> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.basement.chat/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.basement.chat/_mcp/server.

# SAP with Basement Gateway

## How it works

There are four parts. You use only the first part.

```text
 your computer                      cloud (Basement)                      customer
┌───────────────────┐   encrypted       ┌──────────────┐   signed    ┌──────────────┐
│ Basement Gateway  │◄════════════════►│ SAP server   │◄───────────│ Gateway      │◄──── Claude / ChatGPT /
│ app + the         │   channel (relay)│ (reads SAP   │  requests   │ (sign-in,    │      Claude Code
│ customer's VPN    │                  │  with YOUR   │            │  MCP, access)│
└─────────┬─────────┘                  │  user)       │            └──────────────┘
          │ VPN                        └──────────────┘
          ▼
   ┌─────────────┐
   │ customer's  │
   │ SAP         │
   └─────────────┘
```

1. **You** sign in to the app with your e-mail. The app shows the VPN. You create the connection with the data of the system and your SAP user.
2. **The app** registers your computer with the Gateway. The app gives the network path: all data to SAP goes through your computer and the VPN of the customer. This is the same path that SAP GUI uses.
3. **The SAP server** is in our cloud. It opens the SAP session with **your** user and reads what the AI asked for. Only the SAP server can open your password.
4. **The Gateway** is the door for the AI. Claude, ChatGPT or Claude Code sign in with your login and ask for a read. The Gateway checks the permission, sends the read to the SAP server and returns the answer.

## What must stay on

The AI can read SAP only when these three conditions are true at the same time:

* Your computer is on.
* The app is open.
* The VPN of the customer is connected.

Your computer is the only part inside the network of the customer. Without it, there is no path.

| Condition                                       | What the AI gets                                                 | When it works again                                            |
| ----------------------------------------------- | ---------------------------------------------------------------- | -------------------------------------------------------------- |
| You close the app, or you turn off the computer | "The analyst's computer that carries the connection is offline"  | When you open the app again. The app connects again by itself. |
| The VPN disconnects                             | "The VPN is disconnected on this computer"                       | When the VPN connects again. The app sees it and shows it.     |
| SAP refuses the logon                           | The exact cause (language, locked user, password) and what to do | When you correct it under **Reconnect…**                       |

The connection is not lost in these conditions. The app keeps it and uses it again by itself. The app does not keep the password in clear text. If SAP refuses the password, the app asks for it again.

## Where the data is

| Data                                        | Where                                                                     | Who can see it                                                     |
| ------------------------------------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------ |
| The data of the system (SID, host, address) | In the Gateway, in your organization                                      | You and the administrators of the organization                     |
| Your SAP user and password                  | Sealed in the app for the key of the SAP server, stored in the Gateway    | Only the SAP server, in memory, at the SAP logon                   |
| What the AI read                            | Goes from SAP to the server, to the Gateway, to the AI. It is not stored. | The conversation with the AI                                       |
| The activity log                            | In the Gateway                                                            | The tool, the system and the result. Never the data that was read. |

## What you need

|                              |                                                                                                                                        |
| ---------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| **An invitation**            | A member of your organization invites your e-mail to the Gateway. Without an invitation, you cannot sign in to the app or to the site. |
| **The Basement Gateway app** | On your computer (Mac, Windows or Linux). See [Install and sign in](/sap/install).                                                     |
| **The VPN of the customer**  | The VPN client that you use today for that SAP (for example FortiClient), connected.                                                   |
| **Your SAP user**            | The user and the password that you use in SAP GUI for that customer.                                                                   |

> **Note**
>
> The Gateway only reads. No tool creates, changes, activates, runs or deletes data in SAP. The Gateway never reads tables with passwords, keys or personal data (USR\*, USH\*, RFCDES, PA\*).

## Step by step

### Install the app and sign in

Download the app. Open it. Sign in with the invited e-mail and the code. See [Install and sign in](/sap/install).

### Connect the VPN

Connect the VPN of the customer. The card at the top of **Connections** shows "connected".

### Create the connection

Click **New connection…**. Enter the data of the system as in SAP Logon. Set the logon language to **EN**. Enter your SAP user and password. Click **Create and connect**. The app shows the result for each method. See [Connect a SAP system](/sap/connect).

### Connect Claude

In Claude, add the connector `https://mcp.basement.chat/mcp`. Sign in with the same e-mail. On the approval, select the organization and an access level with SAP read. See [Use it with Claude](/sap/claude).

SAP is only for AI agents through MCP. The HTTP API and the SDKs do not offer SAP. A SAP system is reached only through the app on the computer of an analyst, with the VPN of the customer. A program has no such path.

### Ask a question

For example: "Which dumps occurred today on SBX?". Keep the app open.

![The Connections screen of the app, with the VPN detected and an SBX system connected](/_fern-img/81b5f35f7640a9c6deefd7ceff15235e299134b375824c6f92c29572d2b18acf.webp)