Back to Browse

Frappe MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Interact with Frappe/ERPNext sites — document CRUD, search, and whitelisted method calls

About

Interact with Frappe/ERPNext sites — document CRUD, search, and whitelisted method calls

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-architected Frappe MCP server with strong authentication, proper input validation, and clear permission scoping. The server requires API credentials (token-based auth via environment variables), implements URL-safe path encoding to prevent traversal attacks, and provides comprehensive tool documentation. Minor code quality observations around broad exception handling and logging do not materially impact security. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.

5 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Base URL of your Frappe/ERPNext site, e.g. https://your-site.erpnext.comOptional

Environment variable: FRAPPE_URL

Frappe API key for token-based authenticationRequired

Environment variable: FRAPPE_API_KEY

Frappe API secret paired with the API keyRequired

Environment variable: FRAPPE_API_SECRET

Set to 'false' to skip TLS certificate verification. Defaults to 'true'.Optional

Environment variable: FRAPPE_VERIFY_SSL

Per-request timeout in seconds. Defaults to 30.Optional

Environment variable: FRAPPE_TIMEOUT

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-muthanii-frappe-mcp": {
      "env": {
        "FRAPPE_URL": "your-frappe-url-here",
        "FRAPPE_API_KEY": "your-frappe-api-key-here",
        "FRAPPE_TIMEOUT": "your-frappe-timeout-here",
        "FRAPPE_API_SECRET": "your-frappe-api-secret-here",
        "FRAPPE_VERIFY_SSL": "your-frappe-verify-ssl-here"
      },
      "args": [
        "frappe-mcp-server"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Frappe MCP Server

PyPI Python Docker Hub Docker pulls GHCR MCP Registry License

frappe_mcp MCP server

mcp-name: io.github.muthanii/frappe_mcp

A Model Context Protocol (MCP) server for Frappe Framework. Connect Claude Desktop, VS Code Copilot, and other MCP clients to any Frappe/ERPNext site via its REST API.

Where to get it

DistributionReferencePage
PyPIfrappe-mcp-serverpypi.org/project/frappe-mcp-server
Docker Hubmuthanii/frappe-mcphub.docker.com/r/muthanii/frappe-mcp
GitHub Container Registryghcr.io/muthanii/frappe-mcpghcr package
MCP Registryio.github.muthanii/frappe_mcpregistry API
Glamaglama.ai/mcp/servers/muthanii/frappe_mcp
Sourcegithub.com/muthanii/frappe_mcp

Features

  • Document CRUD — get, create, update, delete Frappe doctypes
  • Search — full-text and filtered document search
  • Remote method calls — invoke any server-side Python method
  • Authentication — API key + secret (token-based auth)
  • Docker-first — single docker run command, no Python install needed

Quick start

With uvx (no install):

FRAPPE_URL=https://your-site.com \
FRAPPE_API_KEY=your-api-key \
FRAPPE_API_SECRET=your-api-secret \
  uvx frappe-mcp-server

With pip:

pip install frappe-mcp-server
frappe-mcp-server

With Docker (Docker Hub):

docker run -i --rm \
  -e FRAPPE_URL=https://your-site.com \
  -e FRAPPE_API_KEY=your-api-key \
  -e FRAPPE_API_SECRET=your-api-secret \
  muthanii/frappe-mcp

With Docker (GHCR):

docker run -i --rm \
  -e FRAPPE_URL=https://your-site.com \
  -e FRAPPE_API_KEY=your-api-key \
  -e FRAPPE_API_SECRET=your-api-secret \
  ghcr.io/muthanii/frappe-mcp

Available tools

Every tool ships MCP tool annotations and a declared outputSchema, so a client can tell read tools from destructive ones before calling them.

ToolDescriptionAccessDestructiveIdempotent
frappe_pingCheck connectivity and credentialsread-onlynoyes
frappe_get_docRetrieve a single document by doctype + nameread-onlynoyes
frappe_search_docsSearch/list documents with filtersread-onlynoyes
frappe_create_docCreate a new documentwritenono
frappe_update_docUpdate an existing documentwriteyesyes
frappe_delete_docDelete a document — irreversiblewriteyesno
frappe_run_methodCall a whitelisted server-side methodwriteyesno

frappe_run_method is marked destructive because its effect is determined entirely by the method you name.

Configuration

Environment variableRequiredDescription
FRAPPE_URLYesBase URL of your Frappe site (e.g. https://erp.example.com)
FRAPPE_API_KEYYesFrappe API key
FRAPPE_API_SECRETYesFrappe API secret
FRAPPE_VERIFY_SSLNoSet to false to skip TLS verification (default: true)
FRAPPE_TIMEOUTNoRequest timeout in seconds (default: 30)

MCP client config

Add this to your claude_desktop_config.json or Copilot config.

Via uvx:

{
  "mcpServers": {
    "frappe": {
      "command": "uvx",
      "args": ["frappe-mcp-server"],
      "env": {
        "FRAPPE_URL": "https://your-site.com",
        "FRAPPE_API_KEY": "your-api-key",
        "FRAPPE_API_SECRET": "your-api-secret"
      }
    }
  }
}

Via Docker:

{
  "mcpServers": {
    "frappe": {
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "-e", "FRAPPE_URL",
        "-e", "FRAPPE_API_KEY",
        "-e", "FRAPPE_API_SECRET",
        "muthanii/frappe-mcp"
      ],
      "env": {
        "FRAPPE_URL": "https://your-site.com",
        "FRAPPE_API_KEY": "your-api-key",
        "FRAPPE_API_SECRET": "your-api-secret"
      }
    }
  }
}

Local development

pip install -e .
frappe-mcp

License

MIT — see LICENSE.


frappe_mcp MCP server

Reviews

No reviews yet

Be the first to review this server!