1C Base MCP

An MCP server for a test 1C base via V83.COMConnector with an HTTP transport, an access token and a switchable read-only mode

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • create_document and execute_code can write to the base and run arbitrary code once MCP_READONLY is turned off
  • Access is protected by a single token; network isolation is the user's responsibility
All reasons and checks
Russian stack

testovmax/1c-base-mcp

Install

Manual install

python -m pip install -r requirements-server.txt

Installs server dependencies on the machine running 1C.

This is third-party code. Review the repository files before installing.

What it does

The server runs alongside 1C on Windows, opens a COM connection and publishes tools over Streamable HTTP: list_metadata, describe_object, run_query for reads, count_data for counting, plus create_element, create_document and execute_code for writes and arbitrary code through an external runner.epf processing object. The write tools and execute_code are blocked while MCP_READONLY is set to true, the default. A local Python bridge, mcp_bridge.py, lets stdio clients connect to the HTTP server via a token, and access can be restricted to a list of allowed IP prefixes.

Who it is for. For 1C developers who need networked MCP access to an isolated test or demo base with controllable write access.

Good fit when

  • You need networked agent access to a test 1C base from several machines
  • You need a controllable write mode, enabled only for the duration of a task
  • You need object counts and structure without manually opening the designer

Not a fit when

  • You need to work with a production base: the project is explicitly for an isolated demo or test base only
  • You need access without Windows: the server side requires COM and 1C:Enterprise 8.3 on Windows

Example request

Count the elements in the Counterparties catalog and show the structure of the РеализацияТоваровУслуг document

Limitations

The author states plainly: the project is intended only for an isolated demo or test base. Write tools and execute_code are off by default but flip on with a single environment variable, so operational discipline is entirely up to the user. The ?token= parameter is supported only for compatibility and may end up in logs or history.

How to disable. Stop the mcp_base_server.py process and remove the server from your stdio client configuration.

MCP

Transport
http, stdio
Authentication
API key
Environment variables
Environment variables
ONEC_SRVR
required
Cluster server of the test 1C base.
MCP_AUTH_TOKEN
required, secret
Access token for the HTTP server.
MCP_READONLY
Blocks writes and execute_code, defaults to true.

Security check

  • create_document and execute_code can write to the base and run arbitrary code once MCP_READONLY is turned off
  • Access is protected by a single token; network isolation is the user's responsibility

README in short

The README warns upfront that the project is only for an isolated demo or test base, describes the client-bridge-server-COM architecture, a list of environment variables for the 1C connection and security settings, server and client setup steps, an MCP handshake check script check_mcp_base.py, and a security section with recommendations on tokens, firewalling and IP restriction.

FAQ

How do you enable data writes?

Explicitly set the MCP_READONLY environment variable to false; it defaults to true and blocks writes and execute_code.

How do you restrict network access?

With the MCP_ALLOWED_IP_PREFIXES variable listing allowed IP prefixes, plus the mandatory MCP_AUTH_TOKEN.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium risk292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium risk139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AI1C Base MCP

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.