AshybulakStroy MCP 1C Bridge
A policy-gated read-only MCP server for 1C Accounting for Kazakhstan data via OData: stock, payments, receivables
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads financial data: payments, stock and counterparties' receivables
- Recommends but does not technically enforce a separate read-only 1C OData user
Install
Manual install
python -m venv .venv && pip install -e . && cp .env.example .envInstall dependencies and prepare .env with the OData endpoint.
This is third-party code. Review the repository files before installing.
What it does
The server talks to published OData entities of 1C Accounting for Kazakhstan 3.0 and gives the agent read-only tools: metadata search and description, stock and low-stock items, incoming and outgoing payment reports, top customers and suppliers, overdue debtors, and reconciliation of the fetched data against the text of an official 1C report. Every tool call goes through a policy decision engine from config/policy.yaml: unknown and forbidden tools are blocked, risk levels L3 and L4 are always blocked, and every call is written to an audit/audit.jsonl log.
Who it is for. For accountants and business owners on 1C Accounting for Kazakhstan who need a safe read-only report on stock and money through an agent.
Good fit when
- You want to ask the agent who was paid or who has not paid an invoice, for a period
- You need to check stock without manually building a report
- You need a transparent access policy with a log of every call
Not a fit when
- You need to post or change a document: the server only reads data
- You need standard Russian 1C Accounting without the Kazakhstan adaptation
Example request
Show who has not paid an invoice within 3 days, and the top customers by incoming payments for AprilLimitations
Built for 1C Accounting for Kazakhstan 3.0 and its standard OData interface; there is no separate adapter for the Russian edition. Stock and money reports are built by OData heuristics and should be checked against official 1C reports. Overdue and typical payment terms use a managerial FIFO method, not an official accounting register. The project carries a lot of internal development documentation, a sign of an early, not fully settled state.
How to disable. Remove the ashybulakstroy-1c server from your MCP client configuration and stop the process.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| ONEC_ODATA_URL required | OData endpoint of 1C Accounting for Kazakhstan. |
| ONEC_USERNAME required | 1C OData user, ideally with a read-only role. |
| ONEC_PASSWORD required, secret | Password of the OData user. |
Security check
- Reads financial data: payments, stock and counterparties' receivables
- Recommends but does not technically enforce a separate read-only 1C OData user
README in short
The README describes the product's role as a read-only Secure Mode bridge to 1C Accounting for Kazakhstan, explains an L0-L4 risk model, a capability registry, the policy format in config/policy.yaml, an append-only audit log, and an output filter that masks IIN and bank account numbers. It lists money scenarios for payments and receivables, and reconciliation of stock against the text of an official 1C report.
FAQ
Can the server post or delete a document?
No, all write and posting operations are forbidden by policy at the Phase 1 Secure MVP level, including post_document_validated.
What does Secure Mode do in practice?
Every tool call is checked against an allowlist and risk level in policy.yaml, unknown calls are denied, and the result passes an output filter before returning to the agent.
Related
A set of investment research skills for Claude Code and Codex built on four investors' methodologies. It is a research tool, not investment advice
Stripe's official MCP server, plugins and skills: the agent searches the API and docs, reads and changes account data
Alpaca's official MCP server: orders for stocks, ETFs, crypto and options, position management and market data in plain language
inn-check-ru: counterparty risk traffic light
inn-check-ru
An open-source skill that checks a Russian company by tax ID across EGRUL, bailiffs, courts, bankruptcy and sanctions, and returns a dated risk verdict