Docs
Everything you need to add the connector, connect an EPM environment and understand what Claude can and cannot do.
Add to Claude · Connections · Oracle SSO setup · Tools · Policies · Security · Support
Add to Claude
The connector URL is https://mcp.fmepm.com/mcp. It is the same for every surface.
claude.ai
- Open Customize, then Connectors.
- Choose Add custom connector and paste
https://mcp.fmepm.com/mcp. - Claude opens a Microsoft sign-in. Sign in with your work, school or personal Microsoft account and approve the connector.
Claude Desktop
- Open Settings, then Connectors.
- Choose Add custom connector and paste
https://mcp.fmepm.com/mcp. - Finish the Microsoft sign-in in the browser window that opens.
Claude Code
claude mcp add --transport http fmepm-connect https://mcp.fmepm.com/mcp
Then run /mcp inside Claude Code to sign in. The sign-in uses a loopback redirect, so no extra setup is needed.
After the sign-in, add a connection on the Connections page. Claude can also send you there: ask it to connect an EPM environment and it replies with the link. Claude never asks you for a password.
Connections
A connection is one EPM environment. You can keep several, for example a test pod and production, and tell Claude which one to use by label. One connection is the default.
| Type | When to use it | What I store |
|---|---|---|
| Demo | Trying the connector without an Oracle account. Mock data, no Oracle calls. | Nothing sensitive. |
| Credentials | You have an EPM username and password and your organization allows basic authentication. | Username and password, encrypted at rest. |
| Oracle SSO | Your organization uses federated sign-in or MFA for EPM, or does not allow passwords in tools. | An Oracle refresh token and access token, encrypted at rest. No password. |
Credentials: on OCI (Gen 2) pods, which have .epm. in the URL, the username is the plain username, usually your email. On classic pods it is identitydomain.username.
Oracle SSO setup (one time, by your identity domain admin)
Oracle SSO uses the OAuth 2 device code grant on your OCI IAM identity domain, the same method EPM Automate uses. Your admin registers one public OAuth client; after that every user signs in with their usual company sign-in.
- In the OCI console open Identity and Security, then Domains, and pick the identity domain that holds your EPM users.
- Note the Domain URL on the overview page. It looks like
https://idcs-xxxx.identity.oraclecloud.com. This is the identity domain URL you enter in the portal. - Open Integrated applications, choose Add application, and pick Mobile Application. This creates a public client with no secret, which is what the device code grant needs.
- Under Allowed grant types select Device code and Refresh token.
- Under Resources, add the EPM resource application for your instance and give the client the scope
urn:opc:serviceInstanceID=<id>urn:opc:resource:consumer::all. The service instance id is shown on that EPM resource application. Copy the full scope string: it is what you enter in the portal. - Activate the application and copy its Client ID.
- Make sure the users who will connect are assigned to the EPM application with a role in the identity domain, as they would be for the EPM web interface.
Then, on the Connections page, choose Oracle SSO, enter the EPM URL, the identity domain URL, the client ID and the scope, and start the sign-in. I show a short code and a link to Oracle. You sign in there, enter the code, and I save the tokens. Oracle refresh tokens expire after seven days; I renew them in the background so the connection keeps working.
Tools by plan
Every tool takes an optional connection argument (an id or label). Without it, Claude uses your default connection. Read and write actions are never in the same tool, so a read-only policy can block every write with one setting.
Connector tools Every plan
| Tool | What it does | Access |
|---|---|---|
list_connectionsList connections | Lists the Oracle EPM connections this user can use: their own and the ones shared across their tenant. Returns id, label, environment (production, test or demo), application, auth type, status and which one is the default. Use it to pick the connection argument for other tools or to check whether a connection exists before calling Oracle. | Read |
connect_epm_environmentConnect an EPM environment | Returns the link to the connect portal and the three ways to connect an Oracle EPM environment: traditional credentials, Oracle SSO, or a demo connection with sample data. Credentials are entered in the portal, not in chat; this tool takes no credentials and stores nothing. Use it when the user has no connection yet, wants another one, or needs to fix a failing one. | Read |
get_effective_policyShow effective policy | Returns the policy in force for this user and plan: allowed and denied tools, applications, environments, business rules, job types, confirmation rules, limits and time window. It is the merge of the baseline, the plan policy and the tenant policy, with the tenant's own guidance text. Use it to explain why a call was refused or to check what is allowed before proposing a change. | Read |
about_connectorAbout this connector | Returns the current plan and its limits, usage so far (this minute and today), the tools available on this plan, the connector version and the links for docs and upgrades. Use it when the user asks what the connector can do, which plan they are on, or why a tool is missing. | Read |
Core EPM tools Every plan
| Tool | What it does | Access |
|---|---|---|
get_api_versionGet API version | Returns the REST API versions the connected Oracle EPM environment supports (for example v3). Use it to confirm that a connection works before making other calls. | Read |
list_applicationsList applications | Lists the applications in the connected Oracle EPM environment with their type and settings (for example Planning, FreeForm). Use it to find the application name other tools need. | Read |
get_substitution_variablesGet substitution variables | Reads all substitution variables of an application (for example CurrMonth, CurrYear) with their values and plan type scope. These control which period, year, scenario and version the application points at. Use it before changing one or when a form or rule depends on one. | Read |
export_data_sliceExport data slice | Exports a slice of numbers from any cube of the connected application (Planning, FreeForm, NSPB, EPBCS). It reads the cube's dimensions first, puts the account dimension on rows and the period dimension on columns, maps scenario, year and entity to the cube's matching dimensions whatever they are called (Entity or Subsidiary, Year or Fiscal Year), and gives every other dimension its top member unless pov names a member for it, for example pov: { Version: "NSP_Base", Currency: "USD" }. Returns the rows as a table and as structured data, cut to the policy's cell limit with a note when that happens, and reports which member was used for each dimension. Use it to read actuals, plan or forecast numbers for analysis or commentary. | Read |
check_job_statusCheck job status | Returns the status of a job in the connected application: Processing (-1), Completed (0), Error (1), Cancelled (2), with Oracle's details text. Use it after run_business_rule or any job submission to see whether the job finished and how. | Read |
run_business_ruleRun business rule | Launches a business rule (calculation script) in the connected application and returns the job id. The rule runs in Oracle and changes data; the call returns before it finishes. Use it when the user wants a calculation, aggregation or allocation run, then follow up with check_job_status. | Write, destructive |
update_substitution_variableUpdate substitution variable | Sets a substitution variable to a new value in the connected application, for example rolling CurrMonth from Mar to Apr at month end. The change takes effect for every form, rule and report that uses the variable. Use it when the user asks to move a period, year or scenario pointer. | Write, destructive |
Pro tools Pro and Enterprise
| Tool | What it does | Access |
|---|---|---|
get_dimension_metadataGet dimension metadata | Without a dimension, lists the dimensions of an application with their types. With a dimension, returns its members with parent, alias and level (on a live pod this may run the Export Metadata job, which can take a few minutes). Use it to learn member names before exporting data, or to explain an outline. | Read |
list_formsList forms | Lists the data forms of an application with their type and, where available, the members they reference. Use it to find a form by name or to see which forms touch a member. | Read |
list_rulesList business rules | Lists the business rules of an application (rule job definitions) with, where available, the members they reference. Use it to find the exact rule name before run_business_rule. | Read |
list_job_definitionsList job definitions | Lists the job definitions of an application (export and import jobs, rules, cube refresh and so on) with their job type. Use it to find the exact job name before submitting a job with epm_rest_run_job. | Read |
export_metadataExport metadata | Exports the outline of an application through the Export Metadata job (submit, wait, download, parse) and returns member counts and a sample of names per dimension, not the raw file. Takes up to a few minutes on a live pod. Use it to size an outline or to confirm that dimensions and members exist; use get_dimension_metadata for one dimension's full member list. | Read |
download_fileDownload a file | Reads a file from the application's outbox or inbox (for example the zip an Export Data job wrote, or a dataset from a Groovy rule). Zip exports are extracted: with several files inside, the entry list comes back and entry picks one; csv and txt entries are parsed into rows and paged with offset and maxRows under the policy's cell limit. JSON files are parsed, text files are previewed and other binary files report their size only. Use it after an export job completed, or to check a Groovy rule's output. | Read |
export_dataExport data | Runs an Export Data job definition of the connected application (name from list_job_definitions) and returns the exported rows in one step: submit the job, wait for it, download the zip from the outbox, extract it and parse the csv. rowMembers, columnMembers and povMembers narrow the export the way the job definition allows. Large results are paged with offset and maxRows under the policy's cell limit, and nextOffset says where the next page starts. If the job is still running when waitSeconds is over, the result says so with the job id and file name to follow up with check_job_status and download_file. Use it to pull actuals, plan or forecast data for a whole cube region without building a grid. | Read |
get_job_detailsGet job details | Returns Oracle's detailed status record for one job, including the error and log lines it reports (GET /jobs/{jobId}/details). Use it when check_job_status shows an error and the user wants to know why. | Read |
list_rest_operationsList REST operations | Lists the Oracle EPM REST operations this connector can call, grouped into read (GET, via epm_rest_read), jobs (POST /jobs, via epm_rest_run_job) and write (PUT/POST/DELETE, via epm_rest_write), with method, path and path parameters. Use it to find the operation id and parameters before a generic REST call. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/ | Read |
epm_rest_readCall a read REST operation | Calls one GET operation of the Oracle EPM REST API by catalog id (see list_rest_operations) with path parameters and query string, and returns Oracle's JSON response. Only read operations are reachable here. Use it for reads the dedicated tools lack, such as one member, user variables, planning units or named connections. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/ | Read |
epm_rest_run_jobSubmit a job | Submits one job to an application through POST /jobs by catalog id (see list_rest_operations), for example exportData, importData, cubeRefresh or clearCube, and returns the job id to follow with check_job_status. The job type comes from the operation (or from body.jobType for executeJob); body carries jobName and parameters as Oracle documents them. Use it for job types the dedicated tools lack. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/ | Write, destructive |
epm_rest_writeCall a write REST operation | Calls one PUT, POST or DELETE operation of the Oracle EPM REST API that is not a job, by catalog id (see list_rest_operations): add a member, set or delete a substitution variable, import or clear a data slice. Only write operations are reachable here. Use it for changes the dedicated tools lack. Oracle's reference: https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/ | Write, destructive |
import_data_sliceImport data slice | Writes numbers into a cube of the connected application (POST /plantypes/{cube}/importdataslice). The body is Oracle's import shape: { aggregateEssbaseData, cellNotesOption, dateFormat, dataGrid: { pov, columns, rows } }. Use it when the user wants values loaded or corrected directly, for example a handful of plan numbers. | Write, destructive |
clear_data_sliceClear data slice | Clears a region of a cube in the connected application (POST /plantypes/{cube}/clear). The body is Oracle's clear shape, with the point of view and the members to clear. Data in the region is removed and cannot be recovered from here. Use it only when the user asks to wipe a region before a reload. | Write, destructive |
Policies
A policy is a small JSON document that says what Claude may do: which tools, which applications, which business rules, test or production, during which hours, and how many calls. I merge three layers before every call: the baseline I set and nobody can loosen, the limits of your plan, and your organization's own policy.
Presets. Pro and Enterprise admins can start from a preset such as read-only, close-operator or administrator, then edit the JSON on the Policies page.
Confirmation previews. When a write needs your confirmation, for example running a rule in production or any job type in the baseline list, Claude does not fail. It gets a preview of what would happen and is told to show it to you and ask. Only after you agree does it call again with confirm: true.
Guidance. The instructions field is free text I give to Claude as advice. The rest is enforced in code: if Claude tries something the policy forbids, the call is refused before anything reaches Oracle, and the refusal is in your audit log.
Security
- Encryption at rest. EPM passwords and Oracle tokens are encrypted with AES-256-GCM before they are stored. The key lives in Azure Key Vault, not in the database.
- No credentials in chat. Claude never sees a password or token and never asks for one. Connections are added in this portal only.
- Audit log. Every tool call, including refused ones, is recorded with the user, the tool, the connection and the outcome. Arguments are redacted. The log is kept for 90 days.
- Tokens. Claude holds a short-lived access token for the connector (one hour) and a refresh token that rotates on every use. Oracle refresh tokens are single use and rotated on every refresh.
- Sign-in. Microsoft Entra ID handles identity. I never see your Microsoft password. Portal sessions end after eight hours.
- Hosting. Azure Container Apps in Canada Central, with secrets held in Key Vault.
Found a problem? Email security@fmepm.com. I answer security reports first.
Support
Email support@fmepm.com with what you tried, the connection label and the time. I do not need your password, ever.
Service status: /health. More on the support page.