<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Agents on ScipioERP</title><link>https://www.scipioerp.com/community/developer/agents/</link><description>Recent content in Agents on ScipioERP</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Thu, 17 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.scipioerp.com/community/developer/agents/index.xml" rel="self" type="application/rss+xml"/><item><title>Agent quickstart</title><link>https://www.scipioerp.com/community/developer/agents/quickstart/</link><pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.scipioerp.com/community/developer/agents/quickstart/</guid><description>&lt;p&gt;This guide takes an administrator from a running Scipio 4.0 server to a
working agent connection in five steps. It covers Claude Code, Claude
Desktop, Cursor, VS Code, and any other client that speaks MCP over
Streamable HTTP.&lt;/p&gt;
&lt;h2 id="1-check-the-server"&gt;1. Check the server&lt;a class="heading-anchor" href="#1-check-the-server" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Open &lt;code&gt;https://&amp;lt;host&amp;gt;/admin/control/McpServers&lt;/code&gt; as an administrator. The
page lists every MCP server profile and its tools. Each application has
its own endpoint: &lt;code&gt;/ordermgr/mcp&lt;/code&gt;, &lt;code&gt;/accounting/mcp&lt;/code&gt;, &lt;code&gt;/cms/mcp&lt;/code&gt;,
&lt;code&gt;/shop/mcp&lt;/code&gt;, and so on. The hub is &lt;code&gt;/admin/mcp&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Confirm the server runs behind HTTPS. A plain HTTP request is refused
unless &lt;code&gt;mcp.allowInsecure=true&lt;/code&gt; in &lt;code&gt;framework/mcp/config/mcp.properties&lt;/code&gt;
(development only).&lt;/li&gt;
&lt;li&gt;When a reverse proxy terminates TLS, set &lt;code&gt;mcp.trustedProxies&lt;/code&gt; to the
proxy addresses. Only those addresses may assert
&lt;code&gt;X-Forwarded-Proto: https&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="2-create-a-user-for-the-agent"&gt;2. Create a user for the agent&lt;a class="heading-anchor" href="#2-create-a-user-for-the-agent" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;The seed user &lt;code&gt;scp-agent&lt;/code&gt; (group &lt;code&gt;SCIPIO_AGENT&lt;/code&gt;) exists after the seed
data load. It has read access to every back-office application and no
write permission.&lt;/li&gt;
&lt;li&gt;For an agent that must write, create a dedicated user login and put it
in a security group with the needed &lt;code&gt;&amp;lt;APP&amp;gt;_UPDATE&lt;/code&gt; permissions, plus
&lt;code&gt;MCP_ACCESS&lt;/code&gt;, &lt;code&gt;MCP_GATEWAY&lt;/code&gt; and &lt;code&gt;OFBTOOLS_VIEW&lt;/code&gt;. Grant &lt;code&gt;MCP_CODE_WRITE&lt;/code&gt;
only when the agent must edit CMS templates or scripts.&lt;/li&gt;
&lt;li&gt;Never give an agent the &lt;code&gt;system&lt;/code&gt; or &lt;code&gt;admin&lt;/code&gt; login. Tokens for &lt;code&gt;system&lt;/code&gt;
are refused.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="3-create-a-token"&gt;3. Create a token&lt;a class="heading-anchor" href="#3-create-a-token" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Open &lt;code&gt;https://&amp;lt;host&amp;gt;/admin/control/McpTokens&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fill in the user login, a token name, the webapps the token may use
(&lt;code&gt;*&lt;/code&gt; for all), the read-only flag, the expiry (default 90 days, maximum
365) and, for a shop token, a spend cap (&lt;code&gt;maxOrderAmount&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Click &amp;ldquo;Create Token&amp;rdquo;. Copy the token now. The page shows it once,
together with ready-made connection snippets that already contain the
token.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="4-connect-the-client"&gt;4. Connect the client&lt;a class="heading-anchor" href="#4-connect-the-client" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Open &lt;code&gt;https://&amp;lt;host&amp;gt;/admin/control/McpSkills&lt;/code&gt;. It shows the hub endpoint
and one snippet per client. Replace &lt;code&gt;&amp;lt;token&amp;gt;&lt;/code&gt; with the token from step 3.&lt;/p&gt;</description></item><item><title>Agent access security</title><link>https://www.scipioerp.com/community/developer/agents/security/</link><pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.scipioerp.com/community/developer/agents/security/</guid><description>&lt;p&gt;This page describes how Scipio 4.0 secures agent access through MCP, and
what an operator must do before and during production use. Read
&lt;a href="https://www.scipioerp.com/community/developer/agents/quickstart/"&gt;Agent quickstart&lt;/a&gt;
 for the setup
steps.&lt;/p&gt;
&lt;h2 id="principles"&gt;Principles&lt;a class="heading-anchor" href="#principles" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A token is a user login. An agent has exactly the permissions of that
user. No permission comes from the token itself.&lt;/li&gt;
&lt;li&gt;Default deny. A call passes only when every gate in the policy engine
allows it.&lt;/li&gt;
&lt;li&gt;One rule for every endpoint. The hub and the application endpoints apply
the same policy.&lt;/li&gt;
&lt;li&gt;Everything is audited. Every tool call, denied or not, writes one
&lt;code&gt;McpAuditLog&lt;/code&gt; row.&lt;/li&gt;
&lt;li&gt;Executable code is a separate permission. CMS templates and scripts need
&lt;code&gt;MCP_CODE_WRITE&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="permissions-and-groups"&gt;Permissions and groups&lt;a class="heading-anchor" href="#permissions-and-groups" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Permission&lt;/th&gt;
 &lt;th&gt;Grants&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MCP_ACCESS&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Use any MCP endpoint. Required for every token user.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MCP_GATEWAY&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Call any service through &lt;code&gt;scipio_service&lt;/code&gt; with &lt;code&gt;action&lt;/code&gt; &lt;code&gt;call&lt;/code&gt; (still subject to the policy engine).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MCP_ENTITY_READ&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Read entities outside a server&amp;rsquo;s allowlist through &lt;code&gt;scipio_entity&lt;/code&gt; with &lt;code&gt;action&lt;/code&gt; &lt;code&gt;find&lt;/code&gt;.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MANUFACTURING_FLOOR&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Declare, scan, start and complete production run tasks without &lt;code&gt;MANUFACTURING_UPDATE&lt;/code&gt;.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MCP_MAIL_SEND&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Send a mail from a template through &lt;code&gt;mail_send_template&lt;/code&gt;. Granted to &lt;code&gt;FULLADMIN&lt;/code&gt;.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MCP_ENTITY_WRITE&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Write entities through the entity tools (also needs &lt;code&gt;ENTITY_MAINT&lt;/code&gt;).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MCP_ADMIN&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Manage tokens of any user, view the audit log, reload the registry, run services of components without a webapp.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;MCP_CODE_WRITE&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Write CMS FreeMarker templates, Groovy scripts and asset templates. Remote code execution by design.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Seed groups:&lt;/p&gt;</description></item><item><title>Extending agent access</title><link>https://www.scipioerp.com/community/developer/agents/extending/</link><pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.scipioerp.com/community/developer/agents/extending/</guid><description>&lt;p&gt;This page shows how to extend &lt;code&gt;framework/mcp&lt;/code&gt;: a tool, a service tool, a
server profile, a provider, a skill, a path handler, a permission, and how
to smoke-test a change with &lt;code&gt;curl&lt;/code&gt;. Read
&lt;code&gt;framework/resources/templates/mcp/README.txt&lt;/code&gt; first for the starter files.&lt;/p&gt;
&lt;h2 id="1-add-a-tool"&gt;1. Add a tool&lt;a class="heading-anchor" href="#1-add-a-tool" aria-label="Link to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;A tool is one static method on a class an &lt;code&gt;@McpServer&lt;/code&gt; annotation already
covers. Add a public static method under your component&amp;rsquo;s &lt;code&gt;src/.../mcp/&lt;/code&gt;
package; the first parameter is always &lt;code&gt;McpCallContext ctx&lt;/code&gt;, each other
parameter carries an &lt;code&gt;@McpParam&lt;/code&gt; with an explicit &lt;code&gt;name&lt;/code&gt;. Annotate the
method with &lt;code&gt;@McpTool&lt;/code&gt;: a &lt;code&gt;topic&lt;/code&gt;, a &lt;code&gt;name&lt;/code&gt; in &lt;code&gt;snake_case&lt;/code&gt;, a short
&lt;code&gt;description&lt;/code&gt;, &lt;code&gt;readOnly = true&lt;/code&gt; when the tool only reads data. The topic is
the tool the agent sees; the name is the &lt;code&gt;action&lt;/code&gt; it passes. Every method that
names the same topic joins the same tool, which is why one application shows an
agent five tools and not fifty. Return a &lt;code&gt;Map&lt;/code&gt;, a &lt;code&gt;List&lt;/code&gt;,
a &lt;code&gt;GenericValue&lt;/code&gt;, a &lt;code&gt;String&lt;/code&gt;, or an &lt;code&gt;McpResult&lt;/code&gt;; convert a raw service
result with &lt;code&gt;ResultConverter.toJsonMap(result)&lt;/code&gt;. Throw &lt;code&gt;McpToolException&lt;/code&gt;
for a tool error, or &lt;code&gt;McpToolException.denied(msg)&lt;/code&gt; for a permission
denial.&lt;/p&gt;</description></item><item><title>Agent tools reference</title><link>https://www.scipioerp.com/community/developer/agents/tools/</link><pubDate>Thu, 17 Sep 2026 00:00:00 +0000</pubDate><guid>https://www.scipioerp.com/community/developer/agents/tools/</guid><description>&lt;p&gt;Every application answers &lt;code&gt;POST /&amp;lt;webapp&amp;gt;/mcp&lt;/code&gt;. A tool is one business object; the
&lt;code&gt;action&lt;/code&gt; argument selects what to do with it. An action marked with &lt;code&gt;*&lt;/code&gt; writes data and
needs the update permission of the application; the others read. The six core tools
(&lt;code&gt;scipio_whoami&lt;/code&gt;, &lt;code&gt;scipio_apps&lt;/code&gt;, &lt;code&gt;scipio_service&lt;/code&gt;, &lt;code&gt;scipio_entity&lt;/code&gt;, &lt;code&gt;scipio_document&lt;/code&gt;,
&lt;code&gt;scipio_admin&lt;/code&gt;) exist on every endpoint. Call a tool with &lt;code&gt;{&amp;quot;action&amp;quot;: &amp;quot;find&amp;quot;, ...}&lt;/code&gt;; the
schema of each action is in &lt;code&gt;tools/list&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;This page is generated from the &lt;code&gt;@McpServer&lt;/code&gt; classes in the source tree.&lt;/p&gt;</description></item></channel></rss>