{"_id":"@arc-mcp/arc-1-lsp","name":"@arc-mcp/arc-1-lsp","dist-tags":{"latest":"0.3.0"},"versions":{"0.3.0":{"name":"@arc-mcp/arc-1-lsp","version":"0.3.0","description":"ARC-1 edition that delegates all ABAP/ADT work to SAP's embedded adt-ls language server.","keywords":["sap","abap","adt","adt-ls","mcp","model-context-protocol","claude","llm","ai","btp"],"license":"MIT","author":{"name":"Marian Zeis"},"homepage":"https://github.com/arc-mcp/arc-1-lsp#readme","repository":{"type":"git","url":"git+https://github.com/arc-mcp/arc-1-lsp.git"},"bugs":{"url":"https://github.com/arc-mcp/arc-1-lsp/issues"},"type":"module","bin":{"arc1-lsp":"dist/index.js"},"publishConfig":{"access":"public"},"engines":{"node":">=22"},"scripts":{"build":"tsc -p tsconfig.json","dev":"tsx src/index.ts","dev:http":"ARC1_TRANSPORT=http-streamable tsx src/index.ts","test":"vitest run","test:watch":"vitest","typecheck":"tsc -p tsconfig.json --noEmit","lint":"biome check src tests","lint:fix":"biome check --write src tests","format":"biome format --write src tests"},"dependencies":{"@marianfoo/adt-ls":"^0.5.0","@modelcontextprotocol/sdk":"^1.12.0","commander":"^12.1.0","vscode-jsonrpc":"^8.2.0","zod":"^3.23.8"},"devDependencies":{"@biomejs/biome":"^1.9.4","@types/node":"^22.9.0","tsx":"^4.19.2","typescript":"^5.6.3","vitest":"^2.1.5"},"_id":"@arc-mcp/arc-1-lsp@0.3.0","_nodeVersion":"22.21.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-GcnpwGP8FJlpcqjCOAEARqZyLMzm6fBjcwCXjuwgtVMdMqUzWQuPCKFxYnSB8cDCM5hkW3NiA9k1lTOiOyrDiA==","shasum":"a78600cbf1a8361698b9f79da20e01f4ff3a11fb","tarball":"https://registry.npmjs.org/@arc-mcp/arc-1-lsp/-/arc-1-lsp-0.3.0.tgz","fileCount":37,"unpackedSize":144982,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHtZqXeyHH93uZHGFUYgfmoHPy3TXkzgil+ElHUJLzeSAiEAo7HFBDg1HkFo/e88Mlhmaqe5Codvt1/Bd/KQCysMnI4="}]},"_npmUser":{"name":"marianfoo","email":"marianbsp@gmail.com"},"directories":{},"maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/arc-1-lsp_0.3.0_1781726735881_0.43452697487457215"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-17T20:05:35.761Z","0.3.0":"2026-06-17T20:05:36.028Z","modified":"2026-06-17T20:05:36.334Z"},"maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"description":"ARC-1 edition that delegates all ABAP/ADT work to SAP's embedded adt-ls language server.","homepage":"https://github.com/arc-mcp/arc-1-lsp#readme","keywords":["sap","abap","adt","adt-ls","mcp","model-context-protocol","claude","llm","ai","btp"],"repository":{"type":"git","url":"git+https://github.com/arc-mcp/arc-1-lsp.git"},"author":{"name":"Marian Zeis"},"bugs":{"url":"https://github.com/arc-mcp/arc-1-lsp/issues"},"license":"MIT","readme":"# arc-1-lsp\n\nAn edition of **ARC-1** — a Model Context Protocol (MCP) server for SAP ABAP\ndevelopment — that delegates **all** ABAP/ADT interaction to SAP's own embedded\n**`adt-ls`** language server instead of a hand-rolled ADT HTTP client. arc-1-lsp\nowns the MCP front-end, auth/scopes, write-safety, and orchestration; `adt-ls`\nowns CSRF, locking, XML, activation, transport — everything system-specific.\n\n> **Status:** working — connects headless to a SAP system, exposes 39 MCP tools\n> (reads + LSP code-intelligence incl. hover · ATC + ABAP-Unit coverage · a full\n> create→edit→activate→test→delete authoring loop · RAP generation · run-application ·\n> service-binding publish · native transport), runs locally\n> over stdio or as a Docker app on SAP BTP Cloud Foundry. Single-tenant / one\n> technical user today; per-user principal propagation is on the roadmap.\n\n## Where `adt-ls` comes from\n\n`adt-ls` is **SAP's** language server: the headless core of the Eclipse-based\n**ABAP Development Tools (ADT)**, shipped inside the official\n[**ABAP Development Tools for VS Code**](https://marketplace.visualstudio.com/items?itemName=SAPSE.adt-vscode)\nextension (`sapse.adt-vscode`). It exposes **three** surfaces, and arc-1-lsp drives\nall of them:\n1. **standard LSP code-intelligence** (`textDocument/*` — document symbols, go-to-\n   definition, references/where-used, type hierarchy, diagnostics/syntax check,\n   completion) — it *is* a language server;\n2. a **private LSP namespace** (`adtLs/*` — destinations, logon, filesystem,\n   activation, transport, unit tests);\n3. an embedded **experimental MCP server** (object creation, activation, RAP\n   generators, transports, …).\n\narc-1-lsp does not reimplement any of that — it **discovers, spawns, and drives**\nthe developer-provided `adt-ls` headless (no Eclipse, no VS Code, no browser). The\n`adt-ls` binary is under SAP's Developer License and is **never bundled or\nredistributed** — you bring your own (see [Prerequisites](#prerequisites) and\n[ADR-0002](docs/adr/0002-byo-adt-ls-no-redistribution.md)).\n\n## arc-1-lsp vs. main ARC-1 — which should I use?\n\nBoth are MCP servers for SAP ABAP and share the same tool shape. They differ in\n*how* they talk to SAP, and therefore in what they can do.\n\n| | **[ARC-1](https://github.com/marianfoo/arc-1)** (main) | **arc-1-lsp** (this repo) |\n|---|---|---|\n| ADT protocol | Hand-rolled (CSRF, locking, XML, version quirks) | Delegated to SAP's `adt-ls` |\n| System-specific code to maintain | ~29 ADT modules | ~zero (it's SAP's job) |\n| Object-type coverage | **All** — classic *and* modern (programs, tables, function groups, domains, CDS, classes, RAP, …) | **Modern ABAP-Cloud types only** (class, interface, CDS, behavior def, service def/binding, …) |\n| Free SQL / data preview | ✅ | ❌ (absent in adt-ls) |\n| Navigation / where-used / type hierarchy | ✅ | ✅ (via adt-ls's standard LSP — `textDocument/*`) |\n| Syntax check / ATC | ✅ | ✅ syntax check (`check_syntax`) + ATC (`run_atc`, system-default variant) |\n| Git (gCTS / abapGit) | ✅ | ❌ (absent in adt-ls) |\n| Maturity | Production, multi-user, write-capable | Working; reads + authoring loop; single technical user |\n\n**Use main ARC-1** for the broadest coverage (classic objects, free SQL, git,\ntransport release/delete) and production multi-user deployments. **Use arc-1-lsp** when you want\nSAP itself to own the ADT protocol — less code to maintain, and behavior that\ntracks ADT exactly (including its standard LSP code-intelligence) — and your work\nis on modern ABAP-Cloud objects.\n\nThe honest, line-by-line map of what is and isn't wired (and *why*) lives in\n[`docs/arc-1-feature-parity.md`](docs/arc-1-feature-parity.md); the live-verified\ncapability boundary of `adt-ls` itself is in\n[`docs/adt-ls-reference.md`](docs/adt-ls-reference.md).\n\n## What works today\n\n**27 MCP tools.** Reads work read-only; mutating tools are gated behind\n`ARC1_ALLOW_WRITES` + a package allowlist (transport creation additionally needs\n`ARC1_ALLOW_TRANSPORT_WRITES`).\n\n- **Reads (14):** `health`, `list_destinations`, `list_creatable_objects`,\n  `search_objects`, `list_inactive_objects`, `list_users`, `list_generators`,\n  `get_generator_schema`, `get_object_type_details`, `get_service_binding`,\n  `get_service_details`, `read_source`, `validate_object`, `find_transport`.\n- **Code intelligence (9, LSP):** `document_symbols` (outline), `go_to_definition`,\n  `go_to_declaration`, `find_references`, `type_hierarchy` (super/subtypes +\n  implementations), `hover` (signature + ABAP-Doc), `document_highlight`,\n  `check_syntax` (the ABAP syntax check, no activation needed), `completion`.\n  adt-ls is a language server — these proxy its standard `textDocument/*` APIs;\n  target a declared `symbol` by name or a 1-based `line`+`character`.\n- **Quality & test (3):** `run_atc` (ABAP Test Cockpit static analysis — security/\n  performance/cloud-readiness, system-default variant), `list_atc_variants`,\n  `run_unit_tests_with_coverage` (test result + statement/branch/procedure coverage).\n- **Runtime & business services (3):** `run_application` (run an `if_oo_adt_classrun`\n  class or program, capture console output), `service_binding_details`,\n  `publish_service_binding` (publish/unpublish a SRVB → live OData; write-gated).\n- **Authoring loop (5, write-gated):** `create_object`, `update_source`,\n  `activate_object`, `run_unit_tests`, `delete_object` — a full\n  create → edit → activate → test → delete cycle, by object name, for modern\n  ABAP-Cloud types. `activate_object` returns ranged syntax diagnostics so an\n  agent can self-correct.\n- **Generation + transport (5, gated):** `generate_objects` runs a RAP generator\n  (scaffolds a full table/CDS/behavior/service set); `create_transport` opens a\n  CTS request; `assign_transport` pins an existing TR to an object (returns a\n  structured `{assigned, object, transport}`); `list_transports` (capped to `limit`,\n  default 100, with an optional `query` filter — the system can hold thousands of\n  requests) + `get_lock_status` (reads). For transportable (non-`$TMP`) packages the flow is\n  `validate_object` → `find_transport` → (`create_transport`) →\n  `create_object`/`generate_objects` (pass the TR as `transport`).\n\n**Out of scope here (use main ARC-1):** classic object types (program/table/\nfunction group/domain/…), free SQL, transport *release/delete*, and git. These are\nhonest limits of `adt-ls`'s headless surface, not missing features — details in\n[`docs/arc-1-feature-parity.md`](docs/arc-1-feature-parity.md).\n\nThe SAP session behind `adt-ls` self-heals: if it expires (idle timeout →\n\"logged off\"), arc-1-lsp transparently re-logs on and retries the call once.\n\n## Architecture\n\n```\nagent (Claude / Copilot / Cursor / …)\n   │  MCP (stdio | http-streamable)\n   ▼\narc-1-lsp  (Node/TS — discovers, spawns & supervises adt-ls; auth + scopes; owns SAP logon)\n   ├─ LSP over pipe ───────────▶ adt-ls (headless, BYO)   ← bootstrap, destinations, logon, filesystem, activation\n   └─ HTTP localhost ─────────▶ adt-ls's own /mcp         ← federated tools\n                                      │ HTTPS\n                                      ▼\n                          TLS reverse proxy (CN=localhost, in arc-1-lsp)\n                                      │  DIRECT ───────────────▶ SAP ABAP (internet-reachable)\n                                      └  CC ─▶ connectivity bridge ─▶ BTP Connectivity ─▶ Cloud Connector ─▶ SAP ABAP\n```\n\n`adt-ls` requires an **HTTPS** backend and validates its hostname; SAP's default\nself-signed cert (`CN=*.dummy.nodomain`) fails that. So arc-1-lsp runs a local\n**TLS-terminating reverse proxy** (cert `CN=localhost`, trusted via a truststore\nbuilt from `adt-ls`'s own JRE) and re-originates to the real backend — directly,\nor through the connectivity bridge on BTP. Logon is **headless reentrance-ticket**\nemulation (no browser). Full recipe + decisions:\n[`docs/adt-ls-headless-notes.md`](docs/adt-ls-headless-notes.md) +\n[`docs/adr/`](docs/adr/README.md).\n\n## Prerequisites\n\n1. **Node.js 22+**.\n2. **A developer-provided `adt-ls`** (BYO — never redistributed). Install the\n   official **ABAP Development Tools for VS Code** extension (`sapse.adt-vscode`,\n   which accepts SAP's Developer License) and arc-1-lsp finds its `adt-ls`\n   automatically. Discovery order:\n   1. `ARC1_ADT_LS_PATH` (explicit path)\n   2. `vendor/adt-ls/<platform>/…` (build-time injection, for containers)\n   3. the newest installed `sapse.adt-vscode-*` VS Code extension\n3. **A reachable SAP ABAP system** to connect to (optional — the server also\n   starts disconnected and still serves `health`/`tools`). Runtime cert/proxy\n   deps: `openssl` + `keytool` (the latter ships inside `adt-ls`'s JRE). See\n   [`docs/native-deps.md`](docs/native-deps.md).\n\n> **Compatibility:** arc-1-lsp drives `adt-ls`'s private `adtLs/*` protocol, which\n> can change between releases. This build is verified against `sapse.adt-vscode`\n> **1.0.0** / adt-ls **1.0.0.202605281240**; on a different version arc-1-lsp logs\n> a startup warning and you should re-verify against\n> [`docs/adt-ls-reference.md`](docs/adt-ls-reference.md).\n\n## Install & run\n\n### From source (stdio)\n\n```bash\nnpm install\nnpm run build\nnode dist/index.js          # or: npm run dev (tsx, no build)\n```\n\nPoint an MCP client at the process over **stdio**. With no SAP vars set it starts\ndisconnected (handy for inspecting the tool list); set `ARC1_SAP_*` to auto-connect\n(see [Connect a SAP system](#connect-a-sap-system)).\n\n### As a CLI (npm)\n\n```bash\nnpm install -g @arc-mcp/arc-1-lsp\narc1-lsp                    # stdio MCP server (honors the same env/flags)\n```\n\nThe npm package ships the Node wrapper only — it still discovers your BYO `adt-ls`\n(it does **not** contain any SAP binary).\n\n### Docker / http-streamable\n\nThe container bundles a **build-time-injected** linux `adt-ls` and serves MCP over\nhttp-streamable behind an API key — this is the artifact deployed to BTP CF.\n\n```bash\n# stage the linux adt-ls (admin provides the licensed VSIX → vendor/)\nnode scripts/extract-adt-ls.mjs\n# build the linux/amd64 image (host-builds dist; only prod deps + adt-ls are amd64)\nIMAGE=arc-1-lsp:dev bash scripts/docker-build.sh\n# run\ndocker run -e ARC1_API_KEYS=devkey -p 8080:8080 arc-1-lsp:dev\n```\n\n`GET /healthz` (no auth) for health checks; `POST /mcp` with\n`Authorization: Bearer <key>` for MCP.\n\n## Connect a SAP system\n\nSet the `ARC1_SAP_*` vars (or `--sap-*` flags) and arc-1-lsp logs on at startup.\n\n```bash\nARC1_SAP_HOST=a4h.example.com ARC1_SAP_PORT=50001 \\\nARC1_SAP_USER=DEVELOPER ARC1_SAP_PASSWORD=… ARC1_SAP_DESTINATION=A4H \\\nnode dist/index.js\n```\n\n`health` then reports `connectedDestination`, and `list_creatable_objects` returns\nthe system's object catalog. Two connection modes:\n\n- **DIRECT** (default) — the reverse proxy connects straight to an\n  internet-reachable backend. All four of `HOST`/`PORT`/`USER`/`PASSWORD` must be set.\n- **CC** (on-prem via Cloud Connector, on BTP) — bind the `connectivity` +\n  `destination` services and set only `ARC1_SAP_DESTINATION <btp-destination-name>`;\n  the engine resolves it and routes through the connectivity bridge automatically.\n\n**Auth (DIRECT mode):** `basic` (user + password, default), `sso` (interactive browser\nlogon), or `clientcert` (**passwordless X.509 mutual TLS** — no browser, no password, silent\nre-auth; set `ARC1_SAP_CLIENT_CERT`/`_KEY`). The client-cert path has its own guide covering\nthe AS ABAP server setup and how to obtain/store certificates (incl. enterprise / SAP Secure\nLogin Service): **[docs/client-cert-auth-setup.md](docs/client-cert-auth-setup.md)**.\n\n### Connect an MCP client\n\n```jsonc\n// Claude Code (HTTP):\n//   claude mcp add --transport http arc1lsp https://<host>/mcp \\\n//     --header \"Authorization: Bearer <api-key>\"\n//\n// Cursor / Claude Desktop / VS Code — mcp.json:\n{\n  \"mcpServers\": {\n    \"arc1lsp\": {\n      \"url\": \"https://<host>/mcp\",\n      \"headers\": { \"Authorization\": \"Bearer <api-key>\" }\n    }\n  }\n}\n```\n\nFor local stdio, point the client at the `node dist/index.js` (or `arc1-lsp`)\nprocess instead of a URL. GUI inspector: `npx @modelcontextprotocol/inspector`.\n\n## Configuration (precedence: CLI flag > env var > default)\n\n> **Env prefix is `ARC1_*`, not `SAP_*`.** The main ARC-1 server uses `SAP_*` vars;\n> arc-1-lsp uses `ARC1_*` (e.g. `ARC1_ALLOW_TRANSPORT_WRITES`, `ARC1_SAP_USER`). A\n> `SAP_*` var is **ignored** — arc-1-lsp logs a startup warning naming the `ARC1_*`\n> twin it expected so a migrated config doesn't silently lose a setting.\n\n| Env / flag | Default | Meaning |\n|------------|---------|---------|\n| `ARC1_ADT_LS_PATH` / `--adt-ls-path` | (discovered) | explicit `adt-ls` binary |\n| `ARC1_ADT_LS_MCP_PORT` / `--adt-ls-mcp-port` | `2240` | port for `adt-ls`'s own MCP server |\n| `ARC1_ADT_LS_MCP_TOKEN` / `--adt-ls-mcp-token` | (generated) | bearer for `adt-ls`'s MCP server |\n| `ARC1_TRANSPORT` / `--transport` | `stdio` | `stdio` \\| `http-streamable` |\n| `ARC1_PORT` / `--port` | `8080` | HTTP port (http-streamable; CF `$PORT` honored) |\n| `ARC1_API_KEYS` / `--api-keys` | (none) | edge auth: `key[:label-or-profile][,key2…]`; empty disables auth (local only). A profile suffix `:viewer`/`:developer`/`:admin` assigns scopes (per-tool enforcement arrives with the XSUAA edge — see [ADR-0007](docs/adr/0007-enterprise-auth-scopes-xsuaa-pp.md)); any other suffix is a free label (defaults to `developer`) |\n| `ARC1_ALLOW_WRITES` / `--allow-writes` | `false` | enable mutating tools (create/update/activate/delete/generate) |\n| `ARC1_ALLOW_TRANSPORT_WRITES` / `--allow-transport-writes` | `false` | enable CTS transport creation (`create_transport`) — also requires `ARC1_ALLOW_WRITES` |\n| `ARC1_ALLOWED_PACKAGES` / `--allowed-packages` | `$TMP` | packages writes may target — exact / `PREFIX*` / `*` |\n| `ARC1_LOG_LEVEL` | `info` | `debug`\\|`info`\\|`warn`\\|`error` (stderr only) |\n| **SAP connection — DIRECT mode** (internet-reachable backend) | | |\n| `ARC1_SAP_HOST` / `--sap-host` | — | backend host |\n| `ARC1_SAP_PORT` / `--sap-port` | — | backend **HTTPS** port |\n| `ARC1_SAP_AUTH` / `--sap-auth` | `basic` | `basic` (headless user+password), `sso` (interactive browser logon — **local desktop only**; no password, but startup **blocks until you sign in** and re-auth re-opens the browser on your next call), or `clientcert` (passwordless **X.509 mutual TLS** — fully headless, **no browser**, silent re-auth; needs `ARC1_SAP_CLIENT_CERT`/`_KEY`). |\n| `ARC1_SAP_USER` / `--sap-user` | — | SAP user (basic: the reentrance ticket is fetched with these creds; sso / clientcert: an optional destination hint — the real user comes from the cert mapping) |\n| `ARC1_SAP_PASSWORD` / `--sap-password` | — | SAP password (basic mode; set via env / `cf set-env`, never committed). Not used in `sso` / `clientcert` mode. |\n| `ARC1_SAP_CLIENT_CERT` / `--sap-client-cert` | — | PEM client-certificate file path (`clientcert` mode); the subject must map to a SAP user via CERTRULE. **Where to get it** — and why your everyday \"it just works\" SSO cert usually *can't* be used (short-lived / non-exportable): see [Obtaining a client certificate](docs/client-cert-auth-setup.md#obtaining-a-client-certificate). |\n| `ARC1_SAP_CLIENT_KEY` / `--sap-client-key` | — | PEM private-key file path (`clientcert` mode). |\n| `ARC1_SAP_DESTINATION` / `--sap-destination` | `SAP` | `adt-ls` destination id (DIRECT) **or** BTP destination name (CC) |\n| `ARC1_SAP_CLIENT` / `--sap-client` | `001` | SAP client |\n| `ARC1_SAP_LANGUAGE` / `--sap-language` | `EN` | SAP logon language |\n| `ARC1_SAP_INSECURE` / `--sap-insecure` | `true` | accept the backend's self-signed cert (the proxy's own TLS is trusted separately) |\n| **SAP connection — CC mode** (on-prem via Cloud Connector) | | |\n| `ARC1_SAP_DESTINATION` | — | BTP Destination Service name; resolved when `connectivity` is bound |\n\n> Config is read from CLI flags and the process environment only (no `.env`\n> auto-loading) — export the vars in your shell or set them via `cf set-env`.\n\n## Deploy to BTP Cloud Foundry\n\nThe image deploys to CF as a docker app (see `manifest.yml`). Secrets stay out of\ngit — the API key, SAP creds, and the registry pull token are passed at deploy time:\n\n```bash\ndocker push ghcr.io/<owner>/arc-1-lsp:0.1.0\n# secrets via cf set-env (never committed):\ncf set-env arc-1-lsp ARC1_API_KEYS \"$(openssl rand -hex 16)\"\ncf set-env arc-1-lsp ARC1_SAP_HOST   <host>\ncf set-env arc-1-lsp ARC1_SAP_PORT   50001\ncf set-env arc-1-lsp ARC1_SAP_USER   <user>\ncf set-env arc-1-lsp ARC1_SAP_PASSWORD <secret>\ncf set-env arc-1-lsp ARC1_SAP_DESTINATION <id>\ncf set-env arc-1-lsp ARC1_ALLOW_WRITES true          # optional, to enable the authoring loop\ncf set-env arc-1-lsp ARC1_ALLOWED_PACKAGES '$TMP'    # scope writes\n# re-push (stop first if the org memory quota is tight — avoids a transient 2×2G):\ncf stop arc-1-lsp\nCF_DOCKER_PASSWORD=$(gh auth token) cf push arc-1-lsp -f manifest.yml\n```\n\n`cf logs` shows `engine: connected destination …`; the MCP `health` tool reports\n`connectedDestination`. `cf push` preserves `cf set-env` vars not listed in the\nmanifest. If the ghcr image is private, CF pulls it with `CF_DOCKER_PASSWORD`;\nmake the package public to drop that.\n\n## Test a running instance (local or CF)\n\nThe `/mcp` endpoint is **stateless** StreamableHTTP — a bare `tools/call` works, no\nsession handshake.\n\n```bash\nARC1_URL=https://<host>/mcp ARC1_KEY=<api-key> bash scripts/smoke-remote.sh\n# → /healthz ok · health {connectedDestination} · tools/list · list_creatable_objects\n```\n\n## Documentation\n\n| Doc | What it covers |\n|-----|----------------|\n| [`docs/adt-ls-reference.md`](docs/adt-ls-reference.md) | **The authoritative, live-verified `adt-ls` capability map** — URI model, the `getLsUri` name→URI resolver, the method/tool matrix, the object-type boundary, the proven lifecycle, session self-heal, gotchas |\n| [`docs/arc-1-feature-parity.md`](docs/arc-1-feature-parity.md) | arc-1 vs arc-1-lsp coverage, per-capability \"implemented? why / why not\" |\n| [`docs/research/adt-ls-capability-map.md`](docs/research/adt-ls-capability-map.md) | **The complete DECOMPILED `adt-ls` surface** (ground truth — CFR-decompiled `com.sap.adt.ls`): all 23 `adtLs/*` segments / ~92 methods with DTO shapes + per-capability usefulness triage + wiring gap. Corrects hover/ATC/formatting verdicts; documents the embedded MCP server's dynamic tool collection |\n| [`docs/research/whats-left-on-sap.md`](docs/research/whats-left-on-sap.md) | The earlier extension-front-end inventory (superseded in part by the capability map above) — strategic \"what's reachable-but-unwired vs blocked-on-SAP\" framing |\n| [`docs/adt-ls-headless-notes.md`](docs/adt-ls-headless-notes.md) | The reverse-engineered headless connection recipe (initialize, reentrance-ticket logon, TLS/truststore) |\n| [`docs/adr/`](docs/adr/README.md) | Architecture Decision Records — each decision, its context, and **when to revisit** it |\n| [`docs/assumptions-and-future-changes.md`](docs/assumptions-and-future-changes.md) | The watch-list: what to re-verify against new `adt-ls` releases, and what would let us delete complexity |\n| [`docs/native-deps.md`](docs/native-deps.md) | System libraries `adt-ls` needs in a slim container |\n| [`docs/journey.md`](docs/journey.md) | The chronological story, including dead-ends (so they aren't re-walked) |\n\nContributing? See [`CONTRIBUTING.md`](CONTRIBUTING.md) (setup, tests, conventions)\nand [`SECURITY.md`](SECURITY.md) (reporting vulnerabilities). Working with Claude\nCode? [`CLAUDE.md`](CLAUDE.md) is the design + codebase map. Releases are\nautomated from Conventional Commits via release-please.\n\n## Status & roadmap\n\n✅ foundation → ✅ containerize → ✅ deploy to BTP CF → ✅ headless connect\n(DIRECT) → ✅ read + authoring-loop + generation/transport tools →\n✅ session self-heal → ✅ LSP code-intelligence + ATC + coverage + run + native transport (39 tools).\n\n**Next:** CC-mode deploy (code ready; needs a running Cloud Connector + bound\n`connectivity`/`destination`), then **per-user principal propagation** (one\n`adt-ls` session per user via the BTP Destination Service). Roadmap detail in\n[`docs/plans/`](docs/plans/) and [`docs/assumptions-and-future-changes.md`](docs/assumptions-and-future-changes.md).\n\n## License & credits\n\n[MIT](LICENSE) © 2026 Marian Zeis and contributors.\n\nBuilt on the shell of **[ARC-1](https://github.com/marianfoo/arc-1)** (MIT,\n© Alice Vinogradova and contributors) — arc-1-lsp reuses its MCP server,\nconfiguration, authorization model, audit, and logging patterns. SAP's `adt-ls`\nis **not** included or redistributed (SAP Developer License) — bring your own; see\n[ADR-0002](docs/adr/0002-byo-adt-ls-no-redistribution.md).\n","readmeFilename":"README.md","_rev":"1-df0dcf8a475aca4c01884fd3a4810418"}