Bitrix24 MCP via Keycloak and Vault
Bitrix MCP: Keycloak identity and Vault credentials
A Streamable HTTP MCP server for Bitrix24 that checks a Keycloak token on every request and keeps portal credentials in Vault, never in the model
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Tools can read and change Bitrix24 data as the user
- The service is exposed to the internet on ports 80 and 443
- It needs Vault and Keycloak secrets with access to portal keys
Install
Manual install
Set up a Keycloak realm and Vault with an AppRole per the i1i1i1i1i1i11/mcp-bitrix README, set PUBLIC_HOST, VAULT_ROLE_ID and VAULT_SECRET_ID in the VPS .env, configure the redirect URL in the Bitrix local app, and connect the server to OpenWebUI as a Streamable HTTP MCP.
This is third-party code. Review the repository files before installing.
What it does
The server runs a Streamable HTTP MCP for Bitrix24 access from OpenWebUI and refuses Bitrix tokens from the client, tool arguments, or the model itself. Every request must carry a Keycloak access token, which the server verifies for signature, issuer, audience, and expiry via JWKS, using the verified subject as the sole user identity. Bitrix access and refresh tokens live in Vault KV v2 and are fetched via AppRole; local SQLite holds only one-time OAuth state and task-form data. The audit log records request ID, verified subject, external Bitrix user ID, called tool, and status, never secrets.
Who it is for. For teams that already run Keycloak and Vault and need auditable, identity-checked LLM access to Bitrix24 without ever handing portal tokens to the model.
Good fit when
- You already run Keycloak SSO and Vault and want an MCP on top
- You need per-call identity checks instead of one shared webhook for everyone
- Portal tokens must never enter the model's context
Not a fit when
- You have no Keycloak or Vault infrastructure and do not plan to stand one up for this
- You want a simple inbound-webhook server without a separate identity service
Example request
Show my open Bitrix24 tasks for this weekLimitations
It needs your own Keycloak realm, a Vault instance with AppRole configured at /v1/mcp/data/config/bitrix, and a public VPS with ports 80 and 443 open. The issuer, audience, and portal values in the README are for one specific deployment and must be replaced with your own. There is no license file, a single maintainer, no stars or releases, and the README cuts off mid-explanation of the OAuth callback.
How to disable. Stop the service on the VPS, remove it from OpenWebUI's integration settings, and revoke the AppRole in Vault.
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| PUBLIC_HOST required | The VPS public IP or host, without protocol or path |
| VAULT_ROLE_ID required, secret | AppRole ID for Vault access |
| VAULT_SECRET_ID required, secret | AppRole secret for Vault access |
Security check
- Tools can read and change Bitrix24 data as the user
- The service is exposed to the internet on ports 80 and 443
- It needs Vault and Keycloak secrets with access to portal keys
README in short
The README lays out the security model as a diagram: OpenWebUI sends a Keycloak token, the server verifies it and fetches Bitrix keys from Vault via AppRole. It then covers VPS port requirements, the Keycloak issuer and audience values, a Vault config example for the Bitrix local app, and the exact redirect URL to set in that app. The text cuts off while explaining that the OAuth state is server-generated and tied to the session.
FAQ
Can the model see the Bitrix token?
No. Tokens live in Vault and are fetched by the server right before a REST call; they are never returned to the model.
What if I do not have Vault?
This server will not fit: Vault-backed token storage is part of the architecture, not an option.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents