↓ Skip to main content
9 – 17 UHR +49 8031 3508270 LUITPOLDSTR. 9, 83022 ROSENHEIM
DE / EN
CompanyGPT Integration MCP server: self-hosted

Use SAP Business One with AI via MCP

SAP Business One brings accounting, inventory and sales together for mid-sized companies – usually running on their own network or at an implementation partner. For AI access we rely on the SAP B1 MCP server by Versino AG, an SAP Business One partner based in Altötting, Germany: it runs in your infrastructure, talks to the Service Layer and signs every user in with their own SAP identity. CompanyGPT connects to it via Streamable HTTP – ERP data never leaves your network.

What is SAP Business One?

SAP Business One is SAP SE’s ERP for small and mid-sized companies. It combines financial accounting, purchasing, inventory and warehouse management, sales and basic CRM functions in a single system and is almost always rolled out through specialized partners. Deployment is classically on-premises on a server at the company, on SAP HANA or Microsoft SQL Server, or in an implementation partner’s cloud.

As a result, day-to-day operations in many mid-market businesses live inside Business One: quotations, delivery notes, invoices, item and business partner master data. That is precisely what makes it valuable for AI agents – questions from sales, purchasing and accounting can be answered from verifiable records instead of exported spreadsheets, provided access is cleanly scoped. This is exactly where the Versino MCP server comes in: every user sees and changes only what their SAP user is allowed to anyway.

Connection at a Glance

Last updated: October 5, 2026

MCP server
Versino KI SAP B1 MCP (Versino AG), self-hosted in your infrastructure
Version
3.8.4 of October 2, 2026, releases on GitHub
Transport
Streamable HTTP, endpoint https://<host>/mcp behind TLS
Authentication
Per user with their own SAP identity: browser login against the Service Layer or SSO via SAP Authentication Server (OIDC, PKCE)
Interface
Service Layer v2 (REST/OData), SAP HANA and Microsoft SQL Server
Operation mode
READ_ONLY (default) or READ_WRITE; tools per edition BASIC, PRO, ENTERPRISE
License
Licensed product (versino.key), seats = concurrently working SAP users, monthly cancellation according to Versino
Official SAP sample
Since SAP Business One 10.0 FP 2608 as reference code, not released for production

How to Connect SAP Business One to CompanyGPT

Versino AG, an SAP Business One partner headquartered in Altötting, Germany, provides a dedicated MCP server for Business One, the Versino KI SAP B1 MCP (repository Versino-AG/versino_ki_sap_b1_mcp, current version 3.8.4 of October 2, 2026). The server is a binary for Windows or Linux that works directly against the Service Layer (https://<host>:50000/b1s/v2/) and, according to Versino, supports SAP HANA as well as Microsoft SQL Server. Its distinguishing feature is per-user operation: each user signs in with their own SAP identity – classically with user name and password on a browser login page, or via single sign-on through the SAP Authentication Server (OIDC with PKCE). According to Versino, credentials never enter the chat or LLM context, and the SAP permissions of the signed-in user apply one to one.

For CompanyGPT we use the central installation documented by Versino: one instance runs permanently as a service or container close to the Service Layer in your network, behind TLS, and exposes the endpoint https://<host>/mcp as a Streamable HTTP server. CompanyGPT registers this endpoint as an MCP server; nothing needs to be installed on workstations. In the chat, “Connect me to SAP” is enough: the agent returns a login link, the user signs in in the browser, selects the company database and then works with their own permissions. Which tools the agent sees at all is determined by the licensed edition and the operation mode READ_ONLY or READ_WRITE – write tools that are not enabled are, according to the documentation, not offered in the first place. For customers whose Business One is hosted by a partner, Versino additionally names operation through the hosting partner Cloudiax.

SAP itself has shipped an official MCP server as sample code since SAP Business One 10.0 FP 2608 (Streamable HTTP, Service Layer entities as dynamic tools, OAuth via Keycloak), which SAP explicitly labels as a reference for learning and demonstration purposes. We keep an eye on this sample; for production use, the Versino server with its license, support, curated reports and ongoing releases is the more robust foundation today. Where specific document types or processes go beyond it, we extend the integration directly on the Service Layer. Since Business One is rarely publicly reachable, establishing the secured network link between CompanyGPT and the MCP server is part of the project scope.

Note for on-premises operation: CompanyGPT runs in your own Azure tenant – so your on-premises network can be connected directly: via a site-to-site VPN (Azure VPN Gateway) or ExpressRoute between your corporate network and the virtual network of your CompanyGPT environment. The system does not need to be publicly reachable; we set up the connection together with your IT team.

Setup in SAP Business One and CompanyGPT

How the connection is set up step by step

1

Define edition and seats with Versino

Together with you we clarify whether the agent should only read (master data or all data including documents) or also create, update and trigger document actions. This determines the edition. The license file versino.key is issued via Versino’s license portal; seats count concurrently working SAP users, not workstations.

2

Install the central instance close to the Service Layer

Binary, license file and .env live in one folder on a Windows or Linux server in the customer network, as a service or container. You configure the Service Layer URL, the selectable company databases, the operation mode and the public HTTPS address of the instance. TLS is terminated by the server itself or by a reverse proxy in front of it.

3

Secure the network between CompanyGPT and the MCP server

CompanyGPT reaches the endpoint over a secured connection (VPN or private link) – exposing it to the open internet is not necessary. In addition, the server supports an allowlist of permitted client addresses so that only your CompanyGPT environment can send requests.

4

Register the MCP server in CompanyGPT and grant access

We add the endpoint to your CompanyGPT instance and create agents, for example a read-only sales agent and an accounting agent. Your administrators release the integration specifically for roles and groups; all other users do not see it.

5

Users connect with their SAP identity

In the chat, the user writes “Connect me to SAP”, follows the login link in the browser, selects the company and then works with their SAP permissions. The login is valid for the session; according to the documentation, Versino limits browser sessions to one hour. We test typical workflows on a test database before the agent goes live.

What the Agent Can Do in SAP Business One

Functions that SAP Business One exposes via MCP

Read and analyze

  • Find business partners, items and other master data via OData queries or fuzzy search
  • Query documents such as quotations, orders, invoices and open items and condense them by criteria
  • Use the bundled, curated reports (AI_* queries) that calculate key figures the way Business One calculates them
  • Include your own reports from the SAP Query Manager, for example with additional user-defined fields

Create and update (READ_WRITE)

  • Create business partners and documents, change fields such as delivery date or remarks
  • Remove lines from open quotations, orders and purchasing documents
  • Upload files as SAP attachments and link them to a document without the file passing through the chat

Document actions (ENTERPRISE)

  • Cancel or close documents
  • Delete records – only if the SAP user is permitted to and the edition enables it

Multiple companies

  • Configure several company databases; a session is always connected to exactly one company
  • Switch company in the chat: disconnect and reconnect with another database

Typical Use Cases

How AI agents in CompanyGPT work with SAP Business One

Customer history before the call

Inside sales condenses quotations, open orders and invoices for a business partner into one short overview instead of opening several document screens – with exactly the data the user's own SAP account may see.

Check stock and item data

During customer enquiries the agent reads stock levels, item master data and serial numbers per warehouse from Business One and drafts the reply directly.

Prepare open receivables

Accounting has overdue invoices grouped by customer and due date, and turns the result into draft payment reminders.

Adjust an order conversationally

With write permissions the agent updates the delivery date of an order on request or removes a line from an open quotation – the change takes effect directly in SAP, which is why the agent shows what it is about to change first.

Example Prompts for SAP Business One

How employees talk to SAP Business One in CompanyGPT

Connect me to SAP, database SBO_PROD.
Which open invoices does Mustermann GmbH have, and how many of them are more than 30 days overdue?
Show me the last 10 quotations with customer, amount and status.
How many orders were there this month, grouped by customer?
Set the delivery date of order 1234 to next Friday.
Which fields does a business partner have, and what does table OCRD mean?

Security, Privacy and Governance

What SAP Business One and CompanyGPT secure together

Own SAP permissions instead of a service user

Every user signs in with their own SAP identity; Business One enforces its permissions one to one. The password is entered only on the login page in the browser and, according to Versino, is never requested in the chat. With SSO via the SAP Authentication Server, existing sessions, MFA and federated logins apply.

Read-only is the default

The instance starts in READ_ONLY mode. Write tools appear only when READ_WRITE has been deliberately enabled and the edition includes them – a tool that is not enabled is invisible to the agent and therefore cannot be suggested.

Hardened network operation

TLS is mandatory for network operation, optionally with mTLS. The server throttles failed logins per address, logs every login attempt and restricts via allowlist which clients can reach it. On top come the role and group permissions in CompanyGPT.

Data stays in-house

ERP data flows only between your SAP system, the MCP server in your network and your CompanyGPT environment. For license validation the server, according to Versino, reports only metadata such as customer number, edition, version and seat count to the license server; no business data. Operation without this connection is intended for air-gapped environments.

Frequently Asked Questions

SAP Business One and AI – the most important answers

Does SAP Business One have an official MCP server?

Since SAP Business One 10.0 FP 2608, SAP has shipped an MCP server as sample code: Streamable HTTP, Service Layer entities as dynamic tools, OAuth via Keycloak. SAP explicitly labels it as a reference for learning and demonstration purposes, not as a product released for production. For production use we therefore rely on the licensed MCP server by Versino AG, which is continuously developed and supported.

Why the Versino server rather than a community server?

The Versino server signs every user in with their own SAP identity, so the permissions from Business One apply unchanged. It ships curated reports, supports read and write via the Service Layer, can be limited to what is needed through operation mode and edition, and is maintained by the vendor with releases and support. Community servers usually work with a shared service user and read-only.

Where does that MCP server run?

In your own infrastructure: as a service or container on a server close to the Service Layer, behind TLS. CompanyGPT connects to the endpoint over a secured network connection. No external service sits in between, and queries to Business One stay within your network. If Business One is hosted by a partner, Versino names operation through the hosting partner Cloudiax as an option.

Can the AI create or change documents in Business One?

Yes, if the instance runs in READ_WRITE mode, the edition includes write tools and the signed-in SAP user has the permission. The agent can then create business partners and documents, change fields, remove lines from open documents and upload attachments; cancelling, closing and deleting are reserved for the highest edition. Many customers start read-only and release write access step by step.

How do users sign in without typing their password into the chat?

The agent returns a login link. On the login page in the browser the user enters SAP user, password and company, or signs in via single sign-on with your identity provider. In multi-user operation, login via chat can be disabled entirely so that credentials are captured exclusively through the browser.

What is needed if Business One runs in our own server room?

Then the MCP server runs in the same network, and CompanyGPT needs a secured connection to it. We set this up with your IT team or your Business One partner; exposing the system to the open internet is not required.

Who in the company may use the integration?

Two levels: your CompanyGPT administrators release the integration via roles and groups, and within SAP the permissions of the signed-in user apply. In addition, the license limits how many SAP users work concurrently.

What does the integration cost?

The Versino server is a licensed product offered per user in the editions BASIC, PRO and ENTERPRISE, with monthly cancellation according to Versino. Current terms are published in Versino's license portal. On the CompanyGPT side, the MCP connection is part of the platform; setup, network connectivity and training are handled by us as part of your CompanyGPT project.

Sources and Further Reading

SAP Business One and Your AI – GDPR-Compliant with CompanyGPT

CompanyGPT is the enterprise AI assistant in your own cloud tenant: all relevant AI models, your company data and integrations like SAP Business One – centrally managed, with roles and permissions. We set up the connection together with you.

SAP Business One is a trademark of its respective owner (SAP SE (MCP server: Versino AG)). Its mention describes compatibility and does not imply any partnership or endorsement. Availability and scope of the connection depend on the respective vendor.