Back to Browse

Successfactors Toolkit MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

SAP SuccessFactors OData and Compound Employee queries with PII tokenization for AI agents.

About

SAP SuccessFactors OData and Compound Employee queries with PII tokenization for AI agents.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 2 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. Trust signals: trusted author (3/3 approved).

4 files analyzed · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

Documentation

View on GitHub

From the project's GitHub README.

SuccessFactors Toolkit

CI License Python

A self-hosted toolkit for SAP SuccessFactors API troubleshooting, payload extraction, and integration development, exposed as a REST API and as an MCP (Model Context Protocol) server.

APIProtocolEndpoint prefix
EC SFAPI — Compound EmployeeSOAP 1.1/api/sfapi/ce/
ODataREST (v2, v4)/api/odata/

OData v4 covers the SuccessFactors APIs published as v4 services (for example Calibration and Continuous Feedback); Employee Central and Onboarding data stay on v2. See OData API.

This is an independent project, not affiliated with or endorsed by SAP SE. SAP and SuccessFactors are trademarks of SAP SE.

Start here: Docker MCP → credentials → ask → export

Data security: prefer local deployment. For sensitive SuccessFactors employee data and credentials, we recommend running the MCP server in local Docker and using a local AI agent, rather than an online AI platform or a third-party hosted MCP service. Keep credentials and exports on your machine; do not upload private keys or employee payloads to online platforms.

A local AI agent is not necessarily a local model. If it calls a cloud model, prompts, tool responses, previews, and file contents supplied to that model may leave your machine. If HR data must stay within your controlled environment, use a locally hosted model and local file-processing tools, and check the agent's outbound data handling. Local Docker alone does not guarantee this. The toolkit still connects to your configured SuccessFactors tenant to query data.

For functional consultants and business key users, start with the business user guide or its English/Chinese HTML edition. Ask IT to complete the one-time Docker Compose setup and provide approved connection files. Then:

  1. Check Docker Desktop or your IT-managed Docker service is running, then open your local AI application.
  2. Confirm with IT that the connection files are in sf-toolkit/credentials.
  3. Confirm the SuccessFactors environment and ask for the employee, date, and information you need.
  4. Find results under sf-toolkit/data/mcp. Ask a file-capable AI application for CSV or another supported format, or a copy in an authorized folder.

The guide includes example business questions, completion checks, troubleshooting, and expandable one-time settings for your administrator. Original OData results are JSON; Compound Employee results are XML. CSV conversion requires local file tools in the AI application.

Documentation

PageCovers
REST APIFail-closed setup, install and run, cheat sheet, response format
Connect to SuccessFactorsKey pair generation, environment variables, private key resolution order, tenant management
EC SFAPI (SOAP)Compound Employee single lookup, structured filter query, pagination, known footguns
OData APIexecute / extract / extract-by-filter-in, OData v4 services, per-request connection override, known API footguns
MCP serverTools for AI agents, payload handling, export formats, PII tokenization, plugins
DevelopmentLocal dev setup, linting, tests, release process

Data handling

Use synthetic examples and test fixtures. Credentials, certificates, tenant exports, employee payloads, and generated results do not belong in Git — .gitignore and scripts/check_repository.py are a basic guardrail, not a complete secret or personal-data scanner. See SECURITY.md for deployment guidance and how to report a vulnerability.

License

Apache License 2.0. Copyright 2026 Justin Gong. See NOTICE for third-party and migrated-code attribution.

Reviews

No reviews yet

Be the first to review this server!