commerce-mcp
An MCP control plane for SAP Commerce Cloud that exposes safe, read-only tools to LLM agents for inspecting types, running FlexibleSearch, and validating ImpEx.
README
commerce-mcp
An AI / MCP control plane for SAP Commerce Cloud (Hybris).
🌐 Live site: https://alextsvetkov.github.io/commerce-mcp/
commerce-mcp exposes a SAP Commerce estate to LLM agents and developer copilots as a set of safe, typed, read-only tools over the Model Context Protocol (MCP). Instead of clicking through HAC and Backoffice, an engineer (or an agent acting on their behalf) can ask:
"Describe the
Ordertype." "Why did orderPROD-4471fail validation?" "Write ImpEx to add aloyaltyTierattribute toCustomer— and validate it against the live model first."
⚠️ Status: early scaffold. The tool surface, safety model and mock connector are real and tested; the live Hybris connector is a documented extension point, not yet implemented. See Roadmap.
Why this exists
SAP Commerce is powerful but opaque and expertise-gated. Every meaningful interaction — inspecting the type system, running a FlexibleSearch, writing correct ImpEx, tracing an order — requires deep tribal knowledge and manual navigation. LLMs can't help today because they have no safe, structured way in.
commerce-mcp is that way in. It is the "hands and eyes" that make a legacy commerce platform legible to agents — collapsing the single biggest cost driver on any SAP Commerce program: scarce expertise and slow onboarding.
See docs/ (the GitHub Pages site) for the full benefits narrative.
Design principles
- Read-only by default. Every shipped tool is non-mutating.
run_flexible_searchrejects anything that isn't aSELECT; write paths (applying ImpEx) are deliberately out of scope for this surface and require separate, explicit authorization. - Safe by construction. Row caps, keyword denylists, and (planned) PII redaction + audit logging are product features, not afterthoughts.
- Offline-first. A fixture-backed
MockConnectormakes the entire tool surface runnable and testable with zero configuration — no live instance needed for demos or CI. - Transport-neutral core. Tools are plain (schema, description, handler) triples; MCP is one adapter. A CLI or HTTP surface can reuse the same catalogue.
Architecture
LLM / Agent (Claude, Copilot, …)
│ MCP (stdio)
┌───────────▼───────────┐
│ commerce-mcp server │ src/server/index.ts
├────────────────────────┤
│ tool catalogue │ src/tools/index.ts (zod-typed, read-only)
├────────────────────────┤
│ CommerceConnector │ src/types.ts (interface)
│ ├─ MockConnector │ fixtures — offline
│ └─ LiveConnector* │ HAC / OCC / read-only DB view (*planned)
└────────────────────────┘
│
SAP Commerce Cloud (Hybris)
Tools (v0.1)
| Tool | Purpose |
|---|---|
describe_type |
Full definition of an item type (attributes, parent, deployment table). |
list_types |
Enumerate type codes, optional substring filter. |
run_flexible_search |
Execute a read-only FlexibleSearch SELECT, capped rows. |
validate_impex |
Statically validate ImpEx against the live type model before applying. |
Quick start
npm install
npm run build
npm start # runs the MCP server on stdio against the MockConnector
npm test # unit tests, no live instance required
Use from an MCP client
Add to your client's MCP server config (example for a Claude-style client):
{
"mcpServers": {
"commerce": { "command": "node", "args": ["dist/server/index.js"] }
}
}
Roadmap
- [ ]
LiveConnectorover HAC + OCC + a read-only DB view. - [ ] PII redaction layer + structured audit log for every tool call.
- [ ]
explain_business_process,list_feature_toggles,trace_ordertools. - [ ]
zod-to-json-schemawiring so tool input schemas are fully published to the client. - [ ] Opt-in, separately-authorized write surface (apply validated ImpEx).
Contributing
See CONTRIBUTING.md. This project follows conventional commits and keeps generated code out of version control.
License
MIT © 2026 Aliaksandr Tsviatkou
Honest assessment
From the v2 self-critical analysis. Scores use Gap · Value · Moat · Time-to-revenue · Risk (for Risk, higher = safer). Prior art is named deliberately — "no competitor" is almost never true.
Scores: Gap 5 · Value 4 · Moat 3 · TTR 4 · Risk 3 (higher=safer)
- Prior art / competition. MCP is new; SAP's Joule/CX AI is storefront-facing, not developer/ops-facing. Thin prior art — the strongest of the suite.
- True differentiator. Depth and safety of type-system / ImpEx / FlexibleSearch semantics, and being the first safe agent entry point others build on.
- Kill criterion. If target teams won't let an agent touch prod data even read-only, and won't pay for a sandboxed variant, the wedge is weaker than it looks.
- Verdict. Build this as the one commercial wedge — but from public HAC/OCC APIs, never internal employer code.
See the full landscape, go-to-market and the IP / conflict-of-interest discussion in sap-commerce-general-ideas-for-startup.md.
Part of a suite of backend tools for SAP Commerce Cloud. commerce-mcp is the AI-native flagship; sibling projects cover schema migration, ImpEx tooling, tracing, upgrades, and eventing correctness.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。
mcp-server-qdrant
这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。