For pharma and biotech manufacturers running PAS-X

A read-only PAS-X MCP server for batches and exceptions that supports decisions and never signs

A PAS-X MCP server gives Claude, ChatGPT or Copilot read-only tools for batch status, open process exceptions, process orders and material consumption. The read source is PAS-X Data Access, a separately licensed SQL store. Körber ships no MCP server as of 21 September 2026, so Pexon builds one as non-GMP decision support.

Why PAS-X is hard for agents

Where a PAS-X connection needs engineering, not configuration

01 · GMP

Decision support, not a GMP record

Any tool that reads batch records has to be validated or clearly positioned as non-GMP decision support. The connector is the second: it answers questions, and the batch record in PAS-X stays the record of truth. Writes into the EBR are out of scope.

02 · Licensing

The safe read path is a paid add-on

Körber publishes no API reference. PAS-X Data Access is licensed separately and needs PAS-X MES 3.3.x or 3.4.x, so the first question in the blueprint is whether you have it or want it.

03 · Versions

Every site has its own master batch records

The installed base spans PAS-X 3.1.8 to 3.4.x, with customer-specific master batch records. Tools are mapped to your version and your recipes, not to a generic PAS-X model.

04 · Data integrity

Every question is part of the audit trail

ALCOA+ requirements mean the MCP server logs every query and every answer with user and time. The log is designed with your QA team before go-live, not added afterwards.

Checked 21 September 2026

PAS-X at a glance: interfaces, access and what exists for AI

What we found
InterfacesPAS-X Data Access (SQL, docs behind customer or partner login): separately licensed; qualified change-data-capture replication into a dedicated store, version-stable across PAS-X MES 3.3.x and 3.4.x · PAS-X MSI (Message-based Shopfloor Integration) (SOAP web services, docs behind customer or partner login): equipment integration adapter, not built for business queries; the connector does not use it
AuthenticationNot documented publicly. Read access to the Data Access store is set up with your PAS-X and validation teams in the blueprint.
Vendor MCP serverNo vendor server. No Körber MCP server for PAS-X found; the vendor's AI product PAS-X K.AI is a documentation chatbot.
Vendor AI assistantPAS-X K.AI, a web-based chatbot that researches PAS-X documentation for PAS-X MES 3.1.8 and later, Data Access, Track & Trace and PAS-X2X.
Other connectorsHighByte documents an MSI integration for equipment data through web services; it is not an AI connector.

Körber, Business Area Pharma (formerly Werum IT Solutions) (DE). Pharma, biotech and cell and gene therapy manufacturers running GMP electronic batch records; Körber states PAS-X is used by more than 50 percent of the top 30 pharma companies.

What we build

A first PAS-X tool list, written as the manifest your IT team signs

Built on what Körber, Business Area Pharma (formerly Werum IT Solutions) documents: batches and electronic batch records, process orders, materials, process exceptions, weighing and dispensing records, equipment status and cleaning, KPI and OEE, serialisation data. Backends named below are documented resources; "confirmed in blueprint" means the vendor documentation sits behind a login and the resource is checked against your release first.

# pas-x-mcp-server: tool manifest, draft for blueprint week 1
# Every tool runs as the person asking. Nothing is written without a person confirming.
tools:
  list_open_exceptions:     # product or site, date range -> batches with open exceptions and category
    backend: PAS-X Data Access, SQL views confirmed in blueprint
    mode: read
  get_batch_status:         # batch id -> order, status, current step, review state
    backend: PAS-X Data Access, resource confirmed in blueprint
    mode: read
  get_material_consumption: # batch id -> consumed material lots and quantities
    backend: PAS-X Data Access, resource confirmed in blueprint
    mode: read
  get_order_list:           # site, date range -> process orders with status
    backend: PAS-X Data Access, resource confirmed in blueprint
    mode: read
audit: every call logged with user, tool, arguments and the PAS-X response

The manifest is the contract. A question that needs an operation not on it gets a new line and a review, not a wider permission.

PAS-X holds the records. An assistant without a governed way in answers from whatever someone pasted into the chat. The connector is the governed way in: named operations, the person's own permissions, every call logged.

What the connector answers, and what it will not do

Questions it answers

  • Which batches of product X have open process exceptions this week?
  • What is the status of process order 100234, and which steps are still open?
  • Which material lots were consumed in batch B123?

What it will not do

  • Write to PAS-X or sign anything: the connector is read-only, proposes nothing into the EBR and never replaces a GMP signature.
  • Read more than the asking user may read; access to the Data Access store is scoped per role and tested with two users before go-live.
  • Count as a validated GMP system: answers are decision support until your validation team says otherwise.

When this is the wrong page

If the question is how PAS-X works or where a setting lives, PAS-X K.AI answers it from Körber's documentation. If you need validated GMP reporting, that belongs in a qualified reporting layer on Data Access; a connector is right for ad hoc questions from Claude, ChatGPT or Copilot as decision support.

Start with the Readiness Blueprint.

Two weeks, €4,900 fixed price. Week one agrees the tool list with your PAS-X owners and checks every backend against your release and licence. Week two tests whether a person's own PAS-X permissions reach through the connector. You keep the manifest and a costed build plan, whoever builds it. All prices are net and exclude VAT.

What we need from you: a named PAS-X administrator, a test or sandbox system we may call, and one business owner who can say which questions the assistant should answer first. The first production connector is usually a use-case pilot from €15,000; it runs in your environment, and the code is yours.

Sources: PAS-X MES Suite · PAS-X Data Access · PAS-X K.AI · PAS-X MES 3.4 press release · HighByte: PAS-X MSI. Read 21 September 2026. Vendor documentation changes; verify against the current release.

Related

Questions PAS-X teams ask before the first tool call

Does PAS-X have its own MCP server?

Not as of 21 September 2026. Körber's AI product PAS-X K.AI is a chatbot over PAS-X documentation, not over your batch data. An MCP server for Claude, ChatGPT or Copilot has to be built against PAS-X Data Access.

Do we need extra Körber licences or access for an AI connector?

Usually yes. PAS-X Data Access, the safe read path, is licensed separately and needs PAS-X MES 3.3.x or 3.4.x. Check your licence with Körber before the build; the blueprint starts with that question.

Can the assistant see data a user is not allowed to see in PAS-X?

No. Access to the Data Access store is scoped per role, and each person only gets the scope their role allows. Every query and answer is logged with user and time, and two users are tested against each other before go-live.

What does a PAS-X connector cost?

The two-week Readiness Blueprint is fixed at €4,900: agreed tool list, backends checked against your release, identity tested end to end, costed build plan. The production connector is usually a use-case pilot from €15,000. Prices are net, excluding VAT.

Next step

Not a sales call. An architecture call.

Thirty minutes with the engineer who would build the connector, with your PAS-X administrator in the room if you like.