Bitrix24 MCP server with write confirmation
bitrix24-mcp-server
An MCP server for Bitrix24 CRM, tasks, projects, scrum and business processes where every write needs user confirmation, installed via uvx with no cloning
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Can create, update and delete deals, tasks and CRM records, though confirmation is on by default
- Can start and stop business processes, including deleting a process along with its data
Install
Manual install
claude mcp add bitrix24 -e BITRIX24_WEBHOOK_URL=https://your-portal.bitrix24.ru/rest/1/xxxxxxxxxxxxxxxx/ -- uvx --from git+https://github.com/a-shipilo/bitrix24-mcp-server bitrix24-mcp-serverThe direct command from the README for Claude Code.
Security check
How we reviewHigh riskWe rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
- Can create, update and delete deals, tasks and CRM records, though confirmation is on by default
- Can start and stop business processes, including deleting a process along with its data
This is third-party code. Review the repository files before installing.
What it does
The server gives access to four Bitrix24 areas through an inbound webhook: CRM on the universal crm.item API (leads, deals, contacts, companies) with search, a full card, field discovery, pipelines and comments; tasks with attachment reading, comments and checklists; projects and scrum with kanban boards, sprints and a backlog; business processes with templates, launching, a list of pending approval tasks, and delegation. Every create, update or delete is marked in the README with a confirmation icon: the server shows exactly what will change and waits for explicit approval. In clients that support elicitation this is a dialog; in others, including Claude Desktop, the tool returns a one-time confirmation_id valid for 15 minutes that must be passed to a separate confirm_action call. For unattended scenarios there is a BITRIX24_AUTO_APPROVE variable listing tools that skip confirmation, except CRM operations.
Who it is for. For teams working across Bitrix24 CRM, tasks, projects and business processes at once who want an agent that never changes anything without a person's explicit approval.
Good fit when
- You want to manage deals, tasks, project kanban and scrum sprints from a single MCP server
- You need every Bitrix24 write to require confirmation before it runs
- You need to work with business process tasks: approvals, acknowledgements, delegation
Not a fit when
- You need to create or edit business process templates: Bitrix24 itself does not allow that through a webhook
- You do not need tasks and projects, only CRM: a narrower server would fit better
Example request
Show the current sprint board in the Mobile app scrum and move deal 1542 to wonMCP
- Transport
- stdio
- Authentication
- not required
Environment variables
BITRIX24_WEBHOOK_URLrequired, secret- The Bitrix24 portal inbound webhook URL
BITRIX24_CONFIRM_MODE- Confirmation mode: auto, elicitation or token, default auto
BITRIX24_CONFIRM_TASKS- Confirmation for task and project operations, default true
BITRIX24_AUTO_APPROVE- A comma-separated list of tools that run without confirmation, except crm_*
Limitations
The repository is very new, has a single author, and no stars. Creating or editing business process templates through an inbound webhook is not possible, only through an app, and business process methods require portal admin rights. Choosing Always allow for the confirm_action prompt in Claude Desktop disables the protection against accidental writes, which the README calls out explicitly.
How to disable. Remove the bitrix24 entry from your Claude Desktop or Claude Code mcpServers configuration.
FAQ
How does confirmation work in Claude Desktop, which lacks elicitation support?
The tool returns a confirmation_id, Claude Desktop shows the operation description, and the write only runs after a separate confirm_action call with that id within 15 minutes.
Can confirmation be disabled for CRM?
No, crm_* tools listed in BITRIX24_AUTO_APPROVE are ignored; CRM confirmation cannot be turned off.
Related
MCP serversSalesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail
README in short
The README describes four tool groups in tables with a confirmation mark on every write operation, the confirmation mechanics for clients with and without elicitation, webhook permission setup by Bitrix24 section, the BITRIX24_CONFIRM_MODE, BITRIX24_CONFIRM_TASKS and BITRIX24_AUTO_APPROVE environment variables for unattended scenarios, example Russian-language requests, and development instructions using ruff and pytest. MIT license, with CI configured in the repository.