Connecting
The MCP server runs inside the Beas web server, so there is nothing extra to install or start. It has to be switched on in the server's configuration, and the assistant has to authenticate as a Beas user.
Switching it on
The Mcp section of the Beas web server's appsettings.json controls the server. Restart the Beas
web server after changing it.
| Setting | Description |
|---|---|
| Enabled | Whether the server responds at all. When it is off, the endpoint is not published — a client gets nothing to connect to, not an error. |
| Path | Where the endpoint is published. Default /mcp. |
| EnableWriteTools | Whether the four tools that change data are offered. When off, the server is read-only for everyone regardless of their permissions. |
| EnableODataQueryTool | Whether the generic OData query tool is offered. When off, an assistant can only reach the entities that have a dedicated tool. |
| SessionExpirationDays | How long a session created for an API-key caller stays valid. |
| VerifySSL | Whether the server validates the certificate on its own loopback call. Off by default, because a development server presents a self-signed certificate. Switch it on for a hardened deployment. |
EnableWriteTools and EnableODataQueryTool are both on by default. Decide deliberately
whether that is what you want before exposing the endpoint to anyone, and read
Security and permissions first.
Choosing an authentication scheme
The endpoint accepts two schemes, and the choice decides what the assistant can do. It is not a convenience question.
| Scheme | How | What it can reach |
|---|---|---|
| User session | Log in through the Beas API and connect with the session that login returns. | Everything: all read tools, the generic OData tool, and the write tools the user has permission for. |
| API key | Send the Beas web server key as a Bearer token, plus a header naming the company database and a header naming the user code. | Read tools only. Write tools and the generic OData tool refuse an API-key caller outright. |
The API key is the BeasWebServerKey value from the Beas setup — the same key the rest of the Beas web server uses, not a key you create per assistant. There is one, it is shared, and it grants read access to whichever company database the caller names.
Because the key is shared and long-lived, treat it as a server secret. Anyone holding it can read the manufacturing data of any company database the server can reach, as any user code they choose. Prefer a user session wherever the assistant can hold one.
Pointing a client at it
An MCP client needs the endpoint URL and the credentials. The URL is the Beas web server's address followed by the configured path — the same host your users open the web client on.
Once connected, the assistant asks the server what it offers; there is no list to configure on the client side. Ask it to read the usage guide resource first if you want it to orient itself before its first query — see Prompts and resources.
Examples
The client connects but sees no tools at all. The server is reachable but disabled, or it is
published on a different path. Check Enabled and Path, and remember the web server has to be
restarted after the change.
Every write attempt is refused although the user is an administrator. Two different gates
produce this. If the assistant connected with the API key, writes are refused before permissions
are even considered — reconnect with a user session. If it is on a session and still refused, the
server has EnableWriteTools switched off, which overrides the user's permissions entirely.
A tool that worked yesterday now reports that the session is no longer authorized. The stored SAP credentials behind the session have expired. Log in again and reconnect the assistant with the new session; nothing in the MCP configuration needs changing.