Configuration¶
The server knows two configuration sources:
- Environment variables for a single Manager.
- Managers file
~/.cco-mcp-server/managers.jsonwith named profiles, also for several Managers side by side.
If CCOM_URL is set, the environment variables win and the file is
ignored.
Start by listing your Managers¶
Ask your assistant: "List my CCO Managers and check their connections."
list_managers returns readable display names, stable profile keys, privacy modes
and read-only settings. URLs and login identities are visible by default; the
optional experimental minimize filter withholds them when enabled.
With several active profiles, every other tool requires a manager value.
Name the target in your request. The assistant should ask when it is unclear.
Add profiles with cco-mcp-server add-manager, then restart the MCP connection.
A connection pinned with --manager sees only that profile. CCOM_URL also
limits the connection to one Manager and overrides the saved profiles.
Environment variables¶
| Variable | Meaning |
|---|---|
CCOM_URL |
Manager base URL. On-premise e.g. https://ccom.example.com, Cloud Edition https://<tenant>-api.customercheckout.cloud.sap |
CCOM_ADMIN_USER / CCOM_ADMIN_PASSWORD |
User/password (on-premise FP21; the user defaults to Admin) |
CCOM_CLIENT_ID / CCOM_CLIENT_SECRET |
API client (Cloud Edition; takes precedence when set) |
CCO_MCP_READONLY |
true allows read access only; with the managers file this applies to all profiles |
CCO_MCP_MANAGERS_FILE |
Path to the managers file (default ~/.cco-mcp-server/managers.json) |
CCOM_MANAGER |
Profile name from the managers file (alternative to the --manager flag) |
CCOM_DISPLAY_NAME |
Readable label for the single Manager configured with CCOM_URL; defaults to default |
CCO_MCP_PRIVACY_MODE |
minimize or off; when set, overrides every active profile. Missing settings default to off, including older profiles; minimize enables the experimental filter |
CCO_MCP_LICENSE / CCO_MCP_LICENSE_FILE |
License key or path to it, see Operation |
Multiple Managers: the managers file¶
Profiles in managers.json keep the credentials out of the MCP client's
configuration and allow any number of Managers side by side.
The easiest way to create the file is the wizard:
cco-mcp-server add-manager
It asks for a stable key, readable display name, type, URL, credentials (secrets
masked), read-only access and the optional experimental privacy filter. It tests the
connection before saving, creates the file with 0600 permissions, and
prints the matching registration snippets for your MCP client. You can run
it again at any time to add more profiles.
Written by hand, the file looks like this:
{
"managers": {
"zentrale": {
"displayName": "Head office — production",
"url": "https://ccom.example.com",
"user": "Admin",
"password": "...",
"privacyMode": "off"
},
"cloud": {
"displayName": "Cloud demo — training",
"url": "https://<tenant>-api.customercheckout.cloud.sap",
"clientId": "...",
"clientSecret": "...",
"readOnly": true,
"privacyMode": "off"
}
}
}
The server derives the auth type per entry: clientId/clientSecret means
Cloud Edition (OAuth), password (plus optional user, default Admin)
means on-premise (session). readOnly applies per entry;
CCO_MCP_READONLY=true enforces it for all of them.
Profile keys may contain letters, digits, ., _ and - (64 characters at
most). displayName is a readable label of up to 120 characters. It can contain
spaces and Unicode, but no control characters. Missing labels fall back to the
key. Changing a label never changes routing: tools and --manager always use
the key. Duplicate labels are allowed, so the assistant must disambiguate them
using their keys. Use environment or location labels rather than personal names;
these labels and keys are intentionally visible to the AI assistant.
Experimental privacy filter¶
The privacy filter is disabled by default. Missing settings resolve to off
for new and existing profiles, so normal tool results can include personal data
and detailed errors. Existing explicit minimize or off settings are preserved.
To enable the experimental filter for one profile, set "privacyMode": "minimize"
in its entry, or answer yes to the experimental privacy filter prompt in
cco-mcp-server add-manager. The wizard defaults to no for new profiles and
retains the current choice when editing an existing profile.
When enabled, the filter removes known personal fields, personal identifiers and free-text notes from responses. Revenue rows, articles, prices and quick-selection reads and writes remain available. Raw API requests, action deployment and job starts are blocked for that profile. Read-only access remains independent.
CCO_MCP_PRIVACY_MODE=minimize enables the experimental filter across every
active profile, even one explicitly set to off. CCO_MCP_PRIVACY_MODE=off
disables it across every profile. Invalid values stop startup rather than
silently changing the setting.
After changing labels or privacy settings, restart the MCP connection and open a new conversation. Existing conversations may retain their original connection and data already returned. See Privacy mode for filtered fields, limitations and the data processing agreement (DPA/AVV) and legal considerations you must assess for your own use.
Which Manager is used?¶
CCOM_URLset: only the environment variables count, the file is ignored. Combining this with--manageris an error.--manager <name>(as an argument after the binary) orCCOM_MANAGER: exactly this profile. This way, several MCP entries can point at the same file, for examplecco-zentralewith--manager zentrale.- No selection, several profiles: multi-manager mode. A single MCP
entry serves all Managers; every tool gets a required
managerparameter listing the profile names to choose from. Thelist_managerstool describes the profiles and, on request, checks the connection per Manager. This also makes cross-manager work possible within one session, when each target profile permits the requested operation.
Setting up the Cloud Edition¶
- Client ID and client secret are in the Manager under Configuration → General → API settings.
- On the first API access, the Manager automatically creates a Technical
User (in the Users app, named after the client ID). You must assign this
user a role once, for example Administrator. Until then, every access is
answered with
401. The connection test of theadd-managerwizard points out this case.
Recommendations for safe operation¶
- The server acts with the permissions of the configured user or API client. Create a dedicated technical user with exactly the permissions needed, rather than storing an admin account.
- For production systems,
"readOnly": trueon the profile orCCO_MCP_READONLY=trueas the default is worth it. The server then rejects all write tools. - Write calls are additionally confirmed in your MCP client: Claude Code and Claude Desktop ask before every tool call, unless you have allowed it across the board. Details on the Usage page.