# SAP HANA MCP connector

The SAP HANA connector brings SAP HANA user and group administration to Claude, ChatGPT, Cursor and the Elaichi Agent, so your team can list, create, update and remove SAP HANA users and groups with every action logged.

Source: https://elaichi.ai/connectors/saphana/

## Facts

| | |
| --- | --- |
| Application | SAP HANA |
| Category | Database |
| AI tools | 12 |
| Authentication | App credentials |
| Bring your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once SAP HANA is connected

- List every SAP HANA user added in the last 30 days
- Which SAP HANA groups is Priya Nair a member of?
- Create a SAP HANA group called Finance Reporting

## Connect SAP HANA in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick SAP HANA.
2. Optionally set Share with, then press Connect.
3. Paste your SAP HANA app credentials. SAP HANA authenticates the app rather than a person. One person supplies the credentials once, and everyone else works through Share with.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which SAP HANA tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## SAP HANA MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## SAP HANA MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## SAP HANA MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect SAP HANA to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a SAP HANA tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with SAP HANA through Elaichi

### Set up a new hire in SAP HANA

IT. Create the SAP HANA user on day one and add them to the right groups in a single ask. The account is ready before they open their laptop.

### Review who has an SAP HANA account

Security. Ask for every user in SAP HANA and spot accounts that belong to people who have moved teams or left. Follow up on each one without leaving the conversation.

### Remove access on someone's last day

HR. When a leaver is confirmed, have their SAP HANA user removed and their group memberships cleared. The audit log records who did it and when.

### Pull a group membership list for an audit

Compliance. Get the members of any SAP HANA group when an auditor asks, formatted and ready to hand over. No ticket to IT and no waiting a week.

### Add analysts to the reporting group

Data and analytics. When a new analyst joins, add their SAP HANA user to the reporting group so they can start on the data they need. Update the group again when the project ends.

### Fix a user record that is out of date

Operations. Correct a name, email or attribute on a SAP HANA user when it changes. Only the field you mention is touched, and the rest stays as it was.

## Elaichi vs Zapier MCP vs Composio for SAP HANA

All three can connect SAP HANA to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over SAP HANA tools | Allow or restrict single SAP HANA tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per SAP HANA call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect SAP HANA to Claude?

Two steps. In Elaichi, choose SAP HANA and enter the app credentials your SAP HANA administrator gives you, then in Claude go to Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. There is no OAuth application to register and no client ID or secret to generate, and the whole thing takes a few minutes.

### Does SAP HANA work with ChatGPT and Cursor as well as Claude?

Yes. Once SAP HANA is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect SAP HANA once and every client picks it up.

### What can an AI agent actually do with my SAP HANA data?

Through this connector an agent can list the users and groups in SAP HANA, look one up, create new ones, update details and remove them. That covers the everyday administration work: setting up a new hire, adding someone to a group, correcting a record, or removing a leaver. Short concrete asks, like "add Priya to the reporting group in SAP HANA", work better than long paragraphs.

### Does connecting SAP HANA give the AI full administrator rights?

No. Every call to SAP HANA runs inside the access of the person who signed in, so an agent can only see and change what that person's SAP HANA credentials already allow. Elaichi can narrow that access further with roles and restrictions, and it can never widen it.

### Can my team share one SAP HANA connection?

Yes. One administrator connects SAP HANA in Elaichi and shares it with a team, and nobody else ever handles the app credentials. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person behind every SAP HANA change.

### Can I stop an agent from deleting or changing users in SAP HANA?

Yes. Restrictions in Elaichi work per action, so you can allow listing and looking up SAP HANA users and groups while blocking create, update or delete. A restricted action is never advertised to Claude, ChatGPT or any other client, so no prompt can reach it.

### What happens to a SAP HANA connection when someone leaves?

Offboarding that person in Elaichi ends their access to SAP HANA through every client at once. A shared SAP HANA connection keeps working for everyone else on the team. If you ever want to remove SAP HANA entirely, disconnecting it once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client.

### Does the SAP HANA MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. SAP HANA is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for SAP HANA?

Yes. Both let Claude, ChatGPT or Cursor use SAP HANA. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every SAP HANA call.

### How is Elaichi different from Composio for SAP HANA?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to SAP HANA: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 12 SAP HANA tools

Every tool below is callable through https://api.elaichi.ai/mcp once SAP HANA is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all SAP HANA users** (List). List users in SAP Cloud Identity Services (Identity Authentication) via the SCIM 2.0 API (GET /service/scim/Users). Returns SCIM user resources with userName, name, emails, active, userType, groups, enterprise and SAP extension attributes and meta timestamps. Supports SCIM filter expressions (e.g. userName eq "x" or meta.lastModified gt "date"), attribute selection, sorting and startIndex/count paging. No parameters are required.

- **Get single SAP HANA user by ID** (Get). Get a single user from SAP Cloud Identity Services by id via SCIM 2.0 (GET /service/scim/Users/{id}). Returns the full SCIM user resource including name, emails, phone numbers, active flag, userType, group memberships, enterprise attributes (employeeNumber, department, manager) and SAP specific attributes. Required: id (the user UUID).

- **Create a SAP HANA user** (Create). Create a user in SAP Cloud Identity Services via the Identity Directory SCIM 2.0 API (POST /service/scim/Users). Requires schemas, userName and at least one email; optional name, active, userType, enterprise and SAP extension attributes. Set the SAP extension sendMail to true to send the activation email. Returns the created SCIM user with its generated id.

- **Update a SAP HANA user by ID** (Update). Replace a user in SAP Cloud Identity Services (PUT /service/scim/Users/{id}, SCIM 2.0). Sends the full user representation; attributes not included are cleared, so read the user first and resend it with your changes. Required: id and a complete user body with schemas and userName. Returns the updated user.

- **SAP HANA users partial update** (Update). Update selected attributes of a user in SAP Cloud Identity Services without resending the whole record (PATCH /service/scim/Users/{id}, SCIM PatchOp). Use operations such as replace active=false to deactivate, replace name.givenName, or add emails. Required: id (query) and Operations.

- **Delete a SAP HANA user by ID** (Delete). Delete a user from SAP Cloud Identity Services (DELETE /service/scim/Users/{id}, SCIM 2.0). This is permanent; to keep history deactivate the user instead with partial_update (replace active with false). Required: id. Returns no content on success.

- **List all SAP HANA groups** (List). List groups in SAP Cloud Identity Services (Identity Authentication) via the SCIM 2.0 API (GET /service/scim/Groups). Returns SCIM group resources with displayName, members (user ids and display names), the SAP group extension (technical name, description, type) and meta timestamps. Supports SCIM filter expressions (e.g. displayName eq "Admins"), attribute selection, sorting and startIndex/count paging. No parameters are required.

- **Get single SAP HANA group by ID** (Get). Get a single group from SAP Cloud Identity Services by id via SCIM 2.0 (GET /service/scim/Groups/{id}). Returns the SCIM group resource with displayName, the full member list and the SAP group extension. Required: id (the group UUID).

- **Create a SAP HANA group** (Create). Create a group in SAP Cloud Identity Services via the Identity Directory SCIM 2.0 API (POST /service/scim/Groups). Requires schemas and displayName; the SAP extension name sets the technical group name; members can be supplied as user ids. Returns the created group with its id.

- **Update a SAP HANA group by ID** (Update). Replace a group in SAP Cloud Identity Services (PUT /service/scim/Groups/{id}, SCIM 2.0). Sends the full group including the complete members list; members omitted are removed. Required: id and a full group body. Returns the updated group.

- **SAP HANA groups partial update** (Update). Add or remove members or change attributes of a group in SAP Cloud Identity Services (PATCH /service/scim/Groups/{id}, SCIM PatchOp). To add a member: op add, path members, value [{"value": "&lt;user id&gt;"}]. To remove one: op remove, path members[value eq "&lt;user id&gt;"]. Required: id (query) and Operations.

- **Delete a SAP HANA group by ID** (Delete). Delete a group from SAP Cloud Identity Services (DELETE /service/scim/Groups/{id}, SCIM 2.0). Members are not deleted, only the group and its assignments. Required: id. Returns no content on success.

