BW Automation MCP tools
Local-only
bw_studio_status,bw_studio_deploy,bw_studio_launch,bw_studio_rollback,bw_studio_diagnosticsbw_connection_prepare,bw_connection_import_landscape,bw_connection_statusbw_project_create_or_openbw_resolve_and_validate_spec— with the optionalaliasinput it fetches provider metadata through the read-onlydescribeProviderbridge call and verifies every referenced characteristic/key figure; the result carriesmetadataCheckedandreadyForDraft. A valid spec additionally carries abestPracticesarray of design-rule findings (BWQ001–BWQ012) from the shared rule engine (query-rules.mjs); the array is empty when the spec is invalid, and no existing result keys changebw_create_local_draft,bw_apply_spec_to_draft,bw_preview_draftbw_populate_query_editor— builds the confirmed draft inside the wizard-created, still-unsaved query editor. Requires a prior prepared save (SAVE_PENDING_HUMAN). Mutates only the local editor buffer, refuses editors with existing content, returns a per-elementapplyReport, and always returnssaved: false— the human saves. On a successful population it automatically deep-reads the editor model through the read-onlyreadQueryModelbridge call and merges a non-fatalverificationsummary (statusofVERIFIED,DIVERGED, orUNAVAILABLE, plus per-elementchecksandcounts) that compares the confirmed spec against the live model; the read failing never fails the populate.
Read-only tenant
bw_connection_test_reachability— network only, unauthenticatedbw_inspect_capabilities— includes theproviderMetadataSupported,populateSupported, andmodelReadSupportedgates with per-feature diagnosticsbw_describe_provider— besides open-editor summaries, returnsmetadata(characteristics with dimension groups, key figures, dimensions) via the capability-gated BWMT connectivity services; offline or unauthenticated sessions yieldmetadata.available: falsewith an instructionbw_list_queriesbw_read_querybw_read_query_model— serializes the complete EMF model of an open, name-matching query to the deep-read JSON contract (axes; structures with members; selection groups and tokens; filter, condition, and exception selections; display settings) with aserializationIssueslist. Capability-gated behindmodelReadSupported, strictly read-only (no editing domain, no save), and returnsfound: falsewith an instruction when the query is not open in BW Query Designer.bw_review_query— best-practices review of an OPEN query. Reuses the read-onlyreadQueryModelbridge call (no new bridge method), normalizes the deep model, and runs the shared rule engine (query-rules.mjs). Returnsfound,technicalName,provider,findings(each withruleId,severity,path,message,rationale),serializationIssues, andreadOnly: true; returnsfound: falsewith the deep-read instruction when the query is not open. Never mutates or saves.
Mutating tenant classification
bw_prepare_new_query_save— explicit approval required. This checks collision information, binds the specification hash, and schedules Eclipse confirmation. It does not perform the final save.
All input schemas use additionalProperties: false. The server returns generic errors and keeps request bodies out of logs. Password detection uses the mandatory rotation warning.
Credentials, tokens, and secrets are never accepted. Live tenant access is limited to the classified read-only tools; the only tenant-affecting preparation tool requires explicit approval and still cannot perform the final save.
There are no destructive operations and no delete, remove, drop, overwrite, cleanup, uninstall, transport, raw-command, or final-save tools.
Sources
- The authoritative surface is generated from
mcp/src/tool-registry.mjsand checked against the enterprise MCP inventory by the repository validation suite.