MCP for Bitrix infoblocks and highload blocks
Bitrix MCP Server
A PHP script inside a Bitrix site: an HTTP MCP server for reading and writing infoblock and highload-block data, with a whitelist and an audit log
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- It can create, update and delete infoblock elements and highload-block records
- It runs as a Bitrix service user; access is limited only by the whitelist and a Bearer token
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/bitrix-mcp-serverDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport http bitrix-data https://staging.example.com/local/bitrix-mcp-server/public/ --header 'Authorization: Bearer <your AUTHORIZATION>'Or add to the file .mcp.json, in the project
{
"mcpServers": {
"bitrix-data": {
"type": "http",
"url": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"bitrix-data": {
"url": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"bitrix-data","type":"http","url":"https://staging.example.com/local/bitrix-mcp-server/public/","headers":{"Authorization":"Bearer <your AUTHORIZATION>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"bitrix-data": {
"type": "http",
"url": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.codex/config.toml, for all projects
[mcp_servers.bitrix-data]
url = "https://staging.example.com/local/bitrix-mcp-server/public/"
http_headers = { Authorization = "Bearer <your AUTHORIZATION>" }If the file already exists, append the block to the end.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"bitrix-data": {
"httpUrl": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"bitrix-data": {
"serverUrl": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"bitrix-data": {
"type": "streamableHttp",
"url": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"bitrix-data": {
"type": "streamable-http",
"url": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"bitrix-data": {
"type": "remote",
"url": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"bitrix-data": {
"url": "https://staging.example.com/local/bitrix-mcp-server/public/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Clone the repository into local/bitrix-mcp-server on the Bitrix site, run composer install --no-dev, copy config.sample.php to config.php with a token and ID whitelist, create writable logs and sessions folders, then connect an MCP client to the URL with an Authorization: Bearer header.
Other ways from the author
cd /var/www/site/local && git clone https://github.com/dimabresky/bitrix-mcp-server.git bitrix-mcp-server && cd bitrix-mcp-server && composer install --no-devInstall directly into the Bitrix site's local/.
This is third-party code. Review the repository files before installing.
What it does
The server lives right inside a Bitrix site as a plain PHP script under local/, boots through prolog_before.php, and works only over HTTP with the Streamable HTTP transport, with no stdio or SSH tunnel. Its tools read infoblock and highload-block schemas, list sections and elements, read an element card respecting the smart filter, create and update records, and delete them only with explicit confirmation. Access is limited to a whitelist of infoblock and HL-block IDs from config.php, every call is logged to an audit file, and operations run as a Bitrix service user through the standard $USER->Authorize().
Who it is for. For Bitrix developers who need scoped, auditable agent access to catalog and highload-reference data.
Good fit when
- You need access to specific infoblocks or highload-blocks by a whitelist, not the whole portal
- You need an audit trail of every agent call to site data
- It is more convenient to keep the MCP server right on the Bitrix site rather than run a separate process
Not a fit when
- You need tasks, CRM or messenger access: the server only covers infoblocks and highload-blocks
- You cannot place PHP files under the site's local/ and expose an HTTPS-reachable path
Example request
Find element 2449677 in infoblock 16 and show all its properties, not just the smart filterLimitations
Managing property definitions (CIBlockProperty, enum values) and file properties is not supported, only values on elements. The legacy server.php and stdio mode has been fully removed. It requires PHP 8.1+, the iblock and highloadblock modules, and whitelisted infoblocks to have an API_CODE symbolic code set.
How to disable. Delete the bitrix-mcp-server folder from the site's local/, or remove the server from your MCP client config and revoke auth_token in config.php.
MCP
- Transport
- http
- Authentication
- API key
Security check
- It can create, update and delete infoblock elements and highload-block records
- It runs as a Bitrix service user; access is limited only by the whitelist and a Bearer token
README in short
The README explains the request architecture in detail, from an MCP client through public/index.php to the Bitrix ORM, server requirements, install into local/, every config.php parameter, tool tables for infoblocks and HL-blocks, property value formats by type, and a step-by-step check from a 401 with no token to an audit.log entry.
FAQ
Can I connect it over stdio?
No, the legacy server.php and stdio mode is removed; only Streamable HTTP over a URL with a Bearer token works.
Can I add new infoblock properties?
No, only writing values to existing element properties is supported, not property definitions.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything