gt;, &lt;code&gt;TaskSet&lt;/code&gt;, and &lt;code&gt;TimeEntrySet&lt;/code&gt;, with navigation from projects to tasks and from tasks to time entries. The one bit of behavior is the &lt;code&gt;ApproveProject&lt;/code&gt; function import, which changes the project status.&lt;/p&gt;&#xA;&lt;p&gt;This is the old service in SAP Gateway Service Builder. You can see the classic SEGW shape directly: entity types, properties, navigation associations, entity sets, and the function import sitting next to the data model.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;SAP Gateway Service Builder showing the legacy SEGW project service with Project properties, entity sets, associations, and the ApproveProject function import.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/segw-screenshot.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The old UI is a classic master/detail app. The left side shows projects, the right side shows the selected project with tasks and time entries. It works, but it also contains the kind of patterns many SAP teams know too well: manual OData V2 model creation, global formatters, synchronous bootstrap, path string parsing, &lt;code&gt;jQuery.sap.require&lt;/code&gt;, manual function import calls, and UI state that is partly stitched together in controller code.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Legacy UI5 freestyle app showing the old project master/detail application.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/ui5-legacy-app-screenshot.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The backend is similar. The generated &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zcl_zdemo_mig_projects_mpc.clas.abap&#34;&gt;MPC class&lt;/a&gt; describes the model, and the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zcl_zdemo_mig_projects_dpc_ext.clas.abap&#34;&gt;DPC_EXT class&lt;/a&gt; contains the custom logic. For the demo I made the legacy code deliberately rough: manual reads, ignored filters in some places, no authority checks, manual navigation handling, and an &lt;code&gt;ApproveProject&lt;/code&gt; function import that updates the project status directly.&lt;/p&gt;&#xA;&lt;p&gt;That is a good migration target because the interesting question is not &amp;ldquo;can an AI write a RAP sample from scratch?&amp;rdquo;. The more useful question is:&lt;/p&gt;&#xA;&lt;p&gt;Can it inspect the old service, understand the contract, and create a modern replacement that keeps the functional shape?&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-skills&#34;&gt;The Skills&lt;/h2&gt;&#xA;&lt;p&gt;For this run I did not just write one big prompt. I used three ARC-1 skills from the maintained &lt;a href=&#34;https://github.com/arc-mcp/arc-1/tree/main/skills&#34;&gt;&lt;code&gt;arc-1/skills&lt;/code&gt;&lt;/a&gt; folder: &lt;a href=&#34;https://github.com/arc-mcp/arc-1/tree/main/skills/migrate-segw-to-rap&#34;&gt;&lt;code&gt;migrate-segw-to-rap&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1/tree/main/skills/modernize-ui5-app&#34;&gt;&lt;code&gt;modernize-ui5-app&lt;/code&gt;&lt;/a&gt;, and &lt;a href=&#34;https://github.com/arc-mcp/arc-1/tree/main/skills/convert-ui5-to-fiori-elements&#34;&gt;&lt;code&gt;convert-ui5-to-fiori-elements&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The folder is worth looking at beyond this demo. It also contains skills for RAP service generation, ABAP test generation, code explanation, custom-code migration, Clean Core checks, documentation, and system-context setup. The idea is that ARC-1 does not only provide tools, but repeatable workflows around those tools.&lt;/p&gt;&#xA;&lt;p&gt;The point of these skills is not that they are perfect generic migration products. They are templates for a process.&lt;/p&gt;&#xA;&lt;p&gt;That distinction matters. The real value is that the skill forces the agent into a structured workflow:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Read the instructions first.&lt;/li&gt;&#xA;&lt;li&gt;Inspect the old system and source code before designing anything.&lt;/li&gt;&#xA;&lt;li&gt;Print the extracted model and plan.&lt;/li&gt;&#xA;&lt;li&gt;Stop for confirmation before writes.&lt;/li&gt;&#xA;&lt;li&gt;Create the new artifacts.&lt;/li&gt;&#xA;&lt;li&gt;Activate, publish, lint, typecheck, and smoke test.&lt;/li&gt;&#xA;&lt;li&gt;Use the feedback from those gates before calling the run done.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;This is much closer to how I want agentic SAP development to work. Not &amp;ldquo;please convert my system&amp;rdquo; and hope for the best, but a guided workflow with discovery, constraints, acceptance gates, and real SAP system access.&lt;/p&gt;&#xA;&lt;p&gt;For the run, I used Cursor with Composer-2. I did that intentionally. This was not meant to be a best-case frontier-model demo. It should be closer to what people might actually try in an IDE with a good but not magical model.&lt;/p&gt;&#xA;&lt;p&gt;That is also why the skills matter so much. A detailed skill moves part of the intelligence out of the model and into the workflow: what to read first, when to stop, which tools to use, which checks must pass, and what the target shape should look like. The model still has to reason, but it does not have to invent the whole process from scratch.&lt;/p&gt;&#xA;&lt;p&gt;The MCP setup was split by responsibility. &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; handled the SAP system side: object reads, writes, activation, transports, and service binding work. &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;SAP Docs MCP Server&lt;/a&gt; gave RAP and CDS documentation context. &lt;a href=&#34;https://github.com/UI5/mcp-server&#34;&gt;UI5 MCP Server&lt;/a&gt; and &lt;a href=&#34;https://github.com/SAP/open-ux-tools/tree/main/packages/fiori-mcp-server&#34;&gt;SAP Fiori MCP Server&lt;/a&gt; were used for the frontend conversion and validation steps.&lt;/p&gt;&#xA;&lt;p&gt;The net execution time for the three guided runs was below 20 minutes. That does not include the time I spent before the final run building the demo, improving the skills, and learning from earlier failed attempts. But for the final guided process itself, this was comfortably under 20 minutes.&lt;/p&gt;&#xA;&lt;h2 id=&#34;prompt-1-segw-to-rap&#34;&gt;Prompt 1: SEGW to RAP&lt;/h2&gt;&#xA;&lt;p&gt;The first prompt asked the agent to run the &lt;code&gt;migrate-segw-to-rap&lt;/code&gt; skill against &lt;code&gt;ZDEMO_MIG_PROJECTS_SRV&lt;/code&gt;. The full transcript is in &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/llm-chat-history/prompt-1-segw-to-rap&#34;&gt;&lt;code&gt;llm-chat-history/prompt-1-segw-to-rap&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Cursor prompt for the SEGW to RAP run showing ARC-1 reading the legacy service.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/starting-prompt-1-segw-to-rap.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The important part is what happened before the agent wrote anything. ARC-1 first probed the system and confirmed the real constraints: ABAP 7.58, RAP availability, transport access, search access, and write access. The agent then tried the obvious generated MPC naming, discovered that this SEGW service used the generated &lt;code&gt;ZCL_ZDEMO_MIG_PROJECTS_*&lt;/code&gt; class names, and read the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zcl_zdemo_mig_projects_mpc.clas.abap&#34;&gt;MPC class&lt;/a&gt; as the source of the OData model. After that it read the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/zcl_zdemo_mig_projects_dpc_ext.clas.abap&#34;&gt;DPC_EXT class&lt;/a&gt;, because the interesting behavior was not in the metadata. It was in the custom code, especially the &lt;code&gt;ApproveProject&lt;/code&gt; function import.&lt;/p&gt;&#xA;&lt;p&gt;Only after that discovery step did it print the extracted model and stop for &lt;code&gt;ok&lt;/code&gt;:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Project&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  key ProjectId&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  navigation Tasks&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Task&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  key TaskId&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  foreign key ProjectId&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  navigation TimeEntries&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;TimeEntry&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  key EntryId&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  foreign keys TaskId, ProjectId&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Function import&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  ApproveProject(ProjectId) -&amp;gt; Project&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After confirmation, ARC-1 created the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/ABAP_SRC/src/dm&#34;&gt;RAP stack under &lt;code&gt;ABAP_SRC/src/dm&lt;/code&gt;&lt;/a&gt;. This is where the migration becomes interesting on the ABAP side.&lt;/p&gt;&#xA;&lt;p&gt;The root interface view &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zi_dm_project.ddls.asddls&#34;&gt;&lt;code&gt;ZI_DM_PROJECT&lt;/code&gt;&lt;/a&gt; selects from &lt;code&gt;ZDM_PROJECT&lt;/code&gt; and models tasks as a RAP composition child. The same pattern continues with &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zi_dm_task.ddls.asddls&#34;&gt;&lt;code&gt;ZI_DM_TASK&lt;/code&gt;&lt;/a&gt; and &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zi_dm_timeentry.ddls.asddls&#34;&gt;&lt;code&gt;ZI_DM_TIMEENTRY&lt;/code&gt;&lt;/a&gt;. So the old OData navigation model becomes a RAP business object structure instead of staying as manual navigation handling in DPC_EXT.&lt;/p&gt;&#xA;&lt;p&gt;The interface behavior definition &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zi_dm_project.bdef.asbdef&#34;&gt;&lt;code&gt;ZI_DM_PROJECT&lt;/code&gt;&lt;/a&gt; is managed, uses &lt;code&gt;strict ( 2 )&lt;/code&gt;, and enables draft. It maps the nicer RAP field names like &lt;code&gt;ProjectId&lt;/code&gt;, &lt;code&gt;StartDate&lt;/code&gt;, and &lt;code&gt;EstimatedHours&lt;/code&gt; back to the old table fields like &lt;code&gt;project_id&lt;/code&gt;, &lt;code&gt;start_date&lt;/code&gt;, and &lt;code&gt;estimated_hours&lt;/code&gt;. It also defines the project as the lock master and the child entities as dependent by project. The draft tables &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/rap/zdm_project_d.tabl.xml&#34;&gt;&lt;code&gt;ZDM_PROJECT_D&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/rap/zdm_task_d.tabl.xml&#34;&gt;&lt;code&gt;ZDM_TASK_D&lt;/code&gt;&lt;/a&gt;, and &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/rap/zdm_timeentry_d.tabl.xml&#34;&gt;&lt;code&gt;ZDM_TIMEENTRY_D&lt;/code&gt;&lt;/a&gt; are part of that generated target shape.&lt;/p&gt;&#xA;&lt;p&gt;The projection layer then exposes the service-facing model. &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zc_dm_project.ddls.asddls&#34;&gt;&lt;code&gt;ZC_DM_PROJECT&lt;/code&gt;&lt;/a&gt; is a transactional query projection on the interface view, redirects &lt;code&gt;_Tasks&lt;/code&gt; to &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zc_dm_task.ddls.asddls&#34;&gt;&lt;code&gt;ZC_DM_TASK&lt;/code&gt;&lt;/a&gt;, and carries metadata extension support. The projection behavior &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zc_dm_project.bdef.asbdef&#34;&gt;&lt;code&gt;ZC_DM_PROJECT&lt;/code&gt;&lt;/a&gt; reuses create, update, delete, draft actions, and the new approve action from the interface behavior.&lt;/p&gt;&#xA;&lt;p&gt;Finally, the service definition &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zui_dm_projects.srvd.srvdsrv&#34;&gt;&lt;code&gt;ZUI_DM_PROJECTS&lt;/code&gt;&lt;/a&gt; exposes the projection entities as &lt;code&gt;Project&lt;/code&gt;, &lt;code&gt;Task&lt;/code&gt;, and &lt;code&gt;TimeEntry&lt;/code&gt;, and the service binding &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zui_dm_projects_o4.srvb.xml&#34;&gt;&lt;code&gt;ZUI_DM_PROJECTS_O4&lt;/code&gt;&lt;/a&gt; publishes them as OData V4.&lt;/p&gt;&#xA;&lt;p&gt;The new service is OData V4 and published through the service binding:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;/sap/opu/odata4/sap/zui_dm_projects_o4/srvd/sap/zui_dm_projects_o4/0001/&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The old &lt;code&gt;ApproveProject&lt;/code&gt; function import became a RAP action:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-abap&#34; data-lang=&#34;abap&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;action&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;approve_project&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;result&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt; &lt;span class=&#34;err&#34;&gt;$&lt;/span&gt;&lt;span class=&#34;nv&#34;&gt;self&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zbp_dm_project.clas.locals_imp.abap&#34;&gt;behavior implementation&lt;/a&gt; no longer does a direct &lt;code&gt;UPDATE ... COMMIT WORK&lt;/code&gt; in the old DPC_EXT style. It uses RAP EML in local mode, updates the project status, and lets the RAP runtime handle the transactional context.&lt;/p&gt;&#xA;&lt;p&gt;The logs also show why this is not just text generation. The agent had to deal with real ABAP Platform 7.58 details: where the provider contract belongs, how draft table fields need to be named, which timestamp annotations are available, and how the projection behavior should reuse the interface behavior. These are exactly the details that make a generated RAP example look easy and a real migration annoying.&lt;/p&gt;&#xA;&lt;p&gt;That is the first Clean Core angle of the demo. It does not magically make every old custom object clean. But it moves the service shape away from a SEGW/DPC_EXT implementation and toward a RAP business object, CDS projections, behavior definitions, OData V4, draft support, and metadata-driven UI consumption.&lt;/p&gt;&#xA;&lt;p&gt;For an ECC to S/4HANA journey, this is the kind of direction I would rather see than only lifting old custom services into the new system.&lt;/p&gt;&#xA;&lt;h2 id=&#34;prompt-2-ui5-javascript-to-ui5-typescript&#34;&gt;Prompt 2: UI5 JavaScript to UI5 TypeScript&lt;/h2&gt;&#xA;&lt;p&gt;The second prompt converted the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/legacy-ui5-app&#34;&gt;legacy freestyle UI5 JavaScript app&lt;/a&gt; into a &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/modern-ui5-ts-app&#34;&gt;modern UI5 TypeScript app&lt;/a&gt;. The transcript is in &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/llm-chat-history/prompt-2-js-to-ts&#34;&gt;&lt;code&gt;llm-chat-history/prompt-2-js-to-ts&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Cursor prompt for converting the legacy UI5 JavaScript app into UI5 TypeScript.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/starting-prompt-2-ui5-ts.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here the agent did not just rewrite files. The skill forced it to understand the old component setup, manifest, controllers, XML views, formatter logic, model setup, bootstrap, package scripts, and UI5 tooling config before writing the new app.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/UI5/mcp-server&#34;&gt;UI5 MCP Server&lt;/a&gt; was the guardrail around that work. Before writing code, the agent used it for TypeScript conversion guidance and general UI5 guidelines. That shaped the target app: a real TypeScript scaffold, &lt;code&gt;@sapui5/types&lt;/code&gt;, typed controller events, async loading, manifest-driven models, and no old &lt;code&gt;jQuery.sap.*&lt;/code&gt; patterns. It also created the modern UI5 app scaffold and later ran the UI5 linter and manifest validation. Those checks are important because plain TypeScript compilation does not understand UI5-specific conventions, XML event-handler rules, or manifest schema details.&lt;/p&gt;&#xA;&lt;p&gt;The UI result is mostly relevant here because it proves that the RAP service was usable from a real consumer. The old app talked to &lt;code&gt;/ProjectSet&lt;/code&gt;, followed &lt;code&gt;Tasks&lt;/code&gt;, and called &lt;code&gt;ApproveProject&lt;/code&gt; as an OData V2 function import. The new freestyle app talks to the RAP V4 entity set &lt;code&gt;/Project&lt;/code&gt;, follows &lt;code&gt;_Tasks&lt;/code&gt;, and calls &lt;code&gt;approve_project&lt;/code&gt; as a bound OData V4 operation. The app itself also moved from JavaScript controllers and a manual OData V2 model to TypeScript controllers, manifest-driven OData V4, FlexibleColumnLayout routing, imported formatter modules, and real lint/typecheck gates.&lt;/p&gt;&#xA;&lt;p&gt;The new app consumes the RAP V4 service directly from its &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/modern-ui5-ts-app/webapp/manifest.json&#34;&gt;manifest&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-json&#34; data-lang=&#34;json&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;dataSources&amp;#34;&lt;/span&gt;&lt;span class=&#34;err&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nt&#34;&gt;&amp;#34;mainService&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nt&#34;&gt;&amp;#34;uri&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;/sap/opu/odata4/sap/zui_dm_projects_o4/srvd/sap/zui_dm_projects_o4/0001/&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nt&#34;&gt;&amp;#34;type&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;OData&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nt&#34;&gt;&amp;#34;settings&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;      &lt;span class=&#34;nt&#34;&gt;&amp;#34;odataVersion&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;4.0&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The action call in the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/modern-ui5-ts-app/webapp/controller/Detail.controller.ts&#34;&gt;detail controller&lt;/a&gt; also changed from the old OData V2 function import style to a bound OData V4 operation:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-ts&#34; data-lang=&#34;ts&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;kr&#34;&gt;const&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;operation&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;model&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;bindContext&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;s2&#34;&gt;&amp;#34;com.sap.gateway.srvd.zui_dm_projects.v0001.approve_project()&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nx&#34;&gt;ctx&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;await&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;operation&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;invoke&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;$auto&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The UI is still recognizable, but the app is now using a modern runtime and tooling setup.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Modern UI5 TypeScript app consuming the new RAP OData V4 service.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/ui5-modern-ts-app-screenshot.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This part is important because many real SAP teams cannot immediately replace every freestyle UI5 app with Fiori elements. Sometimes a freestyle app is still the right target. But even then, there is a big difference between old UI5 JavaScript glued to a SEGW V2 service and a modern TypeScript app consuming a RAP V4 service.&lt;/p&gt;&#xA;&lt;p&gt;The run ended with the important gates green: ESLint, UI5 linter, manifest validation, TypeScript typecheck, and a browser render check.&lt;/p&gt;&#xA;&lt;p&gt;That is the second lesson from the logs: the model needed tooling feedback. It was not enough to let it generate code once. The loop with UI5 MCP, linting, manifest validation, and browser verification made the result useful.&lt;/p&gt;&#xA;&lt;h2 id=&#34;prompt-3-legacy-ui5-to-fiori-elements&#34;&gt;Prompt 3: Legacy UI5 to Fiori Elements&lt;/h2&gt;&#xA;&lt;p&gt;The third prompt took a different path. Instead of converting the old freestyle app to another freestyle app, it rebuilt the user-facing contract as a &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/modern-fe-app/dm-projects-fe&#34;&gt;Fiori elements V4 list report and object page&lt;/a&gt;. The transcript is in &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/llm-chat-history/prompt-3-js-to-fiori-elements&#34;&gt;&lt;code&gt;llm-chat-history/prompt-3-js-to-fiori-elements&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Cursor prompt for converting the legacy UI5 app into a Fiori elements V4 app.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/starting-prompt-3-fiori-elements.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is the more interesting Clean Core direction for many S/4HANA projects. A lot of old UI5 code exists because the backend metadata did not carry enough UI intent, or because the old stack made custom frontend code feel like the default. With RAP and Fiori elements, more of the application can move into CDS annotations and behavior.&lt;/p&gt;&#xA;&lt;p&gt;The agent mined the legacy UI for the actual user contract: the columns from the old master list, search behavior, project header fields from the detail view, task table columns, time entry navigation from a selected task, &lt;code&gt;Approve&lt;/code&gt; as a project action, and the status, priority, and date semantics that used to live in the formatter.&lt;/p&gt;&#xA;&lt;p&gt;Then it moved that contract into RAP UI metadata, mainly through the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zme_dm_project.ddlx.asddlxs&#34;&gt;&lt;code&gt;ZME_DM_PROJECT&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zme_dm_task.ddlx.asddlxs&#34;&gt;&lt;code&gt;ZME_DM_TASK&lt;/code&gt;&lt;/a&gt;, and &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/ABAP_SRC/src/dm/zme_dm_timeentry.ddlx.asddlxs&#34;&gt;&lt;code&gt;ZME_DM_TIMEENTRY&lt;/code&gt;&lt;/a&gt; metadata extensions. That is where the old UI intent becomes &lt;code&gt;@UI.headerInfo&lt;/code&gt;, line items, selection fields, facets, field groups, presentation variants, search metadata, and semantic keys.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/SAP/open-ux-tools/tree/main/packages/fiori-mcp-server&#34;&gt;SAP Fiori MCP Server&lt;/a&gt; had a different role than the UI5 MCP Server. It did not translate freestyle controller code into another set of controllers. It exposed the Fiori tools workflow for an external OData V4 list report and object page: discover the available generation capabilities, inspect the required generator configuration, and shape the app around a project name, target folder, UI5 version, service URL or metadata file, and main entity &lt;code&gt;Project&lt;/code&gt;. In other words, it kept the frontend target inside the standard Fiori elements model instead of letting the conversion drift back into custom page wiring.&lt;/p&gt;&#xA;&lt;p&gt;That also makes the split of responsibility clearer. ARC-1 and SAP Docs MCP helped create and correct the RAP annotations in the ABAP backend. Fiori MCP helped define and generate the Fiori elements application that consumes those annotations through &lt;code&gt;$metadata&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The result is a Fiori elements list report on the RAP &lt;code&gt;Project&lt;/code&gt; entity. The generated app manifest is also in the repo, under &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/blob/main/modern-fe-app/dm-projects-fe/webapp/manifest.json&#34;&gt;&lt;code&gt;modern-fe-app/dm-projects-fe/webapp/manifest.json&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Fiori elements list report generated from the RAP OData V4 service.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/fe-screenshot-1.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;And the object page uses the RAP annotations and navigation model, including general data, audit data, and a tasks table.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Fiori elements object page generated from the RAP OData V4 service.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-11-segw-to-rap/images/fe-screenshot-2.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is the third lesson from the logs: Fiori elements migration is not mainly a JavaScript conversion. It is a relocation of intent.&lt;/p&gt;&#xA;&lt;p&gt;Old freestyle UI5 had the intent spread across controllers, XML views, formatters, routing, and manual binding code. The Fiori elements version moves much of that intent into the RAP service metadata. That is not always the right answer for every app, but when it fits, it is exactly the direction I would prefer for S/4HANA custom apps.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-the-logs-show&#34;&gt;What The Logs Show&lt;/h2&gt;&#xA;&lt;p&gt;I included the &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/llm-chat-history&#34;&gt;Cursor chat exports&lt;/a&gt; in the repository because I think the transcript is more useful than a polished final result alone.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/llm-chat-history/prompt-1-segw-to-rap&#34;&gt;SEGW to RAP run&lt;/a&gt; has 140 tool records. That is the most important transcript for this post because it shows ARC-1 reading the legacy service, extracting the model from the generated classes, creating the RAP artifacts, activating them, and publishing the service binding. The &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/llm-chat-history/prompt-2-js-to-ts&#34;&gt;UI5 TypeScript run&lt;/a&gt; has 142 tool records and is mostly about making the new V4 service usable from a freestyle app. The &lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap/tree/main/llm-chat-history/prompt-3-js-to-fiori-elements&#34;&gt;Fiori elements run&lt;/a&gt; has 230 tool records because it had to mine the old UI and move more intent into annotations.&lt;/p&gt;&#xA;&lt;p&gt;There are a few patterns that stand out.&lt;/p&gt;&#xA;&lt;p&gt;First, the model needed real SAP context. It did not know the generated class names until ARC-1 searched the system. It did not know the exact service binding shape until ARC-1 read it. It did not know the old &lt;code&gt;ApproveProject&lt;/code&gt; behavior until it inspected the DPC_EXT source.&lt;/p&gt;&#xA;&lt;p&gt;Second, the skills mattered. Without the skills, the model would probably start writing too early. With the skills, it had to read, extract, summarize, stop, then write.&lt;/p&gt;&#xA;&lt;p&gt;Third, the MCP servers had different jobs. &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; was the SAP system bridge. &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;SAP Docs MCP Server&lt;/a&gt; gave release and documentation context. &lt;a href=&#34;https://github.com/UI5/mcp-server&#34;&gt;UI5 MCP Server&lt;/a&gt; and &lt;a href=&#34;https://github.com/SAP/open-ux-tools/tree/main/packages/fiori-mcp-server&#34;&gt;SAP Fiori MCP Server&lt;/a&gt; grounded the frontend work in current UI5 and Fiori conventions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-this-is-more-than-a-conversion-demo&#34;&gt;Why This Is More Than A Conversion Demo&lt;/h2&gt;&#xA;&lt;p&gt;The obvious reading of this demo is &amp;ldquo;AI converted old code to new code&amp;rdquo;. That is true, but it is not the main point for me.&lt;/p&gt;&#xA;&lt;p&gt;There are now companies like &lt;a href=&#34;https://www.novaintelligence.com/&#34;&gt;Nova Intelligence&lt;/a&gt; and &lt;a href=&#34;https://www.conduct.ai/&#34;&gt;Conduct&lt;/a&gt; working on SAP custom-code understanding and modernization. I think that is a good signal for the space. My angle here is different: how far can you get with open-source tools, your own AI setup, and MCP servers whose code you can actually inspect?&lt;/p&gt;&#xA;&lt;p&gt;This kind of setup is not as polished as a full commercial SAP modernization platform. But the tradeoff is interesting. ARC-1 is open source, the SAP Docs MCP server is open source, and the UI5 and Fiori MCP servers are open-source SAP tooling. You can see what the tools do, adapt the skills, run the workflow against your own system, and understand why the agent made a decision. For many teams, that transparency matters as much as the raw automation.&lt;/p&gt;&#xA;&lt;p&gt;The more important point is that this is the kind of workflow SAP teams need when they want to move away from lift and shift.&lt;/p&gt;&#xA;&lt;p&gt;In a pure lift-and-shift migration, the old application survives almost unchanged:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SEGW service stays SEGW&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;DPC_EXT logic stays DPC_EXT logic&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;UI5 JavaScript stays UI5 JavaScript&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;OData V2 stays OData V2&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;custom UI logic stays custom UI logic&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That may be necessary in some places. But if you do that everywhere, the new S/4HANA system inherits most of the old custom development model.&lt;/p&gt;&#xA;&lt;p&gt;In this demo, the target shape is different:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SEGW contract -&amp;gt; RAP business object&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;OData V2 -&amp;gt; OData V4&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;DPC_EXT function import -&amp;gt; RAP action&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;manual UI wiring -&amp;gt; typed UI5 or Fiori elements metadata&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;frontend-only intent -&amp;gt; CDS annotations where possible&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That is much closer to the Clean Core direction. Not because custom code disappears. It does not. But because the custom code is expressed in newer, more structured extension technologies that fit S/4HANA better.&lt;/p&gt;&#xA;&lt;p&gt;For real projects I would still be careful. A large productive SEGW service can contain much more complex behavior than this demo. It may call BAPIs, use conversion exits, have custom authorization logic, support deep inserts, or depend on UI assumptions that are not visible in the service metadata. You do not solve that with one prompt.&lt;/p&gt;&#xA;&lt;p&gt;But that is also why ARC-1 matters. It gives the agent a way to inspect the real objects, not only files copied into a prompt. And with good skills, the agent can be forced to build a migration plan before touching the system.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-i-would-take-from-this&#34;&gt;What I Would Take From This&lt;/h2&gt;&#xA;&lt;p&gt;For me the practical takeaway is:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;ARC-1 is strongest when the task needs real ABAP system context.&lt;/li&gt;&#xA;&lt;li&gt;Skills are the right abstraction for repeatable SAP modernization workflows.&lt;/li&gt;&#xA;&lt;li&gt;MCP servers should be combined by responsibility, not treated as one magic tool.&lt;/li&gt;&#xA;&lt;li&gt;RAP and Fiori elements are not just &amp;ldquo;newer tech&amp;rdquo;, they give the AI a more structured target model.&lt;/li&gt;&#xA;&lt;li&gt;Clean Core migration is not only about deleting custom code. It is also about moving useful custom functionality into cleaner extension patterns.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The demo is intentionally small, but the pattern is the part I care about. If an agent can read an old SEGW service, understand a legacy UI5 app, create a RAP V4 service, modernize the freestyle UI, and generate a Fiori elements app in one guided run, then this is a useful direction for real SAP modernization work.&lt;/p&gt;&#xA;&lt;p&gt;Not as an autopilot that blindly rewrites landscapes, but as a controlled development workflow with real SAP context, clear boundaries, and human review.&lt;/p&gt;&#xA;&lt;p&gt;That is exactly where I want ARC-1 to go.&lt;/p&gt;&#xA;&lt;h2 id=&#34;references--links&#34;&gt;References &amp;amp; Links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1-segw-to-rap&#34;&gt;Demo repository: arc-1-segw-to-rap&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1 on GitHub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;ARC-1 Documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1/tree/main/skills&#34;&gt;ARC-1 Skills&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;SAP Docs MCP Server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://pages.community.sap.com/topics/abap/rap&#34;&gt;ABAP RESTful Application Programming Model&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://ui5.github.io/typescript/&#34;&gt;UI5 TypeScript&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/UI5/mcp-server&#34;&gt;UI5 MCP Server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP/open-ux-tools/tree/main/packages/fiori-mcp-server&#34;&gt;SAP Fiori MCP Server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/SAP-samples/abap-platform-fiori-feature-showcase&#34;&gt;ABAP Platform Fiori Feature Showcase&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.novaintelligence.com/&#34;&gt;Nova Intelligence&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.conduct.ai/&#34;&gt;Conduct&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;discuss-this-post&#34;&gt;Discuss this post&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/posts/marianzeis_i-converted-a-legacy-segw-odata-service-to-activity-7459822169758326786-LagF&#34;&gt;LinkedIn&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://saptodon.org/@Mianbsp/116558132953167166&#34;&gt;Saptodon&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://bsky.app/profile/marian.zeis.de/post/3mlmapv4vu22d&#34;&gt;Bluesky&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>ARC-1 with Joule Studio: Bringing Real ABAP System Context into Joule</title>
      <link>https://blog.zeis.de/posts/2026-05-08-arc-1-joule-studio-clean-core/</link>
      <pubDate>Wed, 06 May 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-05-08-arc-1-joule-studio-clean-core/</guid>
      <description>&lt;p&gt;Series note: This post is part of my &lt;a href=&#34;https://blog.zeis.de/tags/ai-abap-development-series/&#34;&gt;AI ABAP development series&lt;/a&gt;, where I go from AI development in general, to ABAP-specific problems, and then to ARC-1.&lt;/p&gt;&#xA;&lt;p&gt;In the &lt;a href=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/&#34;&gt;previous post&lt;/a&gt;, I showed &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; with Microsoft Copilot Studio. The idea was that SAP system context should not be locked inside a local IDE. If ARC-1 runs centrally on SAP BTP, it can also be used from Teams, Microsoft 365 Copilot, SharePoint, Jira, and other places where functional consultants, architects, support teams, and project leads already work.&lt;/p&gt;&#xA;&lt;p&gt;This post is the SAP-native version of that idea. If Microsoft Copilot Studio is close to the Microsoft workday, then &lt;a href=&#34;https://help.sap.com/docs/JOULE/3fdd7b321eb24d1b9d40605dce822e84&#34;&gt;Joule&lt;/a&gt; is close to the SAP workday. SAP describes Joule as the unified assistant experience across SAP&amp;rsquo;s solution portfolio, and &lt;a href=&#34;https://help.sap.com/docs/Joule_Studio/45f9d2b8914b4f0ba731570ff9a85313/4444cd1ce4cd471bbe127ea2e4735b40.html&#34;&gt;Joule Studio&lt;/a&gt; as the place to build custom Joule agents with SAP and non-SAP integrations.&lt;/p&gt;&#xA;&lt;p&gt;So the question is not only: can Joule call another MCP server? The better question is: can the ARC-1 capabilities be brought to the place where SAP users already ask questions?&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-carries-over-from-earlier-posts&#34;&gt;What Carries Over From Earlier Posts&lt;/h2&gt;&#xA;&lt;p&gt;ARC-1 is a secure ADT MCP server for ABAP systems. It connects AI clients to SAP systems through &lt;a href=&#34;https://help.sap.com/docs/btp/sap-business-technology-platform/abap-development-user-guides&#34;&gt;ABAP Development Tools&lt;/a&gt; APIs and exposes this through tools like &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/&#34;&gt;SAPRead, SAPSearch, SAPWrite, SAPActivate, SAPContext, SAPDiagnose, SAPTransport, and SAPManage&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For this post, the important part is not the full tool list. It is the operating model from the earlier BTP post:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;central server instead of every user laptop&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;safe by default instead of allow all by default&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;server ceiling + user permission + SAP authorization&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;audit logging instead of invisible local tool calls&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In the &lt;a href=&#34;https://blog.zeis.de/posts/2026-04-29-arc-1-btp/&#34;&gt;BTP post&lt;/a&gt;, I described how ARC-1 can run as a central Cloud Foundry application with &lt;a href=&#34;https://docs.arc-1-mcp.com/xsuaa-setup/&#34;&gt;XSUAA&lt;/a&gt;, &lt;a href=&#34;https://docs.arc-1-mcp.com/btp-destination-setup/&#34;&gt;BTP destinations&lt;/a&gt;, &lt;a href=&#34;https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/cloud-connector&#34;&gt;Cloud Connector&lt;/a&gt;, &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;Principal Propagation&lt;/a&gt;, roles, and BTP audit logging. For Joule Studio, I would not create a second SAP access architecture. I would reuse that controlled endpoint.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-arc-1-adds-to-joule&#34;&gt;What ARC-1 Adds To Joule&lt;/h2&gt;&#xA;&lt;p&gt;Joule already has useful SAP context. SAP has &lt;a href=&#34;https://help.sap.com/docs/btp/btp-developers-guide/use-joule-for-developers-generative-ai-in-abap-cloud&#34;&gt;Joule for Developers&lt;/a&gt;, &lt;a href=&#34;https://help.sap.com/docs/abap-ai/generative-ai-in-abap-cloud/joule-for-developers-abap-ai-capabilities-5f175c94900741d6af3dbb23ce37e81a&#34;&gt;Joule for Developers, ABAP AI capabilities&lt;/a&gt;, and &lt;a href=&#34;https://help.sap.com/docs/joule/serviceguide/sap-consulting-capability-for-joule&#34;&gt;Joule for Consultants&lt;/a&gt;. So this is not about pretending Joule cannot help with ABAP at all.&lt;/p&gt;&#xA;&lt;p&gt;But there is a difference between a useful standard assistant and a tool that can query my actual ABAP system through ADT, read my custom code, inspect dependencies, run diagnostics, check release state, read ATC findings, and create a system-specific proposal.&lt;/p&gt;&#xA;&lt;p&gt;That workflow is not something I get just by opening standard Joule. If SAP does not expose this level of ABAP system access in Joule today, a custom MCP server can still bring it there. With ARC-1, Joule is no longer limited to general SAP knowledge or predefined product capabilities. It can ask the real ABAP system.&lt;/p&gt;&#xA;&lt;p&gt;Not because the model became smarter. Because the tool access became better.&lt;/p&gt;&#xA;&lt;p&gt;That matters beyond pure development. The same ADT-backed context can help architects with Clean Core planning, functional consultants with impact analysis, support teams with dumps and bug analysis, quality leads with ATC reporting, and developers with implementation proposals.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-architecture-i-would-show&#34;&gt;The Architecture I Would Show&lt;/h2&gt;&#xA;&lt;p&gt;SAP&amp;rsquo;s Architecture Center describes &lt;a href=&#34;https://architecture.learning.sap.com/docs/ref-arch/ca1d2a3e/1&#34;&gt;A2A and MCP for interoperability&lt;/a&gt;. The important part for this post is the direction: Joule as the user-facing assistant, A2A for agent-to-agent collaboration, and MCP for tool access. SAP also describes an &lt;a href=&#34;https://architecture.learning.sap.com/docs/ref-arch/ca1d2a3e/1#mcp-gateway-in-integration-suite&#34;&gt;MCP Gateway in SAP Integration Suite&lt;/a&gt; as a governed way to expose SAP and non-SAP APIs, integrations, data sources, and external MCP servers as tools for AI agents.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 fits that pattern as the ADT development-tooling adapter:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;User in Joule&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; Joule Studio Agent&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; SAP Integration Suite API Management / future MCP Gateway&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; ARC-1 on SAP BTP Cloud Foundry&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; Destination Service + Connectivity Service&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; SAP Cloud Connector&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; SAP S/4HANA or ABAP system&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; ADT development APIs&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;ARC-1 can fit the architecture pattern SAP describes. Joule is the user-facing AI entry point, Integration Suite is the governed access layer, ARC-1 is the ADT adapter, and the SAP system stays protected behind BTP connectivity and SAP authorizations.&lt;/p&gt;&#xA;&lt;p&gt;There are still open points. &lt;a href=&#34;https://help.sap.com/docs/Joule_Studio/45f9d2b8914b4f0ba731570ff9a85313/3d9dfad0bc39468292d508f0808a12fe.html&#34;&gt;Joule Studio already supports adding MCP servers&lt;/a&gt; through BTP destinations, but the documentation also lists restrictions: the destination must be streamable HTTP and MCP servers requiring interactive OAuth user authorization are not supported. SAP also shows MCP hub capabilities on the roadmap, but from what I can see this is still a future SAP Build capability and not the fully available enterprise MCP hub today.&lt;/p&gt;&#xA;&lt;p&gt;So I would present this as a target architecture and showcase, not as a final productive setup guide yet.&lt;/p&gt;&#xA;&lt;p&gt;For the showcase, I configured a Joule Studio agent with a small instruction set, Anthropic Claude Sonnet 4 as model, and two MCP servers: &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; for the ABAP system and the &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;SAP Docs MCP Server&lt;/a&gt; for official SAP documentation context. I condensed the screenshots here to show only the relevant configuration parts:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Condensed Joule Studio agent configuration showing the agent basics, instructions, model settings, execution steps, and MCP servers for ARC-1 and SAP_DOCS.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-08-arc-1-joule-studio-clean-core/joule-studio-agent-configuration.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-cases-i-would-show-in-this-post&#34;&gt;Use Cases I Would Show In This Post&lt;/h2&gt;&#xA;&lt;p&gt;I would not repeat all Copilot Studio examples. The Joule post should show scenarios that make sense because the user starts inside the SAP world, not in Teams or SharePoint.&lt;/p&gt;&#xA;&lt;p&gt;One note before the screenshots: I was not able to change the language in this Joule setup, so the screenshots are in German. I describe the important parts in English below each screenshot.&lt;/p&gt;&#xA;&lt;p&gt;The first task for the agent is a Clean Core readiness check for one object. It is narrow enough to be understandable and safe enough because it can be read-only:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Check whether ZCL_ARC1_DEMO_CCORE is clean-core ready.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Use the real SAP system, ATC where possible, API release state, and SAP documentation.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Do not change anything. Return risks, evidence, and suggested next steps.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This is a good first agent task because it shows the difference between &amp;ldquo;Joule explains Clean Core&amp;rdquo; and &amp;ldquo;Joule analyzes this class in this SAP system for Clean Core risk&amp;rdquo;. ARC-1 reads the ABAP source, dependencies, ATC findings, and &lt;code&gt;API_STATE&lt;/code&gt;. &lt;a href=&#34;https://mcp-sap-docs.marianzeis.de/&#34;&gt;mcp-sap-docs&lt;/a&gt; adds SAP guidance and released API context. Joule returns a short assessment with evidence.&lt;/p&gt;&#xA;&lt;p&gt;This is the kind of result I mean:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Joule showing a Clean Core readiness analysis for ZCL_ARC1_DEMO_CCORE with API release state, used SAP tables, and ATC result.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-08-arc-1-joule-studio-clean-core/joule-clean-core-object-analysis.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The screenshot is still a rough showcase, but it already shows the value. Joule is not only giving generic Clean Core advice. It can show that the class is not released for the relevant contracts, that it uses &lt;code&gt;USR02&lt;/code&gt; and &lt;code&gt;BUT000&lt;/code&gt;, and that there are no ATC findings in this small example. That is a much better starting point for an architect or developer than a general explanation of what Clean Core means.&lt;/p&gt;&#xA;&lt;p&gt;I also asked a follow-up prompt for a dependency diagram. The result was almost the answer I wanted: not perfect, but useful because it returned a Mermaid diagram and an evidence table instead of only prose. You can open the &lt;a href=&#34;https://blog.zeis.de/posts/2026-05-08-arc-1-joule-studio-clean-core/full-reply/&#34;&gt;translated and rendered full Joule reply here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The second use case is package-level modernization planning. This is where an agent is useful because it needs multiple tool calls, grouping, prioritization, and a bit more reasoning:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Analyze package ZSD_LEGACY for Clean Core and ABAP Cloud risks.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Group the findings and create a modernization backlog.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Do not change code.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The same agent can combine ARC-1 for package content, dependencies, ATC, release state, and where-used information with SAP documentation for official guidance. The output should be a backlog, not a &amp;ldquo;fixed everything&amp;rdquo; claim:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Priority 1: direct SAP table usage with released successors&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Priority 2: ATC findings with clear fix direction&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Priority 3: objects that need architecture discussion&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Priority 4: probably dead or low-value code to review later&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This screenshot shows another interesting part of Joule. The response is not only a long text answer. Joule created a left-side list with grouped findings and backlog items, and the selected item is shown with details on the right side:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Joule showing an interactive package modernization backlog with grouped Clean Core and ABAP Cloud risk categories on the left and details on the right.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-08-arc-1-joule-studio-clean-core/joule-package-modernization-backlog.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;In this run, the package &lt;code&gt;ZSD_LEGACY&lt;/code&gt; did not exist. Joule still searched the system and found 28 &lt;code&gt;ZSD*&lt;/code&gt; objects that may represent legacy risks. It grouped them into high, medium, and low risk buckets, and then created a modernization backlog. The selected high-risk card shows temporary &lt;code&gt;$TMP&lt;/code&gt; package objects, split into service definitions, tables, and message classes. That is not a final assessment, but it is a useful interactive starting point.&lt;/p&gt;&#xA;&lt;p&gt;These examples have a better through line for this post than repeating the Copilot Studio demos. Copilot Studio is good when the work starts in Microsoft 365. Joule Studio is good when the work starts in SAP, but still needs real ABAP system context.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-i-use-an-agent-here&#34;&gt;Why I Use An Agent Here&lt;/h2&gt;&#xA;&lt;p&gt;For this showcase an agent is perfectly fine. The interesting part is not the packaging. The interesting part is that Joule can call &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; and the &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;SAP Docs MCP Server&lt;/a&gt;, collect system evidence, and turn that into something useful for the user.&lt;/p&gt;&#xA;&lt;p&gt;For ARC-1 I would still keep the first Joule Studio agent conservative: one object or one package, read-only by default, no automatic rewrite. I would not start with a big automation story. I would start with analysis, evidence, and a proposal.&lt;/p&gt;&#xA;&lt;p&gt;And yes, you can also vibe code with this. If write access is enabled for a development or sandbox system, a Joule Studio agent can propose changes and call ARC-1 to apply them. I just do not want this to be the main story here, because the more important point is the architecture: first give Joule controlled access to real ABAP system context, then decide which write actions are safe enough.&lt;/p&gt;&#xA;&lt;h2 id=&#34;open-points&#34;&gt;Open Points&lt;/h2&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://help.sap.com/doc/sap-api-policy/latest/en-US/API_Policy_latest.pdf&#34;&gt;SAP API Policy&lt;/a&gt; also matters here, but it should not become the whole post. ARC-1 should be positioned as ADT development tooling, not as a generic business-data extraction layer. Clean Core checks, ATC, code inspection, syntax checks, ABAP Unit, activation, and development support are the story. Data extraction is not the story.&lt;/p&gt;&#xA;&lt;p&gt;This is also why the Joule Studio architecture is interesting. SAP&amp;rsquo;s architecture guidance describes SAP Integration Suite and API Management as part of a governed pathway for AI agents, including a governance layer like an MCP gateway in front of APIs. That is much closer to the setup in this post than a local MCP server on a developer laptop. It gives the agent a controlled entry point, central configuration, identity, monitoring, and auditability. It does not mean every possible ADT usage is automatically fine, but the architecture shape is much closer to what SAP is describing for API agents.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-this-matters&#34;&gt;Why This Matters&lt;/h2&gt;&#xA;&lt;p&gt;Copilot Studio and Joule Studio are different surfaces:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Copilot Studio = close to Teams, Microsoft 365, SharePoint, Excel, Word, Jira&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Joule Studio = close to SAP products, SAP Build, Joule agents, SAP users&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ARC-1 = governed ABAP system access layer that can serve both&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The client can change, but the security model should not. For me that is the main point. ARC-1 should not be locked to Claude, Cursor, Copilot Studio, or Joule Studio. If the company allows it, the same governed ARC-1 endpoint should be usable from different AI clients.&lt;/p&gt;&#xA;&lt;p&gt;And ARC-1 is open source, which is important to me. If this kind of access layer becomes part of SAP AI architectures, then people should be able to inspect how it works, challenge the security model, test it against real systems, and decide for themselves if it fits their landscape.&lt;/p&gt;&#xA;&lt;p&gt;Also, this does not have to start with write access. Even read-only mode is already very powerful. Reading code, dependencies, ATC findings, release state, dumps, messages, packages, and where-used information can help architects, consultants, support teams, and developers without the assistant writing a single line of ABAP.&lt;/p&gt;&#xA;&lt;p&gt;The target picture is not &amp;ldquo;AI writes ABAP from a chat prompt&amp;rdquo;. The better target is:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;the user asks inside Joule&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Joule has access to the right tools&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ARC-1 provides real ABAP system context&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SAP documentation provides the official direction&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Integration Suite provides governance&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SAP authorizations still protect the backend&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;humans approve the risky parts&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That is much more interesting than a local MCP demo. It is also much closer to what I think enterprise ABAP agentic development needs.&lt;/p&gt;&#xA;&lt;h2 id=&#34;discuss-this-post&#34;&gt;Discuss this post&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://saptodon.org/@Mianbsp/116529573994656695&#34;&gt;Saptodon&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://bsky.app/profile/marian.zeis.de/post/3ml7kulu55s2v&#34;&gt;Bluesky&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/posts/marianzeis_what-if-joule-could-answer-abap-and-clean-activity-7458010353239691264-gbF0&#34;&gt;LinkedIn&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;references--links&#34;&gt;References &amp;amp; links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1 on GitHub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;ARC-1 Documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/tools/&#34;&gt;ARC-1 Tools&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/authorization/&#34;&gt;ARC-1 Authorization and Roles&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/phase4-btp-deployment/&#34;&gt;ARC-1 BTP Cloud Foundry Deployment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;ARC-1 Principal Propagation Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://mcp-sap-docs.marianzeis.de/&#34;&gt;mcp-sap-docs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/JOULE/3fdd7b321eb24d1b9d40605dce822e84&#34;&gt;SAP Help: What is Joule?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/Joule_Studio/45f9d2b8914b4f0ba731570ff9a85313/4444cd1ce4cd471bbe127ea2e4735b40.html&#34;&gt;SAP Help: What is Joule Studio?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/Joule_Studio/45f9d2b8914b4f0ba731570ff9a85313/3d9dfad0bc39468292d508f0808a12fe.html&#34;&gt;SAP Help: Add MCP Servers to Your Joule Agent&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://architecture.learning.sap.com/docs/ref-arch/ca1d2a3e/1&#34;&gt;SAP Architecture Center: A2A and MCP for Interoperability&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/integration-suite/sap-integration-suite/api-management-capability&#34;&gt;SAP Integration Suite API Management&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/btp/btp-developers-guide/use-joule-for-developers-generative-ai-in-abap-cloud&#34;&gt;SAP Joule for Developers&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/abap-ai/generative-ai-in-abap-cloud/joule-for-developers-abap-ai-capabilities-5f175c94900741d6af3dbb23ce37e81a&#34;&gt;SAP Joule for Developers, ABAP AI capabilities&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/joule/serviceguide/sap-consulting-capability-for-joule&#34;&gt;SAP Joule for Consultants&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/doc/sap-api-policy/latest/en-US/API_Policy_latest.pdf&#34;&gt;SAP API Policy&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>ARC-1 with Copilot Studio: SAP System Context Beyond Developers</title>
      <link>https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/</link>
      <pubDate>Mon, 04 May 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/</guid>
      <description>&lt;p&gt;Series note: This post is part of my &lt;a href=&#34;https://blog.zeis.de/tags/ai-abap-development-series/&#34;&gt;AI ABAP development series&lt;/a&gt;, where I go from AI development in general, to ABAP-specific problems, and then to ARC-1.&lt;/p&gt;&#xA;&lt;p&gt;In the &lt;a href=&#34;https://blog.zeis.de/posts/2026-04-29-arc-1-btp/&#34;&gt;previous post&lt;/a&gt;, I wrote about running &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; on SAP BTP. That was the architecture part: central deployment, XSUAA, destinations, Cloud Connector, Principal Propagation, roles, and auditability.&lt;/p&gt;&#xA;&lt;p&gt;This post is the next step. If ARC-1 is already deployed centrally on BTP, then it does not have to be used only from developer tools like VS Code, Claude, Cursor, or Eclipse. It can also be used from &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/&#34;&gt;Microsoft Copilot Studio&lt;/a&gt; and then published into &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/publication-add-bot-to-microsoft-teams&#34;&gt;Teams or Microsoft 365 Copilot&lt;/a&gt;. That changes the audience quite a bit.&lt;/p&gt;&#xA;&lt;p&gt;For developers, ARC-1 is mainly an ADT MCP gateway for code, packages, activation, transports, diagnostics, and system context. MCP is the protocol that lets an AI client call external tools, and ADT is the API layer behind &lt;a href=&#34;https://help.sap.com/docs/btp/sap-business-technology-platform/abap-development-user-guides&#34;&gt;ABAP Development Tools&lt;/a&gt;. But this SAP system access is not only useful for developers. &lt;a href=&#34;https://docs.arc-1-mcp.com/tools/&#34;&gt;ARC-1 tools&lt;/a&gt; can also expose table structures, selected data, messages, transaction metadata, API release state, feature toggles, FLP content, dumps, transport information, and more. Depending on the enabled ARC-1 tools and SAP authorizations, that can become useful for functional consultants, solution architects, testers, security people, and support teams.&lt;/p&gt;&#xA;&lt;p&gt;The question for this post is: what happens if the SAP system context is not only available inside an IDE?&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-copilot-studio-fits-here&#34;&gt;Why Copilot Studio fits here&lt;/h2&gt;&#xA;&lt;p&gt;Functional consultants usually do not live in a local IDE. They work in Teams, Excel, Word, SharePoint, Jira, SAP GUI, Fiori, and many other tools around the actual system. So if the only AI access pattern is &amp;ldquo;install an MCP server locally and configure your IDE&amp;rdquo;, then we miss a large part of the SAP project team.&lt;/p&gt;&#xA;&lt;p&gt;Copilot Studio fits here because it is already close to where many business users work. An agent can be &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/publication-add-bot-to-microsoft-teams&#34;&gt;published into Teams and Microsoft 365 Copilot&lt;/a&gt;. It can use &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/knowledge-add-sharepoint&#34;&gt;SharePoint as a knowledge source&lt;/a&gt;. It can use connectors for systems like &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-365/copilot/connectors/jira-cloud-deployment&#34;&gt;Jira Cloud&lt;/a&gt;, and the same idea also applies to other enterprise sources like Confluence if there is a connector or MCP server for it. I did not use Confluence in this test, but the architecture would be the same. And since Copilot Studio can &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-existing-server-to-agent&#34;&gt;connect to existing MCP servers&lt;/a&gt;, it can also call ARC-1 when the server is deployed to BTP.&lt;/p&gt;&#xA;&lt;p&gt;That does not mean everyone should get write access to SAP from Teams. Quite the opposite. For this kind of usage I would start read-only and very controlled. But even read-only is already powerful if the agent can combine:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;A business specification from SharePoint.&lt;/li&gt;&#xA;&lt;li&gt;SAP documentation from the separately deployed &lt;a href=&#34;https://mcp-sap-docs.marianzeis.de/&#34;&gt;mcp-sap-docs&lt;/a&gt; MCP server.&lt;/li&gt;&#xA;&lt;li&gt;Real system context from ARC-1.&lt;/li&gt;&#xA;&lt;li&gt;Tickets or tasks from Jira.&lt;/li&gt;&#xA;&lt;li&gt;The conversation interface in Teams.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h2 id=&#34;the-architecture-stays-the-same&#34;&gt;The Architecture Stays The Same&lt;/h2&gt;&#xA;&lt;p&gt;Copilot Studio should not create a second SAP access architecture. It should use the same &lt;a href=&#34;https://docs.arc-1-mcp.com/phase4-btp-deployment/&#34;&gt;BTP-deployed ARC-1 endpoint&lt;/a&gt; from the previous post.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Copilot Studio / Teams&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; ARC-1 MCP endpoint on SAP BTP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; XSUAA / OAuth&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; Destination Service&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; Cloud Connector&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; SAP ABAP system&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This means the security story does not change only because the client changes. ARC-1 still has the &lt;a href=&#34;https://docs.arc-1-mcp.com/authorization/#the-model-in-one-picture&#34;&gt;server ceiling&lt;/a&gt;. &lt;a href=&#34;https://docs.arc-1-mcp.com/xsuaa-setup/&#34;&gt;XSUAA roles&lt;/a&gt; still control what the user can do in ARC-1. If &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;Principal Propagation&lt;/a&gt; is active, ARC-1 does not call SAP as one shared technical user. The signed-in user&amp;rsquo;s identity is propagated to the ABAP backend, so SAP checks the request with that user&amp;rsquo;s normal SAP authorizations, for example object, package, transport, table, or &lt;code&gt;S_DEVELOP&lt;/code&gt; permissions.&lt;/p&gt;&#xA;&lt;p&gt;In simpler words: Copilot calls ARC-1 over HTTPS, BTP authenticates the user and resolves the SAP destination, and the Cloud Connector forwards the request to the ABAP system. The server ceiling is the maximum ARC-1 capability the admin enabled for this instance, so a user role can never enable more than the server allows.&lt;/p&gt;&#xA;&lt;p&gt;For Copilot Studio I would be extra conservative with the first setup:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;read/search/diagnose only&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;data preview only for selected users&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;free SQL only for selected users&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;writes disabled by default&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;transport writes disabled&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A Copilot Studio agent can be much more accessible to non-developers than an IDE tool, so the safety model matters even more.&lt;/p&gt;&#xA;&lt;h2 id=&#34;setup&#34;&gt;Setup&lt;/h2&gt;&#xA;&lt;p&gt;I would keep the setup simple and reuse the BTP deployment from the previous post:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Deploy ARC-1 on BTP with &lt;a href=&#34;https://docs.arc-1-mcp.com/xsuaa-setup/&#34;&gt;XSUAA&lt;/a&gt;, &lt;a href=&#34;https://docs.arc-1-mcp.com/btp-destination-setup/&#34;&gt;BTP destinations&lt;/a&gt;, and ideally &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;Principal Propagation&lt;/a&gt;. The detailed steps are in the &lt;a href=&#34;https://docs.arc-1-mcp.com/phase4-btp-deployment/&#34;&gt;BTP deployment guide&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;Keep ARC-1 read-only first, or at least very restricted with &lt;a href=&#34;https://docs.arc-1-mcp.com/authorization/&#34;&gt;ARC-1 authorization and roles&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;In Copilot Studio, add ARC-1 as an &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-existing-server-to-agent&#34;&gt;existing MCP server&lt;/a&gt; with the public HTTPS endpoint from BTP, for example &lt;code&gt;https://arc1-ecc-dev.cfapps.eu10.hana.ondemand.com/mcp&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;Use OAuth 2.0 for the MCP server authentication. Copilot Studio supports manual OAuth configuration for MCP servers, and ARC-1 on BTP can use XSUAA for that.&lt;/li&gt;&#xA;&lt;li&gt;Add &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/knowledge-add-sharepoint&#34;&gt;SharePoint as a knowledge source&lt;/a&gt;, add the &lt;a href=&#34;https://mcp-sap-docs.marianzeis.de/&#34;&gt;SAP documentation MCP server&lt;/a&gt; with its public MCP endpoint &lt;code&gt;https://mcp-sap-docs.marianzeis.de/mcp&lt;/code&gt;, and then add other enterprise sources only where they make sense.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/publication-add-bot-to-microsoft-teams&#34;&gt;Publish the agent to Teams or Microsoft 365 Copilot&lt;/a&gt; after testing.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-existing-server-to-agent&#34;&gt;existing MCP server page&lt;/a&gt; also documents Streamable transport and the API key or OAuth 2.0 authentication options. For SAP system access I would not start with API keys unless it is a very controlled automation scenario, because OAuth gives a better identity story.&lt;/p&gt;&#xA;&lt;p&gt;In my test agent I used ARC-1 on BTP, a Jira MCP server, and SAP Docs as tools. For knowledge, I added SharePoint locations for specifications and IT documents, plus a Jira connector. For this showcase I enabled the available read and write tools.&lt;/p&gt;&#xA;&lt;p&gt;Microsoft&amp;rsquo;s own &lt;a href=&#34;https://learn.microsoft.com/en-us/graph/mcp-server/use-enterprise-mcp-server-copilot-studio&#34;&gt;MCP Server for Enterprise&lt;/a&gt; points in a similar direction for Microsoft Graph: enterprise context should come through governed endpoints, not random local scripts.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio SAP Agent tools screen showing ARC-1 BTP, Jira MCP Server, and SAP Docs as MCP tools.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/copilotstudio-tools.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio SAP Agent knowledge screen showing SharePoint knowledge sources and a Jira connector.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/sapcopilot-knowledge.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;sharepoint-and-sap-documentation&#34;&gt;SharePoint And SAP Documentation&lt;/h2&gt;&#xA;&lt;p&gt;The most natural non-developer setup is probably SharePoint plus SAP docs plus SAP system context. SharePoint is where many specifications and project documents already live, and Copilot Studio can use &lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/knowledge-add-sharepoint&#34;&gt;SharePoint as a knowledge source&lt;/a&gt; while Microsoft authentication keeps the normal document permissions in place.&lt;/p&gt;&#xA;&lt;p&gt;But SharePoint alone is not enough. A specification can say what should happen, but it often does not know how the SAP system actually works today. This is where ARC-1 comes in. The agent can ask ARC-1 for current ABAP objects, CDS views, table structures, message texts, service bindings, transaction metadata, or selected table data, depending on what is enabled and authorized in the &lt;a href=&#34;https://docs.arc-1-mcp.com/authorization/&#34;&gt;ARC-1 tool and role model&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Then I would add the separately deployed &lt;a href=&#34;https://mcp-sap-docs.marianzeis.de/&#34;&gt;mcp-sap-docs&lt;/a&gt; server as the documentation layer, using the public MCP endpoint &lt;code&gt;https://mcp-sap-docs.marianzeis.de/mcp&lt;/code&gt;. It can search SAP documentation, ABAP keyword docs, RAP samples, style guides, DSAG guidelines, SAP Community, and also released object information. That gives the agent a much better chance to not only say &amp;ldquo;this is possible&amp;rdquo;, but also explain what SAP recommends and where the current system differs.&lt;/p&gt;&#xA;&lt;p&gt;This combination is more useful than any single source alone:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SharePoint = what the project wants&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Jira = what needs to be solved&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;mcp-sap-docs = what SAP recommends&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ARC-1 = what the SAP system actually does&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Of these four, ARC-1 is the only one that can read or write actual ABAP in actual SAP. Everything else is orchestration around it.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-real-use-cases-i-tested&#34;&gt;The Real Use Cases I Tested&lt;/h2&gt;&#xA;&lt;p&gt;I created a few small demo scenarios and tested them in Copilot Studio with ARC-1. The screenshots below are from those conversations.&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-case-1-bug-fix-from-a-jira-ticket&#34;&gt;Use Case 1: Bug Fix From A Jira Ticket&lt;/h2&gt;&#xA;&lt;p&gt;The first scenario is still a developer scenario, but it shows the complete loop very well. The Jira ticket &lt;code&gt;KAN-2&lt;/code&gt; only says that a customer with exactly EUR 1,000,000.00 revenue gets the wrong discount tier. Copilot reads the ticket, searches the SAP system, reads &lt;code&gt;ZARC1_DEMO_DISCOUNT&lt;/code&gt;, compares the implementation with the header comment specification, and proposes the one character patch.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Look at KAN-2, propose a patch, but don&amp;#39;t apply it yet.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The important part for me is the confirmation step. The agent does not immediately write to SAP. It first shows the root cause and the diff. Only after the follow-up prompt it updates and activates the report.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Jira ticket KAN-2 describing the wrong discount tier for exactly EUR 1,000,000.00 revenue.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/01/jira-ticket.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio proposing a patch for Jira ticket KAN-2 after reading the ABAP report ZARC1_DEMO_DISCOUNT.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/01/patch-proposal.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio confirming that the patch for ZARC1_DEMO_DISCOUNT was applied and activated.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/01/patch-applied.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;full-answer-viewer.html?case=Use%20Case%201&amp;amp;title=Bug%20fix%20from%20a%20Jira%20ticket&amp;amp;answer=conversations/01/full-answer.txt&#34;&gt;Open the formatted full answer&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This captured run shows both steps: first the patch proposal, then the explicit follow-up to apply and activate it. In a safer setup, the first step alone can already be enough. The developer can copy the suggested diff, review it, test it manually, and keep ARC-1 read-only for that scenario.&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-case-2-sharepoint-change-request-to-impact-analysis&#34;&gt;Use Case 2: SharePoint Change Request To Impact Analysis&lt;/h2&gt;&#xA;&lt;p&gt;The second use case is more interesting for architects. A short SharePoint memo asks to widen &lt;code&gt;ZARC1_DEMO_AMOUNT_DOM&lt;/code&gt; from &lt;code&gt;CURR 13,2&lt;/code&gt; to &lt;code&gt;CURR 23,2&lt;/code&gt;. Copilot reads the memo and then uses ARC-1 to walk the dependency chain in SAP.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Read the change request in IT/Clean Core/ and tell me what would break.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The answer is not just &amp;ldquo;yes, change the domain&amp;rdquo;. It lists the dependency chain from domain to data element to table to report, then explains the risks: activation order, possible table lock, output length, and the hardcoded report layout.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio showing an impact analysis for a SharePoint change request to widen an ABAP amount domain.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/02/impact-analysis.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;full-answer-viewer.html?case=Use%20Case%202&amp;amp;title=SharePoint%20change%20request%20impact%20analysis&amp;amp;answer=conversations/02/full-answer.txt&#34;&gt;Open the formatted full answer&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is where a solution architect or functional consultant benefits from SAP system context without needing an IDE. It turns a business change request into a better technical discussion.&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-case-3-build-a-cds-view-from-a-sharepoint-specification&#34;&gt;Use Case 3: Build A CDS View From A SharePoint Specification&lt;/h2&gt;&#xA;&lt;p&gt;The third use case combines SharePoint, SAP documentation, and ARC-1. The input is a small SharePoint specification for a sales order KPI CDS view. Copilot reads the spec, uses &lt;a href=&#34;https://mcp-sap-docs.marianzeis.de/&#34;&gt;mcp-sap-docs&lt;/a&gt; for SAP documentation and CDS conventions, reads the source table from SAP, and then creates and activates the views.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Build the CDS view from IT/Specifications/spec-orders-kpi.md.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;What I liked in this example is that the agent had to adapt to the system. The first simple idea did not work because the system did not allow arithmetic expressions directly inside aggregate functions. The final result was a two-layer CDS design: a base view for line revenue and a KPI view for aggregation.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio explaining that it created and activated a two-layer CDS view design from a SharePoint specification.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/03/cds-view-built.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;full-answer-viewer.html?case=Use%20Case%203&amp;amp;title=CDS%20view%20from%20a%20SharePoint%20specification&amp;amp;answer=conversations/03/full-answer.txt&#34;&gt;Open the formatted full answer&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is where Copilot Studio becomes more than a chatbot over documents: SharePoint for the requirement, mcp-sap-docs for the SAP pattern, and ARC-1 for the real table and activation.&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-case-4-code-quality-report&#34;&gt;Use Case 4: Code Quality Report&lt;/h2&gt;&#xA;&lt;p&gt;The fourth scenario is reporting only. The prompt asks Copilot to audit the &lt;code&gt;$TMP&lt;/code&gt; &lt;code&gt;ZARC1_DEMO_*&lt;/code&gt; ABAP programs and post a quality report. The captured answer shows the generated Markdown report, not the SharePoint write-back step.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Audit our $TMP ZARC1_DEMO_* ABAP programs and post a quality report.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Copilot searches the SAP system, reads the programs, runs both SAP ATC checks and abaplint, and produces a per-program report with the two findings axes scored against an overall Risk column. It also catches things pure linting would not flag on its own: SQL injection in the dump-trigger report, full-table scans in the invoice list, and table-buffer bypass on &lt;code&gt;USR02&lt;/code&gt;. The same output could then be written to SharePoint, Word, or another document store depending on the connectors and permissions.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio showing an ABAP code quality audit report for ZARC1_DEMO programs.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/04/code-quality-report.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;full-answer-viewer.html?case=Use%20Case%204&amp;amp;title=ABAP%20code%20quality%20report&amp;amp;answer=conversations/04/full-answer.txt&#34;&gt;Open the formatted full answer&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is not mainly a coding example. It gives an architect, technical lead, or quality manager a faster first view: which programs are risky, which findings are only style, and which ones would block a promotion.&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-case-5-short-dump-diagnosis-from-a-jira-ticket&#34;&gt;Use Case 5: Short Dump Diagnosis From A Jira Ticket&lt;/h2&gt;&#xA;&lt;p&gt;The fifth example starts from an intentionally weak Jira ticket. It only says that &lt;code&gt;ZARC1_DEMO_DUMP_RPT&lt;/code&gt; short dumped overnight and that ST22 has the dump. This is close to how many real support tickets start.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Investigate KAN-3 and apply a defensive fix.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Copilot reads the Jira ticket, uses ARC-1 to read short dumps, identifies &lt;code&gt;DBSQL_SQL_ERROR&lt;/code&gt;, reads the report, explains the root cause, and applies a defensive fix. In this demo it adds validation before a dynamic &lt;code&gt;SELECT FROM (p_table)&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Jira ticket KAN-3 with a short description that the ABAP report ZARC1_DEMO_DUMP_RPT short dumped overnight.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/05/jira-dump-ticket.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio showing ST22 short dump analysis and the defensive fix for ZARC1_DEMO_DUMP_RPT.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/05/short-dump-fix.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;full-answer-viewer.html?case=Use%20Case%205&amp;amp;title=Short%20dump%20diagnosis%20from%20Jira&amp;amp;answer=conversations/05/full-answer.txt&#34;&gt;Open the formatted full answer&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In bug fixing, the analysis is often the biggest part. If the agent can collect the ticket, dump, source code, and related objects, then the developer starts much further ahead.&lt;/p&gt;&#xA;&lt;h2 id=&#34;use-case-6-clean-core-readiness-check&#34;&gt;Use Case 6: Clean Core Readiness Check&lt;/h2&gt;&#xA;&lt;p&gt;The last scenario is about clean core readiness. The prompt is simple:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Is ZCL_ARC1_DEMO_CCORE clean-core ready?&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Copilot reads the class through ARC-1 and finds direct selects on &lt;code&gt;USR02&lt;/code&gt; and &lt;code&gt;BUT000&lt;/code&gt;. Then it uses two different context sources for the assessment. ARC-1&amp;rsquo;s &lt;code&gt;API_STATE&lt;/code&gt; read capability asks the SAP system for release state and successor information. The SAP documentation source adds the official guidance around clean core, released APIs, ABAP Cloud readiness, and why direct table access to internal SAP tables is problematic. When SAP documentation returned no entry at all for &lt;code&gt;USR02&lt;/code&gt;, the agent treated that as &amp;ldquo;strictly internal, find a released alternative&amp;rdquo; rather than &amp;ldquo;unknown, assume fine&amp;rdquo;, and inferred the right successor anyway. Based on that combined context, Copilot proposes released successor APIs like &lt;code&gt;I_BUSINESSUSERBASIC&lt;/code&gt; and &lt;code&gt;I_BUSINESSPARTNER&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Copilot Studio showing a clean core readiness analysis for class ZCL_ARC1_DEMO_CCORE.&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-05-05-arc-1-copilot-studio/conversations/06/clean-core-readiness.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;full-answer-viewer.html?case=Use%20Case%206&amp;amp;title=Clean%20core%20readiness%20check&amp;amp;answer=conversations/06/full-answer.txt&#34;&gt;Open the formatted full answer&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 provides the real custom code and the system-specific release state, while SAP documentation provides the official target direction. That makes the result useful for architecture and modernization planning, not only for a developer sitting in an IDE.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-this-matters&#34;&gt;Why This Matters&lt;/h2&gt;&#xA;&lt;p&gt;The important change is not that Copilot Studio can call one more tool. The important change is that a centrally deployed ARC-1 endpoint can make SAP system context available in places where more project roles can use it.&lt;/p&gt;&#xA;&lt;p&gt;Developers still need IDEs, and Copilot Studio does not replace ABAP development tools. But it can become a useful layer for analysis, specification, support, documentation, and architecture work, especially when it combines SAP system context, SAP documentation, SharePoint, Jira, and Microsoft 365 through governed tools and connectors. Without that central architecture, this would again become a local tool story. With BTP, it becomes an enterprise agent story.&lt;/p&gt;&#xA;&lt;h2 id=&#34;discuss-this-post&#34;&gt;Discuss this post&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://saptodon.org/@Mianbsp/116518419049843109&#34;&gt;Saptodon&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://bsky.app/profile/marian.zeis.de/post/3ml2me6teds2q&#34;&gt;Bluesky&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/posts/marianzeis_what-if-copilot-could-start-from-a-support-activity-7457285481433559041-tvAA&#34;&gt;LinkedIn&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;references--links&#34;&gt;References &amp;amp; links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1 on GitHub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;ARC-1 Documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/tools/&#34;&gt;ARC-1 Tools&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/enterprise-auth/&#34;&gt;ARC-1 Authentication Overview&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/phase4-btp-deployment/&#34;&gt;ARC-1 BTP Cloud Foundry Deployment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/xsuaa-setup/&#34;&gt;ARC-1 XSUAA Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/btp-destination-setup/&#34;&gt;ARC-1 BTP Destination Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;ARC-1 Principal Propagation Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/authorization/&#34;&gt;ARC-1 Authorization and Roles&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;mcp-sap-docs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/btp/sap-business-technology-platform/abap-development-user-guides&#34;&gt;SAP Help: ABAP Development Tools for Eclipse: User Guides&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/&#34;&gt;Microsoft Learn: Copilot Studio documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-existing-server-to-agent&#34;&gt;Microsoft Learn: Connect your agent to an existing MCP server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-create-new-server&#34;&gt;Microsoft Learn: Create a new MCP server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/knowledge-add-sharepoint&#34;&gt;Microsoft Learn: Add SharePoint as a knowledge source&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-copilot-studio/publication-add-bot-to-microsoft-teams&#34;&gt;Microsoft Learn: Connect and configure an agent for Teams and Microsoft 365 Copilot&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/microsoft-365/copilot/connectors/jira-cloud-deployment&#34;&gt;Microsoft Learn: Jira Cloud connector for Microsoft 365 Copilot&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/mcp-server/use-enterprise-mcp-server-copilot-studio&#34;&gt;Microsoft Learn: Use Microsoft MCP Server for Enterprise from Copilot Studio&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>ARC-1 on SAP BTP: Secure ABAP Agentic Development Beyond the Laptop</title>
      <link>https://blog.zeis.de/posts/2026-04-29-arc-1-btp/</link>
      <pubDate>Wed, 29 Apr 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-04-29-arc-1-btp/</guid>
      <description>&lt;p&gt;Series note: This post is part of my &lt;a href=&#34;https://blog.zeis.de/tags/ai-abap-development-series/&#34;&gt;AI ABAP development series&lt;/a&gt;, where I go from AI development in general, to ABAP-specific problems, and then to ARC-1.&lt;/p&gt;&#xA;&lt;p&gt;In the &lt;a href=&#34;https://blog.zeis.de/posts/2026-04-27-arc-1/&#34;&gt;previous post&lt;/a&gt;, I introduced &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; as a secure ADT MCP gateway for ABAP systems. The main point was not only that ARC-1 can expose ABAP development functionality to AI clients. The main point was that this access needs a place in the architecture.&lt;/p&gt;&#xA;&lt;p&gt;This post is about that place. If ARC-1 should not run uncontrolled on every developer laptop, then SAP BTP is the most natural enterprise option for me. Not because BTP makes the problem disappear, but because it already has the pieces you need for this kind of setup: XSUAA, destinations, Cloud Connector, role collections, audit logging, and the normal BTP operating model.&lt;/p&gt;&#xA;&lt;p&gt;This is not a full setup guide. The exact commands are in the &lt;a href=&#34;https://docs.arc-1-mcp.com/deployment/&#34;&gt;ARC-1 deployment docs&lt;/a&gt;, the &lt;a href=&#34;https://docs.arc-1-mcp.com/phase4-btp-deployment/&#34;&gt;BTP deployment guide&lt;/a&gt;, and the pages for &lt;a href=&#34;https://docs.arc-1-mcp.com/xsuaa-setup/&#34;&gt;XSUAA&lt;/a&gt;, &lt;a href=&#34;https://docs.arc-1-mcp.com/btp-destination-setup/&#34;&gt;destinations&lt;/a&gt;, and &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;Principal Propagation&lt;/a&gt;. Here I want to explain the architecture options and what I would look at first.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-btp&#34;&gt;Why BTP&lt;/h2&gt;&#xA;&lt;p&gt;The problem with agentic ABAP development is not only context. It is controlled context. The AI needs to read real SAP objects, but the company also needs to know who is authenticated, where credentials live, what the effective permission is, and who can later audit what happened.&lt;/p&gt;&#xA;&lt;p&gt;That is where BTP helps. ARC-1 can run as one central Cloud Foundry application instead of many local MCP servers. The SAP connection can use BTP destinations. On-premise and private cloud systems can be reached through Cloud Connector. Users can authenticate through XSUAA. Role collections can decide who gets read, write, data preview, SQL, transport, git, or admin scopes. If the BTP Audit Log Service is bound, ARC-1 can write audit events into the platform instead of only to a local laptop.&lt;/p&gt;&#xA;&lt;p&gt;For me this is the real difference. A local setup is good for testing and for special cases, but it is not the architecture I would want for a real ABAP team. A central BTP deployment gives you one managed MCP endpoint per SAP system, one place for policy, and no need to store SAP passwords in every developer client.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-basic-shape&#34;&gt;The Basic Shape&lt;/h2&gt;&#xA;&lt;p&gt;The architecture still has the same simple shape:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;MCP client -&amp;gt; ARC-1 -&amp;gt; SAP system&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;But on BTP this becomes two authentication hops:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;AI client&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; XSUAA OAuth&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; ARC-1 on SAP BTP Cloud Foundry&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; Destination Service&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; Connectivity Service&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; Cloud Connector&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  -&amp;gt; SAP ABAP system&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The first hop is the MCP client talking to ARC-1. A client like Claude, Cursor, VS Code, GitHub Copilot for Eclipse, MCP Inspector, or Copilot Studio calls the ARC-1 &lt;code&gt;/mcp&lt;/code&gt; endpoint and authenticates through XSUAA. The second hop is ARC-1 talking to SAP. For that hop, ARC-1 can use a BTP destination with a technical user, a BTP destination with Principal Propagation, or a BTP ABAP Environment service key.&lt;/p&gt;&#xA;&lt;p&gt;For human developer usage, Principal Propagation is the most interesting option. ARC-1 receives the user token, passes it to the Destination Service, and BTP plus Cloud Connector can propagate the user identity to the backend. Then SAP sees the real user instead of one shared technical account. That is important for authorization and for audit.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 uses a dual-destination pattern for this:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SAP_BTP_DESTINATION      = shared BasicAuth destination&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SAP_BTP_PP_DESTINATION   = per-user PrincipalPropagation destination&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SAP_PP_ENABLED           = true&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SAP_XSUAA_AUTH           = true&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The BasicAuth destination is used for startup work like feature probing and cache warmup, because there is no user JWT at startup. The PrincipalPropagation destination is used for authenticated per-user requests. In production I would also look at &lt;code&gt;SAP_PP_STRICT=true&lt;/code&gt;, because then a Principal Propagation problem fails clearly instead of silently falling back to a shared user.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-three-gates&#34;&gt;The Three Gates&lt;/h2&gt;&#xA;&lt;p&gt;The important part is that ARC-1 does not rely on one big switch. A request has to pass three gates:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;The server ceiling: what this ARC-1 instance can ever do, configured with environment variables like &lt;code&gt;SAP_ALLOW_WRITES&lt;/code&gt;, &lt;code&gt;SAP_ALLOW_FREE_SQL&lt;/code&gt;, or &lt;code&gt;SAP_ALLOWED_PACKAGES&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;The user permission: what this user can do inside ARC-1, coming from XSUAA role collections, OIDC scopes, or API-key profiles.&lt;/li&gt;&#xA;&lt;li&gt;The SAP authorization: what the SAP backend user can do, for example through &lt;code&gt;S_DEVELOP&lt;/code&gt;, package authorizations, transport authorizations, or ABAP Cloud restrictions.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;That means the effective permission is an AND model:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Effective permission = server ceiling AND user permission AND SAP authorization&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This is why BTP role collections and ARC-1 safety flags are not the same thing. If the server has &lt;code&gt;SAP_ALLOW_WRITES=false&lt;/code&gt;, a user with &lt;code&gt;ARC-1 Developer&lt;/code&gt; still cannot write. If &lt;code&gt;SAP_ALLOW_FREE_SQL=false&lt;/code&gt;, a user with SQL scope still cannot run freestyle SQL. And even if both ARC-1 layers allow the action, SAP can still reject it.&lt;/p&gt;&#xA;&lt;h2 id=&#34;deployment-options&#34;&gt;Deployment Options&lt;/h2&gt;&#xA;&lt;p&gt;The recommended option is the MTA deployment. ARC-1 includes an &lt;code&gt;mta.yaml&lt;/code&gt; with the Cloud Foundry app and the required services: XSUAA, Destination Service, and Connectivity Service. This is the most reproducible setup because the application and service bindings are described together, similar to how SAP describes multitarget applications for Cloud Foundry.&lt;/p&gt;&#xA;&lt;p&gt;The rough commands are:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;npm run btp:build&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;npm run btp:deploy&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;or combined:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;npm run btp:build-deploy&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Docker on Cloud Foundry is the second option. That can make sense if a company wants to deploy a pinned image from GHCR or an internal registry. You still need the same BTP services, but you manage more yourself with &lt;code&gt;manifest.yml&lt;/code&gt;, &lt;code&gt;cf create-service&lt;/code&gt;, &lt;code&gt;cf bind-service&lt;/code&gt;, and &lt;code&gt;cf set-env&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;A direct Node.js buildpack deployment is also possible, especially if you patch or customize the source and push it directly with &lt;code&gt;cf push&lt;/code&gt;. For a stable team setup, I would start with MTA unless there is a concrete reason not to.&lt;/p&gt;&#xA;&lt;p&gt;BTP ABAP Environment is a separate scenario. There is no Cloud Connector involved. ARC-1 can use a service key and OAuth flow to connect to the ABAP environment. In this case &lt;code&gt;SAP_SYSTEM_TYPE=btp&lt;/code&gt; matters, because ARC-1 adapts tool definitions and avoids on-premise-only object types and assumptions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;configuration-that-matters&#34;&gt;Configuration That Matters&lt;/h2&gt;&#xA;&lt;p&gt;This is not the full reference, but these are the variables I would explain first:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_TRANSPORT&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;http-streamable&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_XSUAA_AUTH&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_BTP_DESTINATION&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;SAP_ECC_DEV&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_BTP_PP_DESTINATION&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;SAP_ECC_DEV_PP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_PP_ENABLED&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_PP_STRICT&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_ALLOW_WRITES&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_ALLOW_DATA_PREVIEW&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_ALLOW_FREE_SQL&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_ALLOW_TRANSPORT_WRITES&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_ALLOW_GIT_WRITES&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nv&#34;&gt;SAP_ALLOWED_PACKAGES&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;$TMP&amp;#39;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The first group makes ARC-1 a remote MCP server with XSUAA authentication. The second group controls the BTP destination setup and Principal Propagation. The third group is the server ceiling, and I would keep it conservative by default.&lt;/p&gt;&#xA;&lt;p&gt;For a development system, you may open selected writes:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf set-env arc1-ecc-dev SAP_ALLOW_WRITES &lt;span class=&#34;nb&#34;&gt;true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf set-env arc1-ecc-dev SAP_ALLOW_TRANSPORT_WRITES &lt;span class=&#34;nb&#34;&gt;true&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf set-env arc1-ecc-dev SAP_ALLOWED_PACKAGES &lt;span class=&#34;s1&#34;&gt;&amp;#39;Z*,$TMP&amp;#39;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf restage arc1-ecc-dev&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;For production, I would usually keep ARC-1 read-only:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf set-env arc1-ecc-prod SAP_ALLOW_WRITES &lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf set-env arc1-ecc-prod SAP_ALLOW_FREE_SQL &lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf set-env arc1-ecc-prod SAP_ALLOW_DATA_PREVIEW &lt;span class=&#34;nb&#34;&gt;false&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cf restage arc1-ecc-prod&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The recommended architecture is like the one-instance-per-SAP-system model. A DEV system can allow selected writes, a PROD system can be read-only, and a BTP ABAP system can have its own endpoint and tool behavior. This keeps policies easier to understand than one large multi-backend gateway.&lt;/p&gt;&#xA;&lt;h2 id=&#34;roles-and-technical-users&#34;&gt;Roles And Technical Users&lt;/h2&gt;&#xA;&lt;p&gt;ARC-1 ships XSUAA scopes like &lt;code&gt;read&lt;/code&gt;, &lt;code&gt;write&lt;/code&gt;, &lt;code&gt;data&lt;/code&gt;, &lt;code&gt;sql&lt;/code&gt;, &lt;code&gt;transports&lt;/code&gt;, &lt;code&gt;git&lt;/code&gt;, and &lt;code&gt;admin&lt;/code&gt;. These are grouped into role collections such as &lt;code&gt;ARC-1 Viewer&lt;/code&gt;, &lt;code&gt;ARC-1 Developer&lt;/code&gt;, &lt;code&gt;ARC-1 Developer + Data&lt;/code&gt;, &lt;code&gt;ARC-1 Developer + SQL&lt;/code&gt;, and &lt;code&gt;ARC-1 Admin&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For human developer usage, I would prefer XSUAA plus Principal Propagation. Then ARC-1 knows the MCP user, and SAP can also see the real SAP user. That gives a much better audit story.&lt;/p&gt;&#xA;&lt;p&gt;But not every use case needs Principal Propagation. For automation, scheduled checks, process agents, or a very controlled BTP Process Automation scenario, a technical user can be fine. The tradeoff just has to be clear: ARC-1 may know which token or client called it, but SAP will see the technical user. With Principal Propagation, SAP sees the real user.&lt;/p&gt;&#xA;&lt;h2 id=&#34;connecting-clients&#34;&gt;Connecting Clients&lt;/h2&gt;&#xA;&lt;p&gt;Once ARC-1 runs centrally, client configuration should become small. Ideally the developer configures only the MCP server URL, not SAP credentials:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-json&#34; data-lang=&#34;json&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;nt&#34;&gt;&amp;#34;mcpServers&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;nt&#34;&gt;&amp;#34;arc1-ecc-dev&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;      &lt;span class=&#34;nt&#34;&gt;&amp;#34;url&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;https://arc1-ecc-dev.cfapps.eu10.hana.ondemand.com/mcp&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;  &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Clients with remote MCP and OAuth discovery can follow the XSUAA flow. ARC-1 exposes OAuth metadata and proxies the flow to XSUAA, so this can work for Claude, Cursor, VS Code-style MCP clients, and MCP Inspector.&lt;/p&gt;&#xA;&lt;p&gt;For Eclipse this becomes more concrete with &lt;a href=&#34;https://marketplace.eclipse.org/content/github-copilot&#34;&gt;GitHub Copilot for Eclipse&lt;/a&gt;. Eclipse ADT can stay the normal ABAP development environment, while Copilot can use MCP to call the same central ARC-1 endpoint. GitHub also added MCP OAuth support for Copilot in Eclipse, JetBrains, and Xcode, so this fits the BTP/XSUAA endpoint model much better than a local server on every laptop. ARC-1 still does not replace Eclipse. It gives the AI part a controlled SAP access path.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-i-would-verify-first&#34;&gt;What I Would Verify First&lt;/h2&gt;&#xA;&lt;p&gt;Before I would enable any write access, I would verify the boring things:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;curl https://arc1-ecc-dev.cfapps.eu10.hana.ondemand.com/health&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;curl https://arc1-ecc-dev.cfapps.eu10.hana.ondemand.com/.well-known/oauth-authorization-server&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Then I would test a read-only MCP call and check the ARC-1 logs. The logs should show which authentication modes are active, for example XSUAA on the MCP side and Principal Propagation on the SAP side.&lt;/p&gt;&#xA;&lt;p&gt;Only after that I would enable writes, and only in steps:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;read-only -&amp;gt; writes to $TMP -&amp;gt; writes to selected packages -&amp;gt; transport writes&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This is less exciting than a demo where the AI writes everything immediately, but it is much closer to how I think enterprise ABAP AI development should be introduced.&lt;/p&gt;&#xA;&lt;h2 id=&#34;where-to-go-deeper&#34;&gt;Where To Go Deeper&lt;/h2&gt;&#xA;&lt;p&gt;The architecture is the important part first, but the actual setup has many landscape-specific details.&lt;/p&gt;&#xA;&lt;p&gt;For the concrete steps, I would start with the &lt;a href=&#34;https://docs.arc-1-mcp.com/phase4-btp-deployment/&#34;&gt;BTP Cloud Foundry deployment guide&lt;/a&gt;, then go through &lt;a href=&#34;https://docs.arc-1-mcp.com/xsuaa-setup/&#34;&gt;XSUAA setup&lt;/a&gt;, &lt;a href=&#34;https://docs.arc-1-mcp.com/btp-destination-setup/&#34;&gt;BTP destination setup&lt;/a&gt;, and &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;Principal Propagation setup&lt;/a&gt; depending on the target landscape.&lt;/p&gt;&#xA;&lt;p&gt;For me the main point stays the same: ARC-1 on BTP is not just a nicer place to host a Node.js app. It is where the MCP server can become part of an enterprise SAP development architecture, with central access, controlled permissions, and a real identity story.&lt;/p&gt;&#xA;&lt;h2 id=&#34;discuss-this-post&#34;&gt;Discuss this post&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://saptodon.org/@Mianbsp/116490533476845801&#34;&gt;Saptodon&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://bsky.app/profile/marian.zeis.de/post/3mkoa3dkw5c27&#34;&gt;Bluesky&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/posts/marianzeis_arc-1-on-btp-is-about-one-simple-shift-agentic-activity-7455473576280817664-6oWh&#34;&gt;LinkedIn&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;references--links&#34;&gt;References &amp;amp; links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1 on GitHub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;ARC-1 Documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/deployment/&#34;&gt;ARC-1 Deployment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/phase4-btp-deployment/&#34;&gt;ARC-1 BTP Cloud Foundry Deployment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/enterprise-auth/&#34;&gt;ARC-1 Enterprise Authentication&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/xsuaa-setup/&#34;&gt;ARC-1 XSUAA Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/btp-destination-setup/&#34;&gt;ARC-1 BTP Destination Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;ARC-1 Principal Propagation Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/authorization/&#34;&gt;ARC-1 Authorization and Roles&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/btp-abap-environment/&#34;&gt;ARC-1 BTP ABAP Environment Setup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/btp/sap-business-technology-platform/multitarget-applications-in-cloud-foundry-environment&#34;&gt;SAP Help: Multitarget Applications in Cloud Foundry&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/btp/sap-business-technology-platform/what-is-sap-authorization-and-trust-management-service&#34;&gt;SAP Help: Authorization and Trust Management Service&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/authenticating-users-against-on-premise-systems&#34;&gt;SAP Help: Authenticating Users Against On-Premise Systems&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://sap.github.io/cloud-sdk/docs/js/features/connectivity/destinations&#34;&gt;SAP Cloud SDK: Destinations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://marketplace.eclipse.org/content/github-copilot&#34;&gt;GitHub Copilot for Eclipse&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.blog/changelog/2025-11-18-enhanced-mcp-oauth-support-for-github-copilot-in-jetbrains-eclipse-and-xcode&#34;&gt;GitHub Changelog: Enhanced MCP OAuth support for Copilot in Eclipse, JetBrains, and Xcode&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>Introducing ARC-1: A Secure ADT MCP Server for Enterprise SAP Development</title>
      <link>https://blog.zeis.de/posts/2026-04-27-arc-1/</link>
      <pubDate>Mon, 27 Apr 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.zeis.de/posts/2026-04-27-arc-1/</guid>
      <description>&lt;p&gt;Series note: This post is part of my &lt;a href=&#34;https://blog.zeis.de/tags/ai-abap-development-series/&#34;&gt;AI ABAP development series&lt;/a&gt;, where I go from AI development in general, to ABAP-specific problems, and then to ARC-1.&lt;/p&gt;&#xA;&lt;p&gt;In the &lt;a href=&#34;https://blog.zeis.de/posts/2026-04-20-how-i-use-ai/&#34;&gt;first post of this series&lt;/a&gt;, I wrote about context and how I use AI in development. In the &lt;a href=&#34;https://blog.zeis.de/posts/2026-04-22-ai-abap-development/&#34;&gt;previous post&lt;/a&gt;, I then moved that discussion into ABAP and ended more or less with one question: what would an ADT MCP setup need to look like if you take control, identity, and security seriously from the beginning?&lt;/p&gt;&#xA;&lt;p&gt;This post is my current answer to that question. It is called &lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1&lt;/a&gt; (ABAP Relay Connector, pronounced arc one [ɑːrk wʌn]), and yes, it is another ADT MCP server. But the important difference is not that it can talk to ADT at all. Other projects already showed very well that this is possible and useful. The difference is the architecture and the focus, which is also why the &lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;ARC-1 documentation&lt;/a&gt; spends a lot of space on security, authentication, deployment, and operations, not only on the tool list.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-arc-1-had-to-exist&#34;&gt;Why ARC-1 had to exist&lt;/h2&gt;&#xA;&lt;p&gt;Luckily, the community already did a lot of the hard work before ARC-1. &lt;a href=&#34;https://github.com/marcellourbani/abap-adt-api&#34;&gt;Marcello Urbani&amp;rsquo;s abap-adt-api&lt;/a&gt; gave many TypeScript projects the foundation to work with ADT APIs at all, which are still not really documented in a useful way. Projects like &lt;a href=&#34;https://github.com/oisee/vibing-steampunk&#34;&gt;oisee/vibing-steampunk&lt;/a&gt;, &lt;a href=&#34;https://github.com/fr0ster/mcp-abap-adt&#34;&gt;fr0ster/mcp-abap-adt&lt;/a&gt;, and &lt;a href=&#34;https://github.com/DassianInc/dassian-adt&#34;&gt;DassianInc/dassian-adt&lt;/a&gt; already proved that MCP and ABAP development can work in practice and can be very useful. And &lt;a href=&#34;https://github.com/lemaiwo/btp-sap-odata-to-mcp-server&#34;&gt;Wouter Lemaire&amp;rsquo;s btp-sap-odata-to-mcp-server&lt;/a&gt; was also important for me, because it already showed a BTP-deployed and centrally managed direction much earlier, and Wouter also helped me during the ARC-1 implementation.&lt;/p&gt;&#xA;&lt;p&gt;So ARC-1 is not me claiming that nobody solved this before. For me it is more this: the others already proved the technical possibility, and ARC-1 is my attempt to close the enterprise gap. That gap is the same one I described in the last post. In ABAP, the hard part is not only getting context into the model. It is that context access, write access, and control are tied very closely together in a real SAP landscape.&lt;/p&gt;&#xA;&lt;p&gt;That is why I did not want to build just another local developer tool that happens to speak MCP. I wanted to build a secure ADT MCP server with a clearer security concept, more central control, and an architecture that fits better into enterprise SAP environments.&lt;/p&gt;&#xA;&lt;h2 id=&#34;central-instead-of-local&#34;&gt;Central instead of local&lt;/h2&gt;&#xA;&lt;p&gt;For me this is probably the biggest architectural difference. Most current MCP ADT setups are still mainly local. The server runs on the developer laptop, gets configured there, stores credentials there, and then talks directly to the SAP system from there.&lt;/p&gt;&#xA;&lt;p&gt;That is fine for trying things out. It is also fine for fast experimentation. And to be clear, ARC-1 can also run locally. That is useful for tests, local development, and simply trying the server out. But local developer setup is not the main story I care about here. The main story is central deployment.&lt;/p&gt;&#xA;&lt;p&gt;That means one managed ARC-1 instance per SAP system, with central configuration, central security settings, central logging, and a clear operational owner. That can run on a company server, in Docker, or ideally on SAP BTP Cloud Foundry. The &lt;a href=&#34;https://docs.arc-1-mcp.com/architecture/&#34;&gt;architecture documentation&lt;/a&gt; goes into the technical flow in more detail, but I will go much deeper into the BTP side in the next post, because that deserves its own post.&lt;/p&gt;&#xA;&lt;p&gt;For me BTP is especially interesting here because it lets you reuse things that already exist in many companies anyway: XSUAA, destinations, Cloud Connector, audit services, role assignment, and the usual BTP login flow. Then the developer mostly just needs the MCP URL and the standard login, while admins and authorization teams keep control in the place where they already work.&lt;/p&gt;&#xA;&lt;p&gt;I also do not think this is only an SAP-specific thought. Salesforce is already moving in a similar direction with &lt;a href=&#34;https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/hosted-mcp-servers-overview.html&#34;&gt;hosted MCP servers&lt;/a&gt; and &lt;a href=&#34;https://www.salesforce.com/news/stories/salesforce-headless-360-announcement/&#34;&gt;Headless 360&lt;/a&gt;, where more of the platform is exposed as APIs, MCP tools, or CLI commands. To me that confirms that enterprise MCP is a platform and governance topic, not only a developer convenience topic.&lt;/p&gt;&#xA;&lt;p&gt;The reason this matters is simple. If the MCP server sits only on the laptop of an individual developer, then the architecture is also controlled there. That is exactly the part I do not find convincing for enterprise usage.&lt;/p&gt;&#xA;&lt;h2 id=&#34;two-auth-hops-matter&#34;&gt;Two auth hops matter&lt;/h2&gt;&#xA;&lt;p&gt;One thing that became very clear while building ARC-1 is that there are really two completely different authentication questions. The first one is who is allowed to talk to the MCP server at all. The second one is as which user the MCP server talks to the SAP system.&lt;/p&gt;&#xA;&lt;p&gt;That sounds obvious, but many discussions around MCP servers blur those two things together. In ARC-1, these are treated as two separate hops: &lt;code&gt;MCP client -&amp;gt; ARC-1&lt;/code&gt; and &lt;code&gt;ARC-1 -&amp;gt; SAP&lt;/code&gt;. This matters because the architecture becomes much clearer after that.&lt;/p&gt;&#xA;&lt;p&gt;For the first hop, ARC-1 can use things like API keys, OIDC/JWT, or &lt;a href=&#34;https://docs.arc-1-mcp.com/enterprise-auth/&#34;&gt;XSUAA OAuth&lt;/a&gt;, depending on how and where it is deployed. For the second hop, ARC-1 can talk to SAP with Basic Auth, BTP service keys, or with &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;Principal Propagation&lt;/a&gt;, depending on the target landscape.&lt;/p&gt;&#xA;&lt;p&gt;That split is very important for enterprise usage, because it lets you separate client access control from SAP identity handling instead of hiding both behind one local config file. It also makes it easier to support different use cases. If ARC-1 is used more like a backend connector for an automation, an API key may be totally fine. If real per-user identity matters, then OAuth or XSUAA plus Principal Propagation is the much more interesting setup.&lt;/p&gt;&#xA;&lt;h2 id=&#34;safe-by-default-not-allow-all-by-default&#34;&gt;Safe by default, not allow all by default&lt;/h2&gt;&#xA;&lt;p&gt;The next big difference is that ARC-1 starts from the assumption that the default should be restrictive. Out of the box ARC-1 is read-only. It blocks free SQL. It blocks named table preview. Transport reads such as list, get, check, and history remain available, but transport mutations require both writes and transport writes to be explicitly enabled. And even if writing is enabled, writes are still restricted to &lt;code&gt;$TMP&lt;/code&gt; unless packages are explicitly allowed.&lt;/p&gt;&#xA;&lt;p&gt;That last point is important to me. Yes, it makes the first setup a bit less magical. Sometimes you need to configure one more thing. But I prefer that over accidentally giving an AI assistant full write access to transportable packages because one flag was too broad.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 also has an action deny list, package restrictions, and safety profiles including &lt;code&gt;viewer&lt;/code&gt;, &lt;code&gt;viewer-data&lt;/code&gt;, &lt;code&gt;viewer-sql&lt;/code&gt;, &lt;code&gt;developer&lt;/code&gt;, &lt;code&gt;developer-data&lt;/code&gt;, &lt;code&gt;developer-sql&lt;/code&gt;, and &lt;code&gt;admin&lt;/code&gt;. So there is not only one on or off switch. For SAP development that feels much more realistic to me than a server that starts by allowing everything and then hopes people will restrict it later.&lt;/p&gt;&#xA;&lt;h2 id=&#34;layered-security-not-just-one-switch&#34;&gt;Layered security, not just one switch&lt;/h2&gt;&#xA;&lt;p&gt;This also leads to the next point. For me, security here is not one boolean setting. It is several layers on top of each other.&lt;/p&gt;&#xA;&lt;p&gt;At the ARC-1 level there is the server safety configuration itself: read-only mode, blocked SQL, package restrictions, the action deny list, and transport gates. Then there is the identity and role layer on top, for example via OIDC or XSUAA scopes and roles. And then there is still the SAP system itself with its own authorization objects and checks.&lt;/p&gt;&#xA;&lt;p&gt;That means all of these layers have to allow something before it actually happens. If ARC-1 is configured read-only, then even a user with a more powerful role still cannot write. If a user has write scope in ARC-1, but the SAP backend authorization is missing, the write still fails.&lt;/p&gt;&#xA;&lt;p&gt;That is exactly how I want it. ARC-1 should not replace SAP authorization. It should add another control layer in front of it.&lt;/p&gt;&#xA;&lt;h2 id=&#34;per-user-identity-matters&#34;&gt;Per-user identity matters&lt;/h2&gt;&#xA;&lt;p&gt;This becomes even more interesting once you look at per-user identity. One of the things I wanted very early is that ARC-1 should not force everything through one shared technical SAP user if that can be avoided.&lt;/p&gt;&#xA;&lt;p&gt;That is why &lt;a href=&#34;https://docs.arc-1-mcp.com/principal-propagation-setup/&#34;&gt;Principal Propagation&lt;/a&gt; is such an important part of the architecture for me. If Principal Propagation is active, the MCP user identity can flow through ARC-1 and into SAP, so that the action runs with the real SAP user and the real SAP authorization of that person. I already tested this and it works.&lt;/p&gt;&#xA;&lt;p&gt;That is important not only because it is cleaner technically. It is important because it fits much better into audit, compliance, and real enterprise authorization models. I do not want the whole architecture to end in &amp;ldquo;trust this one service account and hope nobody asks too many questions later&amp;rdquo;. I want the system to be able to say who actually did what.&lt;/p&gt;&#xA;&lt;h2 id=&#34;audit-logging-is-part-of-the-feature-not-an-afterthought&#34;&gt;Audit logging is part of the feature, not an afterthought&lt;/h2&gt;&#xA;&lt;p&gt;The same applies to audit logging. If AI is allowed to read from or write to a real SAP system, then logging is not some optional extra feature. It is part of the basic architecture.&lt;/p&gt;&#xA;&lt;p&gt;ARC-1 emits structured audit events and can integrate with the &lt;a href=&#34;https://docs.arc-1-mcp.com/security-guide/&#34;&gt;BTP Audit Log Service&lt;/a&gt;. That means you can log who called which tool, what happened, and in which request context it happened. Especially on BTP, that gives you a much better compliance story than a local MCP server that mostly lives on one laptop.&lt;/p&gt;&#xA;&lt;p&gt;For normal hobby tooling this might feel like overkill. For SAP it does not. Especially if the recommended target architecture is BTP, it makes sense to also use the established platform services for logging and identity instead of building a parallel side world around them.&lt;/p&gt;&#xA;&lt;h2 id=&#34;not-locked-into-one-client&#34;&gt;Not locked into one client&lt;/h2&gt;&#xA;&lt;p&gt;This point is also important to me personally. There are already many useful prompt files, local plugins, slash commands, and client-specific workflows around SAP and ABAP. I do not think that is wrong. A lot of that work is useful and practical.&lt;/p&gt;&#xA;&lt;p&gt;But that is still a different architecture. Very often the logic, the access, and the credentials live mainly on one laptop and inside one AI client. For enterprise usage I want the opposite.&lt;/p&gt;&#xA;&lt;p&gt;I want one secure ADT MCP server that can be used from many clients. That can be Claude, &lt;a href=&#34;https://github.com/features/copilot&#34;&gt;GitHub Copilot&lt;/a&gt;, Copilot Studio, IDEs, or later other MCP clients that also support OAuth. In the best case, that can then be combined with Principal Propagation instead of local SAP credentials.&lt;/p&gt;&#xA;&lt;p&gt;That flexibility matters, because in many companies the default AI developer tooling will not be Claude Code. It will more likely be GitHub Copilot or other centrally managed tools. And I do not want the SAP side of the architecture to depend on one specific AI client. MCP is useful exactly because it decouples those things.&lt;/p&gt;&#xA;&lt;h2 id=&#34;testing-matters-more-here-than-for-normal-dev-tooling&#34;&gt;Testing matters more here than for normal dev tooling&lt;/h2&gt;&#xA;&lt;p&gt;I also want to stress the testing part, because for a project like this it matters a lot.&lt;/p&gt;&#xA;&lt;p&gt;If an MCP server only works in one perfect demo system, then that is not enough. SAP systems are messy. Different releases behave differently. Different endpoints exist or do not exist. BTP ABAP is different again. And error handling around ADT is not always beautiful.&lt;/p&gt;&#xA;&lt;p&gt;That is why ARC-1 puts a lot of effort into testing. Right now the project has &lt;a href=&#34;https://github.com/arc-mcp/arc-1#testing&#34;&gt;3,474 unit tests, a 262-test default integration profile, and a 141-test default E2E profile&lt;/a&gt;. The integration and E2E profiles test against live SAP systems, and the E2E tests execute real MCP tool calls against a running ARC-1 server. As a freelancer I obviously do not have access to every possible enterprise landscape, but I do test against real systems. I test against BTP ABAP, the ABAP trial system in Docker, and the older 7.50 trial system.&lt;/p&gt;&#xA;&lt;p&gt;I also do not test only with one ideal model and one toy example. I try it myself with stronger and weaker models and with workflows that are much closer to reality. That includes things like clean core analysis or creating a full RAP project from nothing, not even a table, up to an activated RAP project you can actually use. A lot of the workflows and feature ideas behind that are also visible in the &lt;a href=&#34;https://github.com/arc-mcp/arc-1/blob/main/skills/README.md&#34;&gt;ARC-1 skills catalog&lt;/a&gt;, because those are more or less the kinds of use cases I want to make work reliably.&lt;/p&gt;&#xA;&lt;p&gt;For me that is also one of the big lessons from working with SAP tooling in general: if you do not test against real systems, you often only test your assumptions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;so-yes-this-is-another-adt-mcp-server&#34;&gt;So yes, this is another ADT MCP server&lt;/h2&gt;&#xA;&lt;p&gt;And that is fine. I do not think ARC-1 needs to exist because every other project is wrong. Quite the opposite. The other projects created the category, pushed the ecosystem forward, and showed there is real interest.&lt;/p&gt;&#xA;&lt;p&gt;At the same time I think ARC-1 is different enough in architecture and focus that it makes sense right now. It is especially different from the angle of secure defaults, central deployment, layered security, per-user identity, and auditability.&lt;/p&gt;&#xA;&lt;p&gt;And yes, it now also differentiates itself from SAP&amp;rsquo;s official approach. SAP first announced the server in its &lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/introducing-the-next-era-of-abap-development/ba-p/14260522&#34;&gt;November 4, 2025 post about the next era of ABAP development&lt;/a&gt;. Since then, SAP has &lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/abap-ai-chapter-3-we-go-agentic/ba-p/14391469&#34;&gt;made the official ABAP MCP server available in both Eclipse and VS Code&lt;/a&gt;. I think that is good news.&lt;/p&gt;&#xA;&lt;p&gt;The current difference is architectural. SAP&amp;rsquo;s &lt;a href=&#34;https://help.sap.com/docs/abap-cloud/abap-development-tools-user-guide/configuring-adt-mcp-server-ed94320814734d97801f51a5b6deb802&#34;&gt;configuration guide&lt;/a&gt; describes the ADT MCP server as a local HTTP server hosted by the IDE and protected with a generated bearer token. ARC-1 can also run locally, but the main direction described in this post remains central deployment, BTP integration, enterprise authentication, per-user backend identity, roles, and audit logging.&lt;/p&gt;&#xA;&lt;p&gt;SAP also says that a possible standalone shipment of the ABAP Language Server and MCP Server is still under discussion. If reusable standalone components become available, ARC-1 should evaluate using that foundation instead of reimplementing more and more HTTP details on the community side. For now, the official local server and a centrally deployed ARC-1 instance are two existing approaches with different deployment and governance models.&lt;/p&gt;&#xA;&lt;p&gt;The point is not that my server must win. The point is that different architectures serve different needs, and competition is usually good. It helps people choose, it helps ideas spread, and it gives both SAP and community projects feedback from real use. People can decide whether the official local ADT MCP server, a centrally deployed ARC-1 setup, or both fit their landscape.&lt;/p&gt;&#xA;&lt;h2 id=&#34;a-note-on-adt-apis-and-saps-new-api-policy&#34;&gt;A note on ADT APIs and SAP&amp;rsquo;s new API policy&lt;/h2&gt;&#xA;&lt;p&gt;There is one more point worth separating from the architecture discussion. SAP published a new API policy in April 2026. The &lt;a href=&#34;https://help.sap.com/doc/sap-api-policy/latest/en-US/API_Policy_latest.pdf&#34;&gt;current SAP API Policy is version 4.2026a&lt;/a&gt;. It permits published APIs for their documented use, but says non-published APIs must not be used unless documentation or SAP authorization permits it. It also explicitly restricts API use with generative AI systems that plan, select, or execute sequences of calls outside SAP-endorsed architectures and documented limits. That makes this more than a theoretical support question for SAP customers, partners, and community tools that build on top of SAP development APIs.&lt;/p&gt;&#xA;&lt;p&gt;For ADT, the publicly available material points to a more nuanced situation. SAP provides an official ADT SDK with JavaDoc, and the ADT download page describes it as a public API to implement or integrate your own tools with SAP&amp;rsquo;s ABAP IDE. There is also an SAP document about creating and consuming RESTful APIs in ADT. This does not imply that every internal &lt;code&gt;/sap/bc/adt&lt;/code&gt; endpoint is covered by the same support boundary, but it does show that parts of the ADT tooling and communication model are documented and intended for integration scenarios.&lt;/p&gt;&#xA;&lt;p&gt;Since then, SAP has shipped the ABAP Language Server and MCP Server as parts of Eclipse and VS Code, while a standalone shipment remains under discussion. That does not by itself define the support boundary for every endpoint used by third-party tools. ARC-1&amp;rsquo;s position is therefore deliberately cautious: stay close to documented and discoverable ADT behavior, keep data preview and free SQL off by default, review the SAP policy and the customer&amp;rsquo;s SAP agreement, and ask SAP before production use. The &lt;a href=&#34;https://docs.arc-1-mcp.com/sap-api-policy-and-architecture/&#34;&gt;ARC-1 API Policy and Architecture Alignment&lt;/a&gt; page covers that position in more detail.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-this-matters-for-the-next-post&#34;&gt;Why this matters for the next post&lt;/h2&gt;&#xA;&lt;p&gt;In this post I mainly wanted to explain why ARC-1 exists at all and why it looks the way it does.&lt;/p&gt;&#xA;&lt;p&gt;The next post is where I want to go deeper into the BTP side, because that is where the architecture becomes much more interesting in practice: XSUAA, Destination Service, Cloud Connector, Principal Propagation, and how this can fit into a real enterprise setup instead of just a developer laptop.&lt;/p&gt;&#xA;&lt;h2 id=&#34;discuss-this-post&#34;&gt;Discuss this post&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://saptodon.org/@Mianbsp/116477784495254338&#34;&gt;Saptodon&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://bsky.app/profile/marian.zeis.de/post/3mkikvj4aos2k&#34;&gt;Bluesky&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.linkedin.com/posts/marianzeis_introducing-arc-1-an-enterprise-adt-mcp-activity-7454748910893457408-M8BU&#34;&gt;LinkedIn&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;references--links&#34;&gt;References &amp;amp; links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1&#34;&gt;ARC-1 on GitHub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/&#34;&gt;ARC-1 Documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/architecture/&#34;&gt;ARC-1 Architecture&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/enterprise-auth/&#34;&gt;ARC-1 Authentication Overview&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/security-guide/&#34;&gt;ARC-1 Security Guide&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.zeis.de/posts/2026-04-20-how-i-use-ai/&#34;&gt;How I Use AI for Development and Why Context Matters&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.zeis.de/posts/2026-04-22-ai-abap-development/&#34;&gt;ABAP and Agentic AI: The Hidden Problem in Real Projects&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/marcellourbani/abap-adt-api&#34;&gt;Marcello Urbani: abap-adt-api&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/lemaiwo/btp-sap-odata-to-mcp-server&#34;&gt;Wouter Lemaire: btp-sap-odata-to-mcp-server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/oisee/vibing-steampunk&#34;&gt;oisee/vibing-steampunk&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/fr0ster/mcp-abap-adt&#34;&gt;fr0ster/mcp-abap-adt&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/DassianInc/dassian-adt&#34;&gt;DassianInc/dassian-adt&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/arc-mcp/arc-1/blob/main/skills/README.md&#34;&gt;ARC-1 Skills Catalog&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/introducing-the-next-era-of-abap-development/ba-p/14260522&#34;&gt;Introducing the Next Era of ABAP Development&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/abap-ai-chapter-3-we-go-agentic/ba-p/14391469&#34;&gt;ABAP AI - Chapter 3: We Go Agentic!&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/abap-cloud/abap-development-tools-user-guide/configuring-adt-mcp-server-ed94320814734d97801f51a5b6deb802&#34;&gt;Configuring the ADT MCP Server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/docs/abap-cloud/abap-development-tools-user-guide/model-context-protocol-tools&#34;&gt;SAP Model Context Protocol Tools&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://help.sap.com/doc/sap-api-policy/latest/en-US/API_Policy_latest.pdf&#34;&gt;SAP API Policy&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.arc-1-mcp.com/sap-api-policy-and-architecture/&#34;&gt;ARC-1 API Policy and Architecture Alignment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tools.hana.ondemand.com/#abap&#34;&gt;ABAP Development Tools SDK&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.sap.com/documents/2013/04/12289ce1-527c-0010-82c7-eda71af511fa.html&#34;&gt;Create and Consume RESTful APIs in ADT&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/abap-development-tools-for-vs-code-everything-you-need-to-know/bc-p/14263439/highlight/true#M186133&#34;&gt;ABAP Development Tools for VS Code discussion&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>SAP’s ABAP-1 Loses Every ABAP Benchmark, Even “Explaining”</title>
      <link>https://blog.zeis.de/posts/2026-03-05-abap-llm-benchmark-understanding/</link>
      <pubDate>Tue, 03 Mar 2026 22:00:00 +0100</pubDate>
      <guid>https://blog.zeis.de/posts/2026-03-05-abap-llm-benchmark-understanding/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Previous post (code generation benchmark):&lt;/strong&gt; &lt;a href=&#34;https://blog.zeis.de/posts/2026-02-09-abap-llm-benchmark/&#34;&gt;Benchmarking LLMs for ABAP&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Live benchmark results (old + new):&lt;/strong&gt; &lt;a href=&#34;https://abap-llm-benchmark.marianzeis.de/&#34;&gt;abap-llm-benchmark.marianzeis.de&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In my first evaluation (based on the TH Köln benchmark paper), I extended the original setup with additional models and focused on a very concrete question: how well can LLMs generate ABAP code that actually compiles and passes ABAP Unit tests?&lt;/p&gt;&#xA;&lt;p&gt;I also tested SAP’s model &lt;strong&gt;ABAP-1&lt;/strong&gt;, and it performed very poorly for code generation. To be fair: SAP also states this in the documentation. ABAP-1 is primarily meant &lt;a href=&#34;https://help.sap.com/docs/sap-ai-core/generative-ai/sap-abap-1?locale=en-US&#34;&gt;for explaining ABAP code&lt;/a&gt; not for reliably generating full working implementations.&lt;/p&gt;&#xA;&lt;p&gt;So I built a second test that targets exactly that: understanding and explaining ABAP.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-understanding-test&#34;&gt;The “Understanding” test&lt;/h2&gt;&#xA;&lt;p&gt;In the “Understanding” benchmark, the model gets existing ABAP code plus the corresponding ABAP Unit tests (so this is not a generation task). From that, it must extract concrete facts as structured JSON, for example:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;which classes and methods are relevant&lt;/li&gt;&#xA;&lt;li&gt;expected behavior and validations&lt;/li&gt;&#xA;&lt;li&gt;inputs and outputs&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The JSON output is then scored automatically against a reference, so we can measure in a reproducible way how well a model understands ABAP code and describes it correctly. This works without running SAP or ADT.&lt;/p&gt;&#xA;&lt;p&gt;Here is the key result as a chart (cumulative success across feedback rounds):&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;ABAP understanding benchmark: cumulative success rates by model and feedback round&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-03-05-abap-llm-benchmark-understanding/images/understanding_success_by_model_by_feedbackround_in_percent.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-this-says-about-abap-1&#34;&gt;What this says about ABAP-1&lt;/h2&gt;&#xA;&lt;p&gt;As expected, ABAP-1 is clearly better in this “Understanding” setup than in code generation. But it still does not keep up with current general-purpose models.&lt;/p&gt;&#xA;&lt;p&gt;Even the current Anthropic Haiku model (optimized for speed and cost) beats ABAP-1 on this benchmark.&lt;/p&gt;&#xA;&lt;p&gt;That makes the practical conclusion pretty simple: &lt;strong&gt;for almost any ABAP use case, ABAP-1 is not a good default choice.&lt;/strong&gt; It is priced closer to premium models, but does not deliver premium results. So the “maybe it is cheaper” argument also does not hold.&lt;/p&gt;&#xA;&lt;h2 id=&#34;new-models&#34;&gt;New models&lt;/h2&gt;&#xA;&lt;p&gt;After the first post, people asked for more models to be added. I’m tracking those requests as GitHub issues here: &lt;a href=&#34;https://github.com/marianfoo/LLM-Benchmark-ABAP-Code-Generation/issues?q=sort%3Aupdated-desc%20is%3Aissue&#34;&gt;LLM-Benchmark-ABAP-Code-Generation issues&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I added the following models:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;DeepSeek Reasoner&lt;/li&gt;&#xA;&lt;li&gt;Mistral Large 2512&lt;/li&gt;&#xA;&lt;li&gt;GPT-5.3 Codex&lt;/li&gt;&#xA;&lt;li&gt;Claude Haiku 4.5&lt;/li&gt;&#xA;&lt;li&gt;Gemini 3.1 Flash Preview&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;To put the “new models” into context, here is the updated &lt;strong&gt;code generation&lt;/strong&gt; overview (this is the original benchmark: generate ABAP, then iterate with compiler/test feedback up to 5 rounds). The plot already includes the new lineup:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;ABAP code generation benchmark: cumulative successful code generations by model and feedback round&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-03-05-abap-llm-benchmark-understanding/images/success_by_model_by_feedbackround_in_percent.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;GPT-5.3 Codex produced very strong results and even beat Opus 4.5 on some metrics. My guess is: if we compare against Opus 4.6, the gap will likely be small (or they might end up roughly equal).&lt;/p&gt;&#xA;&lt;p&gt;Depending on the metric, Opus 4.5 is still excellent: it has the highest first-try success rate (Round 0) and the best AUC across all feedback rounds.&lt;/p&gt;&#xA;&lt;p&gt;Unfortunately, Mistral’s current “best” model performed worse than I expected and does not look like a great choice for ABAP.&lt;/p&gt;&#xA;&lt;p&gt;For price/performance, DeepSeek Reasoner is the clear winner in this lineup.&lt;/p&gt;&#xA;&lt;p&gt;Using the public list prices (at the time of writing), Codex is at around &lt;strong&gt;$1.75 per 1M input tokens&lt;/strong&gt;, while DeepSeek Reasoner is at &lt;strong&gt;$0.28 per 1M input tokens&lt;/strong&gt; (more than 6x cheaper). The bigger difference is output: DeepSeek output is &lt;strong&gt;$0.42 per 1M tokens&lt;/strong&gt;, while Codex output is around &lt;strong&gt;$14.00 per 1M tokens&lt;/strong&gt; (about 33x).&lt;/p&gt;&#xA;&lt;h3 id=&#34;gemini-31-flash-preview&#34;&gt;Gemini 3.1 Flash Preview&lt;/h3&gt;&#xA;&lt;p&gt;Gemini 3.1 Flash Preview also surprised me with strong results. It is cheap and in my runs it was even slightly ahead of GPT-5.3 Codex, while being significantly cheaper.&lt;/p&gt;&#xA;&lt;p&gt;At the time of writing, Gemini Flash was roughly &lt;strong&gt;$0.50 per 1M input tokens&lt;/strong&gt; and &lt;strong&gt;$3.00 per 1M output tokens&lt;/strong&gt;, which is a big difference compared to Codex pricing.&lt;/p&gt;&#xA;&lt;p&gt;Unfortunately, I could not test Gemini 3.1 Pro: the rate limit was effectively capped at ~25 requests per minute and I repeatedly hit 503 errors (“system overloaded”). With several thousand requests, that made a full benchmark run impractical. My guess is that Gemini 3.1 Pro would be similar to, or better than, GPT-5.3 Codex, but Flash already delivered very good results.&lt;/p&gt;&#xA;&lt;h3 id=&#34;why-haiku-45-did-so-badly-here&#34;&gt;Why Haiku 4.5 did so badly here&lt;/h3&gt;&#xA;&lt;p&gt;Haiku 4.5 failed systematically because it kept using CDS-style type notation like &lt;code&gt;abap.char(20)&lt;/code&gt; in classic ABAP implementations (syntax errors). Worse, misleading parser error messages made it hard for the model to identify the real root cause, so it did not correct itself even across multiple feedback rounds.&lt;/p&gt;&#xA;&lt;h2 id=&#34;a-practical-takeaway&#34;&gt;A practical takeaway&lt;/h2&gt;&#xA;&lt;p&gt;For me, this is now a pretty solid baseline to decide which models are worth considering for ABAP, and which ones are not, depending on whether you care more about API calls (cost) or daily development (quality + speed).&lt;/p&gt;&#xA;&lt;p&gt;One important reminder: these models acted only on what they already “know”. Results can be improved a lot with tooling and better context, for example:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;ABAP MCP Server&lt;/strong&gt; for ABAP best practices and keyword documentation: &lt;a href=&#34;https://github.com/marianfoo/abap-mcp-server&#34;&gt;marianfoo/abap-mcp-server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;abaplint&lt;/strong&gt; for static checks and fast feedback loops: &lt;a href=&#34;https://abaplint.org/&#34;&gt;abaplint.org&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;With that kind of tooling and feedback loop, you can generate very good ABAP code even if you “only” use a strong general model.&lt;/p&gt;&#xA;&lt;p&gt;And yes, my conclusion from the first post still stands: I would not recommend ABAP-1. If SAP wants better outcomes, I think the bigger lever is not “yet another model”, but better tools and better integration so frontier models (OpenAI, Anthropic, Google) can reliably produce correct ABAP in real-world projects.&lt;/p&gt;&#xA;&lt;p&gt;You can still suggest models I have not tested yet, but benchmarks like this are not cheap. For now I will pause adding more models unless there is a very strong reason to do another run.&lt;/p&gt;&#xA;&lt;h2 id=&#34;references--links&#34;&gt;References &amp;amp; links&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;TH Köln paper: &lt;a href=&#34;https://arxiv.org/html/2601.15188v1&#34;&gt;Benchmarking Large Language Models for ABAP Code Generation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Previous post (code generation benchmark): &lt;a href=&#34;https://blog.zeis.de/posts/2026-02-09-abap-llm-benchmark/&#34;&gt;Benchmarking LLMs for ABAP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Live results website: &lt;a href=&#34;https://abap-llm-benchmark.marianzeis.de/&#34;&gt;abap-llm-benchmark.marianzeis.de&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Original benchmark repo (TH Köln): &lt;a href=&#34;https://github.com/timkoehne/LLM-Benchmark-ABAP-Code-Generation&#34;&gt;timkoehne/LLM-Benchmark-ABAP-Code-Generation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Dataset (prompts + ABAP Unit tests): &lt;a href=&#34;https://github.com/timkoehne/LLM-Benchmark-ABAP-Code-Generation/tree/main/dataset&#34;&gt;dataset folder&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Benchmark repo (my fork with updates): &lt;a href=&#34;https://github.com/marianfoo/LLM-Benchmark-ABAP-Code-Generation&#34;&gt;marianfoo/LLM-Benchmark-ABAP-Code-Generation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Model requests / discussion: &lt;a href=&#34;https://github.com/marianfoo/LLM-Benchmark-ABAP-Code-Generation/issues?q=sort%3Aupdated-desc%20is%3Aissue&#34;&gt;GitHub issues&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;SAP ABAP-1 documentation: &lt;a href=&#34;https://help.sap.com/docs/sap-ai-core/generative-ai/sap-abap-1?locale=en-US&#34;&gt;SAP ABAP-1&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;ABAP Cloud Developer Trial (Docker image used by the benchmark): &lt;a href=&#34;https://github.com/SAP-docs/abap-platform-trial-image&#34;&gt;SAP-docs/abap-platform-trial-image&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Batch APIs (used for running large benchmarks cheaper): &lt;a href=&#34;https://platform.openai.com/docs/guides/batch&#34;&gt;OpenAI Batch API&lt;/a&gt;, &lt;a href=&#34;https://docs.anthropic.com/en/docs/build-with-claude/batch-processing&#34;&gt;Anthropic batch processing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Pricing references:&#xA;&lt;ul&gt;&#xA;&lt;li&gt;OpenAI: &lt;a href=&#34;https://openai.com/api/pricing&#34;&gt;API pricing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;DeepSeek: &lt;a href=&#34;https://api-docs.deepseek.com/quick_start/pricing/&#34;&gt;Pricing (official docs)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Google Gemini: &lt;a href=&#34;https://cloud.google.com/gemini-enterprise-agent-platform/generative-ai/pricing&#34;&gt;generative AI pricing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Anthropic: &lt;a href=&#34;https://docs.anthropic.com/en/docs/about-claude/pricing&#34;&gt;Claude API pricing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>Benchmarking LLMs for ABAP: Why ABAP-1 Isn&#39;t a Code Generator (Yet)</title>
      <link>https://blog.zeis.de/posts/2026-02-09-abap-llm-benchmark/</link>
      <pubDate>Mon, 09 Feb 2026 09:30:00 +0100</pubDate>
      <guid>https://blog.zeis.de/posts/2026-02-09-abap-llm-benchmark/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Live benchmark results:&lt;/strong&gt; &lt;a href=&#34;http://abap-llm-benchmark.marianzeis.de/&#34;&gt;abap-llm-benchmark.marianzeis.de&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In a lot of SAP webcasts and webinars, especially around AI, the question comes up very early: which model are you using, and which one do you recommend?&lt;/p&gt;&#xA;&lt;p&gt;For &lt;a href=&#34;https://cap.cloud.sap/docs/&#34;&gt;CAP&lt;/a&gt; and &lt;a href=&#34;https://ui5.sap.com/&#34;&gt;UI5&lt;/a&gt; the answer is usually pretty simple: use the current best model from Anthropic. If you add good context via &lt;a href=&#34;https://community.sap.com/t5/technology-blog-posts-by-sap/sap-build-introduces-new-mcp-servers-to-enable-agentic-development-for/ba-p/14205602&#34;&gt;MCP servers&lt;/a&gt; from the community or SAP, you are basically fine. There is just a lot of public knowledge available, and most of it is in JavaScript/TypeScript, which LLMs handle extremely well.&lt;/p&gt;&#xA;&lt;p&gt;With ABAP it&amp;rsquo;s different.&lt;/p&gt;&#xA;&lt;p&gt;ABAP is not the framework, it&amp;rsquo;s the language. And compared to JavaScript/TypeScript, far less ABAP knowledge and code is publicly accessible, so models simply know much less about it.&lt;/p&gt;&#xA;&lt;p&gt;Sure, you can help with extra context and tooling, but if you want this to work well, the model should already have a solid ABAP base. A good foundation makes it much easier to build on top.&lt;/p&gt;&#xA;&lt;p&gt;So how do you figure out which models are actually best for ABAP? Anthropic, Google, OpenAI, or maybe &lt;a href=&#34;https://help.sap.com/docs/sap-ai-core/generative-ai/sap-abap-1?locale=en-US&#34;&gt;ABAP-1&lt;/a&gt; from SAP?&lt;/p&gt;&#xA;&lt;p&gt;Luckily, TH Köln recently published a paper that answers exactly this question: &lt;a href=&#34;https://arxiv.org/html/2601.15188v1&#34;&gt;Benchmarking Large Language Models for ABAP Code Generation&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;the-benchmark&#34;&gt;The benchmark&lt;/h2&gt;&#xA;&lt;p&gt;The paper builds a benchmark so different LLMs can be compared fairly for ABAP code generation.&lt;/p&gt;&#xA;&lt;p&gt;It includes 180 tasks (&lt;a href=&#34;https://github.com/marianfoo/LLM-Benchmark-ABAP-Code-Generation/tree/main/dataset/abap_canonical_solution&#34;&gt;HumanEval&lt;/a&gt; adapted to ABAP plus a set of ABAP/SAP practical scenarios). The flow is fully automated: the model generates ABAP code, the code is created and activated in a fixed SAP environment (&lt;a href=&#34;https://github.com/SAP-docs/abap-platform-trial-image&#34;&gt;ABAP Cloud Developer Trial image documentation&lt;/a&gt;), and then ABAP Unit tests run against it.&lt;/p&gt;&#xA;&lt;p&gt;If syntax checks or tests fail, the model gets the error messages as feedback and can try again for up to 5 rounds. In the end, it&amp;rsquo;s not about whether the code &amp;ldquo;looks plausible&amp;rdquo;, but whether it actually passes the tests (and how quickly it gets there).&lt;/p&gt;&#xA;&lt;p&gt;The nice part: the authors published everything.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Original code&lt;/strong&gt;: &lt;a href=&#34;https://github.com/timkoehne/LLM-Benchmark-ABAP-Code-Generation&#34;&gt;LLM-Benchmark-ABAP-Code-Generation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Dataset (prompts, unit tests, expected classes)&lt;/strong&gt;: &lt;a href=&#34;https://github.com/timkoehne/LLM-Benchmark-ABAP-Code-Generation/tree/main/dataset&#34;&gt;dataset folder&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;My updated benchmark repo (additional models, speed-ups, plots, data, webpage)&lt;/strong&gt;: &lt;a href=&#34;https://github.com/marianfoo/LLM-Benchmark-ABAP-Code-Generation&#34;&gt;marianfoo/LLM-Benchmark-ABAP-Code-Generation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;updating-the-benchmark&#34;&gt;Updating the benchmark&lt;/h2&gt;&#xA;&lt;p&gt;One small problem: the evaluation in the paper is from mid-2025 (for example using GPT-5 and Claude Sonnet 4). The model landscape moves fast, and now we already have things like GPT-5.3 and &lt;a href=&#34;https://www.anthropic.com/news/claude-opus-4-6&#34;&gt;Claude Opus 4.6&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;So I wanted a way to update the results and include additional models that are relevant for ABAP.&lt;/p&gt;&#xA;&lt;p&gt;I built on the original benchmark and added runs for additional models, so I can compare them against the original GPT-5 and Sonnet numbers:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Anthropic Claude Opus 4.5 (4.6 will be next)&lt;/li&gt;&#xA;&lt;li&gt;OpenAI GPT-5.2&lt;/li&gt;&#xA;&lt;li&gt;SAP ABAP-1&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;I also made a few changes to speed up execution:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;For OpenAI and Anthropic I used the vendor batch APIs like in the original code (&lt;a href=&#34;https://platform.openai.com/docs/guides/batch&#34;&gt;OpenAI Batch API&lt;/a&gt;, &lt;a href=&#34;https://docs.anthropic.com/en/docs/build-with-claude/batch-processing&#34;&gt;Anthropic batch processing&lt;/a&gt;). GPT-5.2 Codex was not available via batch for me yet, but that model will be next.&lt;/li&gt;&#xA;&lt;li&gt;ABAP-1 has no batch API, so I implemented a parallel execution with multiple threads.&lt;/li&gt;&#xA;&lt;li&gt;I also parallelized the execution on the ABAP Trial system itself to reduce overall runtime. I&amp;rsquo;m happy I have a well-equipped MacBook, but during the runs RAM usage and fan speed were definitely not idle.&lt;/li&gt;&#xA;&lt;li&gt;Since there is a lot of Python code and I don&amp;rsquo;t know Python well enough, all the coding was done with AI help.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The next step is a small website with an overview of the current results and an easy model comparison.&lt;/p&gt;&#xA;&lt;p&gt;You can find the current results here: &lt;a href=&#34;http://abap-llm-benchmark.marianzeis.de/&#34;&gt;abap-llm-benchmark.marianzeis.de&lt;/a&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;so-what-is-the-best-model-for-abap&#34;&gt;So what is the best model for ABAP?&lt;/h2&gt;&#xA;&lt;p&gt;Not too surprising: the best results came from GPT-5 and Claude Opus 4.5, with a small edge for Opus.&lt;/p&gt;&#xA;&lt;p&gt;To make it more concrete, here are the cumulative success rates from my current comparison (Round 0 = first attempt, Round 5 = after up to 5 feedback iterations with compiler/test errors):&lt;/p&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;Model&lt;/th&gt;&#xA;          &lt;th style=&#34;text-align: right&#34;&gt;Round 0&lt;/th&gt;&#xA;          &lt;th style=&#34;text-align: right&#34;&gt;Round 5&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Claude Opus 4.5&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;31.61%&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;78.72%&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;GPT-5&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;19.28%&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;77.11%&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;GPT-5.2&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;16.33%&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;64.00%&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;SAP ABAP-1&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;10.67%&lt;/td&gt;&#xA;          &lt;td style=&#34;text-align: right&#34;&gt;19.89%&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;Here is the same as a chart:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;ABAP LLM benchmark: cumulative success rates by model (GPT-5, Claude Opus 4.5, ABAP-1) and feedback round&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-02-09-abap-llm-benchmark/success_by_model_by_feedbackround_in_percent.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;cost-rough-numbers&#34;&gt;Cost (rough numbers)&lt;/h3&gt;&#xA;&lt;p&gt;One more thing people ask quickly: cost.&lt;/p&gt;&#xA;&lt;p&gt;For my run, I ended up at about $20.26 for GPT-5.2, $39.76 for Claude Opus 4.5 (8,973,159 tokens), and EUR 98.80 for ABAP-1 (17,983,990 tokens).&lt;/p&gt;&#xA;&lt;p&gt;To be fair: for OpenAI and Anthropic I used batch processing, so these numbers are already discounted (batch is usually cheaper, sometimes roughly half compared to the regular API). ABAP-1 has no batch API, so there is no discount like that.&lt;/p&gt;&#xA;&lt;p&gt;Why was ABAP-1 so much more expensive? The benchmark is iterative: when activation or ABAP Unit tests fail, you send the error back to the model and try again. Since ABAP-1 produced errors much more often, many prompts did not get &amp;ldquo;finished&amp;rdquo; early and had to be sent again and again, which drives up tokens and cost.&lt;/p&gt;&#xA;&lt;p&gt;What I find interesting here is not only the final number, but also how the models behave across the feedback loops.&lt;/p&gt;&#xA;&lt;h3 id=&#34;why-is-gpt-52-worse-than-gpt-5-in-this-benchmark&#34;&gt;Why is GPT-5.2 worse than GPT-5 (in this benchmark)?&lt;/h3&gt;&#xA;&lt;p&gt;I can&amp;rsquo;t prove the exact reason (this is a black box), but based on the patterns in the benchmark it looks like GPT-5 is simply better at using compiler feedback to dig itself out of ABAP syntax and declaration issues.&lt;/p&gt;&#xA;&lt;p&gt;GPT-5.2 still does fine, but compared to GPT-5 it is:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;less consistent across reruns (about 41% of prompts solved 10/10 vs about 59% for GPT-5)&lt;/li&gt;&#xA;&lt;li&gt;less likely to recover from certain ABAP-specific errors within a few feedback rounds&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;My best guess is that GPT-5.2 is tuned differently (for example more general, faster, cheaper, or optimized for other coding workflows), and that does not translate 1:1 to &amp;ldquo;generate a full ABAP class that compiles and passes ABAP Unit tests&amp;rdquo;. Maybe when using the codex model, the results are better.&lt;/p&gt;&#xA;&lt;h3 id=&#34;claude-opus-45&#34;&gt;Claude Opus 4.5&lt;/h3&gt;&#xA;&lt;p&gt;Opus starts very strong in Round 0. That usually means less back and forth for basic ABAP class structure and syntax, and more time spent on the actual logic.&lt;/p&gt;&#xA;&lt;p&gt;In practice, this is what you want: you want to reach the unit test stage quickly, because that feedback is much more actionable than &amp;ldquo;your code does not activate&amp;rdquo;.&lt;/p&gt;&#xA;&lt;h3 id=&#34;sap-abap-1&#34;&gt;SAP ABAP-1&lt;/h3&gt;&#xA;&lt;p&gt;ABAP-1 is clearly not competitive for code generation in this benchmark, and it also benefits much less from the feedback loops.&lt;/p&gt;&#xA;&lt;p&gt;This matches what SAP writes in the docs: ABAP-1 is mainly meant to explain ABAP code, while generation is experimental. For me, ABAP-1 is still useful as an &amp;ldquo;ABAP explainer&amp;rdquo;, but if you want to generate correct ABAP code fast, you still want a strong general model plus good tooling and feedback loops.&lt;/p&gt;&#xA;&lt;h3 id=&#34;what-this-means-in-practice&#34;&gt;What this means in practice&lt;/h3&gt;&#xA;&lt;p&gt;This matters most when you work with APIs and actually build things. If you only call APIs, the model choice matters more. If you actively develop, it matters a bit less because we can add a lot of context and feedback loops.&lt;/p&gt;&#xA;&lt;p&gt;When developing ABAP, we can provide much more context (for example via my &lt;a href=&#34;https://github.com/marianfoo/abap-mcp-server&#34;&gt;ABAP MCP server&lt;/a&gt;), catch syntax errors early, run tools like &lt;a href=&#34;https://abaplint.org/&#34;&gt;abaplint&lt;/a&gt;, and then feed that back into the LLM to improve the code, basically like in TypeScript. That usually gets you to pretty good ABAP code that also follows your rules.&lt;/p&gt;&#xA;&lt;p&gt;Depending on cost, I&amp;rsquo;ll try to keep this up to date with newer models. If you have a model you want to see in the comparison, just open an issue in the benchmark repo: &lt;a href=&#34;https://github.com/marianfoo/LLM-Benchmark-ABAP-Code-Generation/issues&#34;&gt;GitHub issues&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Big thanks to Stephan Wallraven, Tim Köhne, Hartmut Westenberger, and Andreas Moser for creating the foundation with their benchmark and paper.&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>Network Request &amp; Response Copier: An OData-Friendly DevTools Request Viewer</title>
      <link>https://blog.zeis.de/posts/2026-02-05-networkcopier-chrome/</link>
      <pubDate>Thu, 05 Feb 2026 09:30:00 +0100</pubDate>
      <guid>https://blog.zeis.de/posts/2026-02-05-networkcopier-chrome/</guid>
      <description>&lt;p&gt;AI assistants already help a lot, but they work best when you can give them good context. In web apps, the most important context is usually the real traffic between frontend and backend: &lt;strong&gt;request URLs, payloads, and responses&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;When debugging, I want to copy that information quickly and completely. And since I mostly work with &lt;strong&gt;UI5 and OData&lt;/strong&gt;, I usually need the full URL plus request and response body. In Chrome DevTools that often means a lot of manuall copy pasting, and if you need more than one request, it gets annoying fast.&lt;/p&gt;&#xA;&lt;p&gt;So I did the obvious thing: I built a small Chrome DevTools extension with AI help that solves this problem for me. Yes, I could also use MCP tooling or an automated browser to extract network data, but for day-to-day debugging I care about speed and I usually know exactly which requests matter.&lt;/p&gt;&#xA;&lt;p&gt;After using it locally for a while, I decided to publish my first extension in the Chrome Web Store.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Network Request &amp;amp; Response Copier inside Chrome DevTools&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-02-05-networkcopier-chrome/screenshot.jpg&#34;&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;Install it here:&lt;/strong&gt; &lt;a href=&#34;https://chromewebstore.google.com/detail/network-request-response/mphiaidjajmllkfkjlkfgmfkccpnomgc&#34;&gt;Chrome Web Store&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Update (2026-02-10):&lt;/strong&gt; Also available in the &lt;a href=&#34;https://microsoftedge.microsoft.com/addons/detail/network-request-respons/mmfhobojdlgibnffjhkidhdcjfbfhgpo&#34;&gt;Microsoft Edge Add-ons store&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Source code:&lt;/strong&gt; &lt;a href=&#34;https://github.com/marianfoo/chrome-extension-copynetworkrequests&#34;&gt;GitHub&lt;/a&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;the-solution&#34;&gt;The solution&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Network Request &amp;amp; Response Copier&lt;/strong&gt; adds a dedicated panel to DevTools that shows network entries in a clean, sortable list.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Left panel&lt;/strong&gt;: sortable request list with filters, a payload preview, and pinning&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Right panel&lt;/strong&gt;: request payload (top) and response body (bottom)&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Copy buttons&lt;/strong&gt;: copy the selected entry, all filtered entries, or all pinned entries&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;And the part that matters most for my work: it makes OData traffic much easier to work with, especially &lt;code&gt;$batch&lt;/code&gt; requests.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;key-features&#34;&gt;Key features&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Copy in one click&lt;/strong&gt;: Copy the selected entry with &lt;code&gt;Ctrl/Cmd+C&lt;/code&gt;, or export all filtered or pinned entries. Output includes method, URL, payload, and response in one readable block.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;OData &lt;code&gt;$batch&lt;/code&gt; parsing&lt;/strong&gt;: Splits multipart &lt;code&gt;$batch&lt;/code&gt; into per-operation blocks and shows a quick “what’s inside” preview in the list (for example: &lt;code&gt;PATCH MockConfig | GET Users&lt;/code&gt;).&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Better OData overview&lt;/strong&gt;: Keeps long &lt;code&gt;$select&lt;/code&gt; and &lt;code&gt;$filter&lt;/code&gt; URLs readable and shows request and response side-by-side, which makes sharing context (and debugging) much faster.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;WebSocket included&lt;/strong&gt;: Captures sent and received messages and shows them alongside HTTP entries.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;DevTools-like workflow&lt;/strong&gt;: Sort, search, filter by method, resize panes, pin important calls.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Stays fast&lt;/strong&gt;: 500-entry cap, throttled UI updates, cached parsing.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;how-it-works-short-version&#34;&gt;How it works (short version)&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Runs as a DevTools panel, so it only exists while DevTools is open.&lt;/li&gt;&#xA;&lt;li&gt;Collects HTTP traffic via &lt;code&gt;chrome.devtools.network.onRequestFinished&lt;/code&gt; (HAR entries).&lt;/li&gt;&#xA;&lt;li&gt;Detects and parses &lt;code&gt;$batch&lt;/code&gt; payloads to show a per-operation overview.&lt;/li&gt;&#xA;&lt;li&gt;Captures WebSocket messages by instrumenting &lt;code&gt;WebSocket&lt;/code&gt; in the inspected page.&lt;/li&gt;&#xA;&lt;li&gt;Copies to clipboard with fallbacks that work in the DevTools environment.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;You&amp;rsquo;re welcome to use it and let me know what you think, try it out suggest changes!&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>Finally: An MCP Server for ABAP</title>
      <link>https://blog.zeis.de/posts/2026-02-04-abap-mcp-server/</link>
      <pubDate>Wed, 04 Feb 2026 09:30:00 +0100</pubDate>
      <guid>https://blog.zeis.de/posts/2026-02-04-abap-mcp-server/</guid>
      <description>&lt;p&gt;Finally, there is an MCP server for ABAP.&lt;/p&gt;&#xA;&lt;p&gt;You can use it directly in Eclipse via &lt;code&gt;https://mcp-abap.marianzeis.de/mcp&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Setup instructions are here: &lt;a href=&#34;https://github.com/marianfoo/abap-mcp-server/blob/main/README.md#eclipse-configuration-github-copilot&#34;&gt;Eclipse configuration (GitHub Copilot)&lt;/a&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;why-a-community-abap-mcp-server&#34;&gt;Why a community ABAP MCP server?&lt;/h2&gt;&#xA;&lt;p&gt;SAP has announced an MCP server for ABAP, so why create a community one?&lt;/p&gt;&#xA;&lt;p&gt;The trigger for me was the &lt;a href=&#34;https://github.com/orgs/community/discussions/151288&#34;&gt;release of Agent Mode in GitHub Copilot for ADT&lt;/a&gt;, which finally makes it possible to edit ABAP code by Copilot.&lt;/p&gt;&#xA;&lt;p&gt;LLM models are already really good, but ABAP knowledge is still a recurring problem. So I wanted an MCP server that is actually tailored for ABAP.&lt;/p&gt;&#xA;&lt;p&gt;For that, I took my existing MCP server for SAP docs, removed documentation that is irrelevant for ABAP, and added ABAP-specific sources like Official ABAP Keyword Documentation, DSAG ABAP Development Guidelines and ABAP Style Guide.&lt;/p&gt;&#xA;&lt;p&gt;I also tweaked the MCP tools so that search automatically looks beyond local docs and includes SAP Community posts and SAP Help, then returns the best results. And since GitHub Copilot in Eclipse is not exactly the fastest, getting to relevant context quicker makes a real difference.&lt;/p&gt;&#xA;&lt;p&gt;Here is what it looks like in Eclipse:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Eclipse with MCP server&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-02-04-abap-mcp-server/eclipse-mcp-server.jpg&#34;&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;why-eclipse-matters-right-now&#34;&gt;Why Eclipse matters (right now)&lt;/h2&gt;&#xA;&lt;p&gt;GitHub Copilot for Eclipse is especially important right now because (currently) Joule for Developers in Eclipse is not available for S/4HANA on-premise systems. For many ABAP developers in Eclipse, Copilot is the only practical way to use LLMs today.&lt;/p&gt;&#xA;&lt;p&gt;Sure, there is also VS Code, and SAP will support it in the near future. But let&amp;rsquo;s be honest: not every ABAP developer is even on Eclipse yet. And the &amp;ldquo;average developer&amp;rdquo; is not going to switch to VS Code now, and probably not anytime soon either.&lt;/p&gt;&#xA;&lt;p&gt;So this means: &lt;strong&gt;right now&lt;/strong&gt;, every ABAP developer, no matter which system, can use LLMs in Eclipse and also access ABAP-specific knowledge.&lt;/p&gt;&#xA;&lt;p&gt;Competition is good, so I published the ABAP MCP server as open source. That way, we have something to compare once SAP releases their own ABAP MCP server. And it also gives us a useful alternative to Joule for Developers.&lt;/p&gt;&#xA;&lt;p&gt;Uwe Fetzer already tested the new ABAP MCP server and confirmed it works better than the SAP MCP Docs server:&#xA;&lt;a href=&#34;https://saptodon.org/@se38@nrw.social/116011617758947257&#34;&gt;saptodon.org post&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Try it out and let me know what you think! You can use either the deployed version on my server or run it locally with Node or Docker.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;update-2026-02-05&#34;&gt;Update (2026-02-05)&lt;/h2&gt;&#xA;&lt;p&gt;Since publishing, I added two new capabilities:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Software Heroes as an online search source&lt;/strong&gt;: The &lt;code&gt;search&lt;/code&gt; tool can now also pull relevant content from &lt;a href=&#34;https://software-heroes.com/&#34;&gt;Software Heroes&lt;/a&gt; (including German and English results).&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;New &lt;code&gt;abap_feature_matrix&lt;/code&gt; tool&lt;/strong&gt;: You can query the &lt;a href=&#34;https://software-heroes.com/abap-feature-matrix&#34;&gt;ABAP Feature Matrix&lt;/a&gt; to quickly check feature availability across releases and ABAP Cloud, also provided by Björn Schulz.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Huge thanks to &lt;strong&gt;Björn Schulz&lt;/strong&gt; for offering his APIs and making these integrations possible.&lt;/p&gt;&#xA;&lt;p&gt;More info about the tools and sources is in the GitHub Repo README: &lt;a href=&#34;https://github.com/marianfoo/abap-mcp-server#available-tools&#34;&gt;https://github.com/marianfoo/abap-mcp-server#available-tools&lt;/a&gt;&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>Animalist in German: I Had to Build This</title>
      <link>https://blog.zeis.de/posts/2026-02-02-animalist/</link>
      <pubDate>Mon, 02 Feb 2026 09:30:00 +0100</pubDate>
      <guid>https://blog.zeis.de/posts/2026-02-02-animalist/</guid>
      <description>&lt;p&gt;I found Vivian Rose’s little web game &lt;strong&gt;“List Animals Until Failure”&lt;/strong&gt; through a Hacker News thread (&lt;a href=&#34;https://news.ycombinator.com/item?id=46842603&#34;&gt;HN discussion&lt;/a&gt;) and immediately got hooked.&lt;/p&gt;&#xA;&lt;p&gt;Then I typed my first few animals… and realized my English animal vocabulary is not exactly perfect. So I did the only sensible thing and made a German version.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Screenshot of the German Animalist game interface&#34; loading=&#34;lazy&#34; src=&#34;https://blog.zeis.de/posts/2026-02-02-animalist/animalist.jpg&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;The UI text is mostly translated with AI help (as all the other code). The part that actually took time was getting the animal names.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;what-the-game-is&#34;&gt;What the game is&lt;/h2&gt;&#xA;&lt;p&gt;It’s simple: you type animal names until you fail. If you repeat something, or you try to sneak in a too-broad term after a more specific one (and vice versa), the game calls you out.&lt;/p&gt;&#xA;&lt;p&gt;The magic is that it feels &lt;strong&gt;instant&lt;/strong&gt; because when you load the app you also load the complete animal list.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;where-the-animal-list-comes-from&#34;&gt;Where the animal list comes from&lt;/h2&gt;&#xA;&lt;p&gt;Vivian explains the original approach in her write-up (&lt;a href=&#34;https://rose.systems/blog/list-animals-until-failure&#34;&gt;blog post&lt;/a&gt;): the game is powered by &lt;strong&gt;Wikidata + Wikipedia&lt;/strong&gt;, and it ships a big offline lookup table so gameplay needs &lt;strong&gt;no network calls&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;At a high level, the original project:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;mines Wikidata entities representing taxons and builds a parent/child tree&lt;/li&gt;&#xA;&lt;li&gt;uses Wikipedia article titles + redirects (and some extra heuristics like disambiguation pages) to decide what inputs should count as “the same animal term”&lt;/li&gt;&#xA;&lt;li&gt;has a bunch of hand-tuning for edge cases&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For the German version, I took a pragmatic route:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;keep the &lt;strong&gt;same Q-IDs and taxonomy structure&lt;/strong&gt; from the original dataset&lt;/li&gt;&#xA;&lt;li&gt;fetch &lt;strong&gt;German names&lt;/strong&gt; for those Q-IDs from Wikidata in batches&lt;/li&gt;&#xA;&lt;li&gt;write out the German lookup tables that the game uses at runtime&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;I ended up with a few small Python helpers: one to fetch the German names from Wikidata, one to re-try missing entries, and one to add common singular forms (so “hai” works even if the canonical title is “haie”).&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;credits&#34;&gt;Credits&lt;/h2&gt;&#xA;&lt;p&gt;This exists because Vivian Rose built something genuinely fun and also wrote about it:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Original game: &lt;a href=&#34;https://rose.systems/animalist/&#34;&gt;List Animals Until Failure&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Original repo: &lt;a href=&#34;https://github.com/Roachbones/animalist&#34;&gt;Roachbones/animalist&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Original write-up: &lt;a href=&#34;https://rose.systems/blog/list-animals-until-failure&#34;&gt;blog post&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;And here’s my German adaptation again:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;German version: &lt;a href=&#34;https://animalist-de.marianzeis.de/&#34;&gt;animalist-de.marianzeis.de&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Repo: &lt;a href=&#34;https://github.com/marianfoo/animalist_de&#34;&gt;marianfoo/animalist_de&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
    <item>
      <title>Supercharged Local Open Source Joule for Consultants: Search Your Data &amp; Code</title>
      <link>https://blog.zeis.de/posts/2025-10-29-librechat/</link>
      <pubDate>Wed, 29 Oct 2025 09:30:00 +0100</pubDate>
      <guid>https://blog.zeis.de/posts/2025-10-29-librechat/</guid>
      <description>&lt;p&gt;This post is a mirrored copy of my LinkedIn article, kept here so it remains searchable and independent from external platforms.&#xA;You can still find the original on LinkedIn: &lt;a href=&#34;https://www.linkedin.com/pulse/supercharged-local-open-source-joule-consultants-search-marian-zeis-gepbf/&#34;&gt;LinkedIn Pulse article&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.sap.com/germany/products/artificial-intelligence/ai-assistant/sap-consulting-capability.html&#34;&gt;Joule for Consultants&lt;/a&gt; costs 250 € and mainly searches SAP Help, SAP Community and SAP for Me (Notes). That is useful, but it stops where real projects start: your own systems, codebase and sensitive data. Even though public assistants like ChatGPT and Claude can already reach SAP Help and SAP Community, the real gap is internal/authenticated data and code.&lt;/p&gt;&#xA;&lt;p&gt;For this case I created a &lt;a href=&#34;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat&#34;&gt;LibreChat fork&lt;/a&gt; that includes and auto-starts SAP MCP servers (Docs, Notes, S/4 OData and ABAP ADT) via Docker. So the MCP Server are local inside your Docker and no external MCP Server is used. &lt;a href=&#34;https://www.librechat.ai/&#34;&gt;LibreChat&lt;/a&gt; is an open‑source local chat UI with MCP support and built‑in Ollama integration, and it also supports many other model providers. You get a private assistant that can read official docs, inspect code and data from your systems without sending customer context to third‑party clouds. The fork’s documentation is here: &lt;a href=&#34;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat/tree/main/sap-mcp-docs&#34;&gt;sap‑mcp‑docs&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Running the assistant locally means the client, tools and, if you choose, the model stay on your machine (LibreChat supports Ollama), so you avoid pasting sensitive context into public chats. By adding S/4 OData and ABAP ADT, you bring real metadata, code and data into the loop.&lt;/p&gt;&#xA;&lt;h3 id=&#34;which-mcp-servers-are-used-here&#34;&gt;Which MCP servers are used here?&lt;/h3&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;SAP Docs MCP&lt;/a&gt; provides unified search and fetch across SAPUI5/OpenUI5, CAP, ABAP keyword docs, SAP Help and SAP Community. The &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-notes&#34;&gt;SAP Notes MCP&lt;/a&gt; is for searching and fetching SAP Notes when you have an error, OSS number or concrete symptom; it requires an S‑User certificate (Passport). The &lt;a href=&#34;https://github.com/mario-andreschak/mcp-abap-adt&#34;&gt;ABAP ADT MCP&lt;/a&gt; reads ABAP sources, DDIC structures and tables content via ADT APIs so you never paste code into chat and still get precise context. The &lt;a href=&#34;https://github.com/lemaiwo/btp-sap-odata-to-mcp-server&#34;&gt;S/4 OData MCP&lt;/a&gt; discovers services and exposes safe CRUD tools so your assistant can read and write via approved APIs.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-this-works-in-practice&#34;&gt;How this works in practice&lt;/h2&gt;&#xA;&lt;p&gt;In my example I used o4‑mini from OpenAI, but LibreChat supports many &lt;a href=&#34;https://www.librechat.ai/docs/configuration/pre_configured_ai&#34;&gt;model providers&lt;/a&gt; including OpenAI, Anthropic, Google, Azure AI Foundry and even SAP AI Core (not tested by me). The key point: you can also use a local &lt;a href=&#34;https://www.librechat.ai/blog/2024-03-02_ollama#getting-started-with-ollama&#34;&gt;model via Ollama&lt;/a&gt;. Depending on your use case, a local model is smart enough to call the right tools and MCP servers. I also use an ABAP Cloud Developer Trial instance connected via the S/4 OData and ADT MCP servers.&lt;/p&gt;&#xA;&lt;h3 id=&#34;sap-notes-lookup--abap-table-verification&#34;&gt;SAP Notes lookup + ABAP table verification&lt;/h3&gt;&#xA;&lt;p&gt;This first example flow combines the SAP Notes MCP and ABAP ADT MCP. First the assistant searches and fetches a specific SAP Note (&lt;code&gt;sap_note_search&lt;/code&gt;, &lt;code&gt;sap_note_get&lt;/code&gt;), then verifies the relevant DDIC table and fields via ADT. This confirms the symptom and the fix steps before proposing a safe, auditable corrective action (for example, an OData action). This is the pattern for many “error → note → verify → fix” tasks.&lt;/p&gt;&#xA;&lt;img src=&#34;example-sap-notes-lookup.jpg&#34; alt=&#34;LibreChat example flow: SAP Notes lookup plus ABAP table verification via ADT MCP tools&#34; loading=&#34;lazy&#34;&gt;&#xA;&lt;h3 id=&#34;service-metadata--valuelist-guidance&#34;&gt;Service metadata + ValueList guidance&lt;/h3&gt;&#xA;&lt;p&gt;The assistant uses the S/4 MCP to discover the Football service and inspect entity schema (&lt;code&gt;search-sap-services&lt;/code&gt;, &lt;code&gt;discover-service-entities&lt;/code&gt;, &lt;code&gt;get-entity-schema&lt;/code&gt;). It then pivots to the SAP Docs MCP to &lt;code&gt;sap_help_search&lt;/code&gt; and &lt;code&gt;sap_help_get&lt;/code&gt; the ValueList documentation and shows exactly where to add annotations. This marries live service metadata with the official docs so consultants can implement confidently, then validate in a Fiori app.&lt;/p&gt;&#xA;&lt;img src=&#34;example-service-metadata-valuelist.jpg&#34; alt=&#34;LibreChat example flow: S/4 service metadata plus ValueList guidance via SAP Docs MCP&#34; loading=&#34;lazy&#34;&gt;&#xA;&lt;h3 id=&#34;cds-view-value-help-research&#34;&gt;CDS view Value Help research&lt;/h3&gt;&#xA;&lt;p&gt;For CDS‑centric cases, the assistant focuses on SAP Docs MCP to collect the canonical examples for &lt;code&gt;Common.ValueList&lt;/code&gt; and relevant ABAP/CDS annotations. If needed, ABAP ADT MCP can retrieve the current CDS definition (&lt;code&gt;GetStructure&lt;/code&gt;/&lt;code&gt;GetInclude&lt;/code&gt;) to compare the as‑is state and generate the minimal edit plan.&lt;/p&gt;&#xA;&lt;img src=&#34;example-cds-value-help.jpg&#34; alt=&#34;LibreChat example flow: CDS value help research with ABAP ADT MCP context&#34; loading=&#34;lazy&#34;&gt;&#xA;&lt;h3 id=&#34;other-options-and-clients&#34;&gt;Other options and clients&lt;/h3&gt;&#xA;&lt;p&gt;There are other options and clients to use these MCP servers. If you prefer the Microsoft ecosystem, Visual Studio Code’s GitHub Copilot Chat supports MCP servers so you can connect the same SAP MCP endpoints there, as described in the &lt;a href=&#34;https://code.visualstudio.com/docs/copilot/chat/mcp-servers&#34;&gt;VS Code Copilot Chat MCP guide&lt;/a&gt;. This is a simpler setup compared to the LibreChat fork. For a more governed setup you can use &lt;a href=&#34;https://adoption.microsoft.com/ai-agents/copilot-studio/&#34;&gt;Copilot Studio&lt;/a&gt; together with the hosted S/4 OData MCP server from &lt;a href=&#34;https://www.sap.com/products/artificial-intelligence/partners/nessi-nv-ai-data-enabler.html?countryCode=US&#34;&gt;Nessi NV&lt;/a&gt; and the SAP Docs MCP Server.&lt;/p&gt;&#xA;&lt;p&gt;I talked about these MCP servers and showed a live example of Copilot Studio and other LLM clients at SAP Inside Track Munich 2025. The recording is here: &lt;a href=&#34;https://www.youtube.com/watch?v=vTZCeaxsOwU&#34;&gt;SAP Inside Track Munich 2025&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;You can also build your own LLM client and use the MCP servers directly. I tried a quick PoC with the current libraries and tools. It worked, but turning it into a production‑ready assistant with robust MCP support is non‑trivial; I would not recommend rolling your own for production. The PoC is here: &lt;a href=&#34;https://github.com/marianfoo/custom-llm-client&#34;&gt;Custom LLM Client&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h3 id=&#34;getting-started&#34;&gt;Getting started&lt;/h3&gt;&#xA;&lt;p&gt;To run this on your own machine, clone the repository, configure the &lt;code&gt;.env&lt;/code&gt; and &lt;code&gt;librechat.yaml&lt;/code&gt; files and start the Docker container. The docs are in this &lt;a href=&#34;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat/tree/main/sap-mcp-docs&#34;&gt;folder&lt;/a&gt; and the setup guide is here: &lt;a href=&#34;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat/blob/main/sap-mcp-docs/MCP_SETUP_GUIDE.md&#34;&gt;MCP_SETUP_GUIDE.md&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Minimal path (see guides for details):&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;# Clone and configure&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;git clone https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cd local-llm-client-for-sap-consultants-librechat&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cp .env.example .env&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cp librechat.example.yaml librechat.yaml&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;# Configure the .env and librechat.yaml files&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;# Start in Docker&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;docker compose up -d&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id=&#34;security-running-ai-and-mcp-locally&#34;&gt;Security: running AI and MCP locally&lt;/h3&gt;&#xA;&lt;p&gt;Because the client, MCP server and (optionally) the model run on your machine, prompts, retrieved docs and tool results stay inside your environment. When you do connect to external sources, do it intentionally and stick to trusted endpoints. Operationally keep it simple and start read-only by default and enable write tools only when you require it. The short version: a local, open-source stack is the safer option here; unlike cloud assistants, your information never leaves your machine unless you choose to send it.&lt;/p&gt;&#xA;&lt;h3 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h3&gt;&#xA;&lt;p&gt;With MCP servers, LLM clients become smarter and more useful in real projects. LLMs simply cannot know everything, especially internal context that lives on enterprise networks and changes quickly. Because the Model Context Protocol is still relatively new in the enterprise, treat adoption with care and integrate it securely. Keeping information on your own machine and using open-source libraries lets you see exactly what runs and how.&lt;/p&gt;&#xA;&lt;p&gt;SAP clearly wants to position Joule for Consultants as a unique product; today it still lags behind community projects for these use cases. At TechEd next week we’ll see whether community MCP servers are embraced and whether SAP’s own products improve enough to justify the price.&lt;/p&gt;&#xA;&lt;h3 id=&#34;references&#34;&gt;References&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Custom LLM Client PoC: &lt;a href=&#34;https://github.com/marianfoo/custom-llm-client&#34;&gt;https://github.com/marianfoo/custom-llm-client&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;SAP Inside Track Munich 2025 session: &lt;a href=&#34;https://www.youtube.com/watch?v=vTZCeaxsOwU&#34;&gt;https://www.youtube.com/watch?v=vTZCeaxsOwU&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;SAP partner listing (S/4 integration via OAuth): &lt;a href=&#34;https://www.sap.com/products/artificial-intelligence/partners/nessi-nv-ai-data-enabler.html?countryCode=US&#34;&gt;https://www.sap.com/products/artificial-intelligence/partners/nessi-nv-ai-data-enabler.html?countryCode=US&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;MCP clients overview (Claude Desktop etc.): &lt;a href=&#34;https://modelcontextprotocol.io/clients/&#34;&gt;https://modelcontextprotocol.io/clients/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Copilot Studio: &lt;a href=&#34;https://adoption.microsoft.com/ai-agents/copilot-studio/&#34;&gt;https://adoption.microsoft.com/ai-agents/copilot-studio/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;VS Code Copilot Chat MCP docs: &lt;a href=&#34;https://code.visualstudio.com/docs/copilot/chat/mcp-servers&#34;&gt;https://code.visualstudio.com/docs/copilot/chat/mcp-servers&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;CAP MCP server (official): &lt;a href=&#34;https://github.com/cap-js/mcp-server&#34;&gt;https://github.com/cap-js/mcp-server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;CAP MCP plugin (community): &lt;a href=&#34;https://github.com/gavdilabs/cap-mcp-plugin&#34;&gt;https://github.com/gavdilabs/cap-mcp-plugin&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;S/4 OData MCP: &lt;a href=&#34;https://github.com/lemaiwo/btp-sap-odata-to-mcp-server&#34;&gt;https://github.com/lemaiwo/btp-sap-odata-to-mcp-server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;ABAP ADT MCP: &lt;a href=&#34;https://github.com/mario-andreschak/mcp-abap-adt&#34;&gt;https://github.com/mario-andreschak/mcp-abap-adt&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;SAP Notes MCP: &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-notes&#34;&gt;https://github.com/marianfoo/mcp-sap-notes&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;SAP Docs MCP: &lt;a href=&#34;https://github.com/marianfoo/mcp-sap-docs&#34;&gt;https://github.com/marianfoo/mcp-sap-docs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;LibreChat Ollama guide: &lt;a href=&#34;https://www.librechat.ai/blog/2024-03-02_ollama#getting-started-with-ollama&#34;&gt;https://www.librechat.ai/blog/2024-03-02_ollama#getting-started-with-ollama&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;LibreChat model providers: &lt;a href=&#34;https://www.librechat.ai/docs/configuration/pre_configured_ai&#34;&gt;https://www.librechat.ai/docs/configuration/pre_configured_ai&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;LibreChat website: &lt;a href=&#34;https://www.librechat.ai/&#34;&gt;https://www.librechat.ai/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;LibreChat fork setup guide: &lt;a href=&#34;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat/blob/main/sap-mcp-docs/MCP_SETUP_GUIDE.md&#34;&gt;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat/blob/main/sap-mcp-docs/MCP_SETUP_GUIDE.md&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;LibreChat fork docs folder: &lt;a href=&#34;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat/tree/main/sap-mcp-docs&#34;&gt;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat/tree/main/sap-mcp-docs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;LibreChat fork (SAP consultants, with MCP servers): &lt;a href=&#34;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat&#34;&gt;https://github.com/marianfoo/local-llm-client-for-sap-consultants-librechat&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
    </item>
  </channel>
</rss>
