FMEPM Connect

Docs

Everything you need to add the connector, connect an EPM environment and understand what Claude can and cannot do.

Add to Claude · Connections · Oracle SSO setup · Tools · Policies · Security · Support

Add to Claude

The connector URL is https://mcp.fmepm.com/mcp. It is the same for every surface.

claude.ai

  1. Open Customize, then Connectors.
  2. Choose Add custom connector and paste https://mcp.fmepm.com/mcp.
  3. Claude opens a Microsoft sign-in. Sign in with your work, school or personal Microsoft account and approve the connector.

Claude Desktop

  1. Open Settings, then Connectors.
  2. Choose Add custom connector and paste https://mcp.fmepm.com/mcp.
  3. Finish the Microsoft sign-in in the browser window that opens.

Claude Code

claude mcp add --transport http fmepm-connect https://mcp.fmepm.com/mcp

Then run /mcp inside Claude Code to sign in. The sign-in uses a loopback redirect, so no extra setup is needed.

After the sign-in, add a connection on the Connections page. Claude can also send you there: ask it to connect an EPM environment and it replies with the link. Claude never asks you for a password.

Connections

A connection is one EPM environment. You can keep several, for example a test pod and production, and tell Claude which one to use by label. One connection is the default.

TypeWhen to use itWhat I store
DemoTrying the connector without an Oracle account. Mock data, no Oracle calls.Nothing sensitive.
CredentialsYou have an EPM username and password and your organization allows basic authentication.Username and password, encrypted at rest.
Oracle SSOYour organization uses federated sign-in or MFA for EPM, or does not allow passwords in tools.An Oracle refresh token and access token, encrypted at rest. No password.

Credentials: on OCI (Gen 2) pods, which have .epm. in the URL, the username is the plain username, usually your email. On classic pods it is identitydomain.username.

Oracle SSO setup (one time, by your identity domain admin)

Oracle SSO uses the OAuth 2 device code grant on your OCI IAM identity domain, the same method EPM Automate uses. Your admin registers one public OAuth client; after that every user signs in with their usual company sign-in.

  1. In the OCI console open Identity and Security, then Domains, and pick the identity domain that holds your EPM users.
  2. Note the Domain URL on the overview page. It looks like https://idcs-xxxx.identity.oraclecloud.com. This is the identity domain URL you enter in the portal.
  3. Open Integrated applications, choose Add application, and pick Mobile Application. This creates a public client with no secret, which is what the device code grant needs.
  4. Under Allowed grant types select Device code and Refresh token.
  5. Under Resources, add the EPM resource application for your instance and give the client the scope urn:opc:serviceInstanceID=<id>urn:opc:resource:consumer::all. The service instance id is shown on that EPM resource application. Copy the full scope string: it is what you enter in the portal.
  6. Activate the application and copy its Client ID.
  7. Make sure the users who will connect are assigned to the EPM application with a role in the identity domain, as they would be for the EPM web interface.

Then, on the Connections page, choose Oracle SSO, enter the EPM URL, the identity domain URL, the client ID and the scope, and start the sign-in. I show a short code and a link to Oracle. You sign in there, enter the code, and I save the tokens. Oracle refresh tokens expire after seven days; I renew them in the background so the connection keeps working.

Tools by plan

Every tool takes an optional connection argument (an id or label). Without it, Claude uses your default connection. Read and write actions are never in the same tool, so a read-only policy can block every write with one setting.

Connector tools Every plan

ToolWhat it doesAccess
list_connections
List connections
Lists the Oracle EPM connections this user can use: their own and the ones shared across their tenant. Returns id, label, environment (production, test or demo), application, auth type, status and which one is the default. Use it to pick the connection argument for other tools or to check whether a connection exists before calling Oracle.Read
connect_epm_environment
Connect an EPM environment
Returns the link to the connect portal and the three ways to connect an Oracle EPM environment: traditional credentials, Oracle SSO, or a demo connection with sample data. Credentials are entered in the portal, not in chat; this tool takes no credentials and stores nothing. Use it when the user has no connection yet, wants another one, or needs to fix a failing one.Read
get_effective_policy
Show effective policy
Returns the policy in force for this user and plan: allowed and denied tools, applications, environments, business rules, job types, confirmation rules, limits and time window. It is the merge of the baseline, the plan policy and the tenant policy, with the tenant's own guidance text. Use it to explain why a call was refused or to check what is allowed before proposing a change.Read
about_connector
About this connector
Returns the current plan and its limits, usage so far (this minute and today), the tools available on this plan, the connector version and the links for docs and upgrades. Use it when the user asks what the connector can do, which plan they are on, or why a tool is missing.Read

Core EPM tools Every plan

ToolWhat it doesAccess
get_api_version
Get API version
Returns the REST API versions the connected Oracle EPM environment supports (for example v3). Use it to confirm that a connection works before making other calls.Read
list_applications
List applications
Lists the applications in the connected Oracle EPM environment with their type and settings (for example Planning, FreeForm). Use it to find the application name other tools need.Read
get_substitution_variables
Get substitution variables
Reads all substitution variables of an application (for example CurrMonth, CurrYear) with their values and plan type scope. These control which period, year, scenario and version the application points at. Use it before changing one or when a form or rule depends on one.Read
export_data_slice
Export data slice
Exports a slice of numbers from any cube of the connected application (Planning, FreeForm, NSPB, EPBCS). It reads the cube's dimensions first, puts the account dimension on rows and the period dimension on columns, maps scenario, year and entity to the cube's matching dimensions whatever they are called (Entity or Subsidiary, Year or Fiscal Year), and gives every other dimension its top member unless pov names a member for it, for example pov: { Version: "NSP_Base", Currency: "USD" }. Returns the rows as a table and as structured data, cut to the policy's cell limit with a note when that happens, and reports which member was used for each dimension. Use it to read actuals, plan or forecast numbers for analysis or commentary.Read
check_job_status
Check job status
Returns the status of a job in the connected application: Processing (-1), Completed (0), Error (1), Cancelled (2), with Oracle's details text. Use it after run_business_rule or any job submission to see whether the job finished and how.Read
run_business_rule
Run business rule
Launches a business rule (calculation script) in the connected application and returns the job id. The rule runs in Oracle and changes data; the call returns before it finishes. Use it when the user wants a calculation, aggregation or allocation run, then follow up with check_job_status.Write, destructive
update_substitution_variable
Update substitution variable
Sets a substitution variable to a new value in the connected application, for example rolling CurrMonth from Mar to Apr at month end. The change takes effect for every form, rule and report that uses the variable. Use it when the user asks to move a period, year or scenario pointer.Write, destructive

Pro tools Pro and Enterprise

ToolWhat it doesAccess
get_dimension_metadata
Get dimension metadata
Without a dimension, lists the dimensions of an application with their types. With a dimension, returns its members with parent, alias and level (on a live pod this may run the Export Metadata job, which can take a few minutes). Use it to learn member names before exporting data, or to explain an outline.Read
list_forms
List forms
Lists the data forms of an application with their type and, where available, the members they reference. Use it to find a form by name or to see which forms touch a member.Read
list_rules
List business rules
Lists the business rules of an application (rule job definitions) with, where available, the members they reference. Use it to find the exact rule name before run_business_rule.Read
list_job_definitions
List job definitions
Lists the job definitions of an application (export and import jobs, rules, cube refresh and so on) with their job type. Use it to find the exact job name before submitting a job with epm_rest_run_job.Read
export_metadata
Export metadata
Exports the outline of an application through the Export Metadata job (submit, wait, download, parse) and returns member counts and a sample of names per dimension, not the raw file. Takes up to a few minutes on a live pod. Use it to size an outline or to confirm that dimensions and members exist; use get_dimension_metadata for one dimension's full member list.Read
download_file
Download a file
Reads a file from the application's outbox or inbox (for example the zip an Export Data job wrote, or a dataset from a Groovy rule). Zip exports are extracted: with several files inside, the entry list comes back and entry picks one; csv and txt entries are parsed into rows and paged with offset and maxRows under the policy's cell limit. JSON files are parsed, text files are previewed and other binary files report their size only. Use it after an export job completed, or to check a Groovy rule's output.Read
export_data
Export data
Runs an Export Data job definition of the connected application (name from list_job_definitions) and returns the exported rows in one step: submit the job, wait for it, download the zip from the outbox, extract it and parse the csv. rowMembers, columnMembers and povMembers narrow the export the way the job definition allows. Large results are paged with offset and maxRows under the policy's cell limit, and nextOffset says where the next page starts. If the job is still running when waitSeconds is over, the result says so with the job id and file name to follow up with check_job_status and download_file. Use it to pull actuals, plan or forecast data for a whole cube region without building a grid.Read
get_job_details
Get job details
Returns Oracle's detailed status record for one job, including the error and log lines it reports (GET /jobs/{jobId}/details). Use it when check_job_status shows an error and the user wants to know why.Read
list_rest_operations
List REST operations
Lists the Oracle EPM REST operations this connector can call, grouped into read (GET, via epm_rest_read), jobs (POST /jobs, via epm_rest_run_job) and write (PUT/POST/DELETE, via epm_rest_write), with method, path and path parameters. Use it to find the operation id and parameters before a generic REST call. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/Read
epm_rest_read
Call a read REST operation
Calls one GET operation of the Oracle EPM REST API by catalog id (see list_rest_operations) with path parameters and query string, and returns Oracle's JSON response. Only read operations are reachable here. Use it for reads the dedicated tools lack, such as one member, user variables, planning units or named connections. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/Read
epm_rest_run_job
Submit a job
Submits one job to an application through POST /jobs by catalog id (see list_rest_operations), for example exportData, importData, cubeRefresh or clearCube, and returns the job id to follow with check_job_status. The job type comes from the operation (or from body.jobType for executeJob); body carries jobName and parameters as Oracle documents them. Use it for job types the dedicated tools lack. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/Write, destructive
epm_rest_write
Call a write REST operation
Calls one PUT, POST or DELETE operation of the Oracle EPM REST API that is not a job, by catalog id (see list_rest_operations): add a member, set or delete a substitution variable, import or clear a data slice. Only write operations are reachable here. Use it for changes the dedicated tools lack. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/Write, destructive
import_data_slice
Import data slice
Writes numbers into a cube of the connected application (POST /plantypes/{cube}/importdataslice). The body is Oracle's import shape: { aggregateEssbaseData, cellNotesOption, dateFormat, dataGrid: { pov, columns, rows } }. Use it when the user wants values loaded or corrected directly, for example a handful of plan numbers.Write, destructive
clear_data_slice
Clear data slice
Clears a region of a cube in the connected application (POST /plantypes/{cube}/clear). The body is Oracle's clear shape, with the point of view and the members to clear. Data in the region is removed and cannot be recovered from here. Use it only when the user asks to wipe a region before a reload.Write, destructive

Policies

A policy is a small JSON document that says what Claude may do: which tools, which applications, which business rules, test or production, during which hours, and how many calls. I merge three layers before every call: the baseline I set and nobody can loosen, the limits of your plan, and your organization's own policy.

Presets. Pro and Enterprise admins can start from a preset such as read-only, close-operator or administrator, then edit the JSON on the Policies page.

Confirmation previews. When a write needs your confirmation, for example running a rule in production or any job type in the baseline list, Claude does not fail. It gets a preview of what would happen and is told to show it to you and ask. Only after you agree does it call again with confirm: true.

Guidance. The instructions field is free text I give to Claude as advice. The rest is enforced in code: if Claude tries something the policy forbids, the call is refused before anything reaches Oracle, and the refusal is in your audit log.

Security

Found a problem? Email security@fmepm.com. I answer security reports first.

Support

Email support@fmepm.com with what you tried, the connection label and the time. I do not need your password, ever.

Service status: /health. More on the support page.