MCP for Bitrix infoblocks and highload blocks

Bitrix MCP Server

A PHP script inside a Bitrix site: an HTTP MCP server for reading and writing infoblock and highload-block data, with a whitelist and an audit log

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • It can create, update and delete infoblock elements and highload-block records
  • It runs as a Bitrix service user; access is limited only by the whitelist and a Bearer token
All reasons and checks
Russian stack

dimabresky/bitrix-mcp-server

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/bitrix-mcp-server

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

This entry is high risk, so there is no one-click install. Review the code and add the config by hand.

Run in a terminal

claude mcp add --transport http bitrix-data https://staging.example.com/local/bitrix-mcp-server/public/ --header 'Authorization: Bearer <your AUTHORIZATION>'

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "bitrix-data": {
      "type": "http",
      "url": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "bitrix-data": {
      "url": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

code --add-mcp '{"name":"bitrix-data","type":"http","url":"https://staging.example.com/local/bitrix-mcp-server/public/","headers":{"Authorization":"Bearer <your AUTHORIZATION>"}}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "bitrix-data": {
      "type": "http",
      "url": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the servers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.codex/config.toml, for all projects

[mcp_servers.bitrix-data]
url = "https://staging.example.com/local/bitrix-mcp-server/public/"
http_headers = { Authorization = "Bearer <your AUTHORIZATION>" }

If the file already exists, append the block to the end.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "bitrix-data": {
      "httpUrl": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "bitrix-data": {
      "serverUrl": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "bitrix-data": {
      "type": "streamableHttp",
      "url": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "bitrix-data": {
      "type": "streamable-http",
      "url": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "bitrix-data": {
      "type": "remote",
      "url": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcp key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "bitrix-data": {
      "url": "https://staging.example.com/local/bitrix-mcp-server/public/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Checked against the repository on Sep 25, 2026, commit 1775975.

Text for your agent

Clone the repository into local/bitrix-mcp-server on the Bitrix site, run composer install --no-dev, copy config.sample.php to config.php with a token and ID whitelist, create writable logs and sessions folders, then connect an MCP client to the URL with an Authorization: Bearer header.

Other ways from the author
cd /var/www/site/local && git clone https://github.com/dimabresky/bitrix-mcp-server.git bitrix-mcp-server && cd bitrix-mcp-server && composer install --no-dev

Install directly into the Bitrix site's local/.

This is third-party code. Review the repository files before installing.

What it does

The server lives right inside a Bitrix site as a plain PHP script under local/, boots through prolog_before.php, and works only over HTTP with the Streamable HTTP transport, with no stdio or SSH tunnel. Its tools read infoblock and highload-block schemas, list sections and elements, read an element card respecting the smart filter, create and update records, and delete them only with explicit confirmation. Access is limited to a whitelist of infoblock and HL-block IDs from config.php, every call is logged to an audit file, and operations run as a Bitrix service user through the standard $USER->Authorize().

Who it is for. For Bitrix developers who need scoped, auditable agent access to catalog and highload-reference data.

Good fit when

  • You need access to specific infoblocks or highload-blocks by a whitelist, not the whole portal
  • You need an audit trail of every agent call to site data
  • It is more convenient to keep the MCP server right on the Bitrix site rather than run a separate process

Not a fit when

  • You need tasks, CRM or messenger access: the server only covers infoblocks and highload-blocks
  • You cannot place PHP files under the site's local/ and expose an HTTPS-reachable path

Example request

Find element 2449677 in infoblock 16 and show all its properties, not just the smart filter

Limitations

Managing property definitions (CIBlockProperty, enum values) and file properties is not supported, only values on elements. The legacy server.php and stdio mode has been fully removed. It requires PHP 8.1+, the iblock and highloadblock modules, and whitelisted infoblocks to have an API_CODE symbolic code set.

How to disable. Delete the bitrix-mcp-server folder from the site's local/, or remove the server from your MCP client config and revoke auth_token in config.php.

MCP

Transport
http
Authentication
API key

Security check

  • It can create, update and delete infoblock elements and highload-block records
  • It runs as a Bitrix service user; access is limited only by the whitelist and a Bearer token

README in short

The README explains the request architecture in detail, from an MCP client through public/index.php to the Bitrix ORM, server requirements, install into local/, every config.php parameter, tool tables for infoblocks and HL-blocks, property value formats by type, and a step-by-step check from a 401 with no token to an audit.log entry.

FAQ

Can I connect it over stdio?

No, the legacy server.php and stdio mode is removed; only Streamable HTTP over a URL with a Bearer token works.

Can I add new infoblock properties?

No, only writing values to existing element properties is supported, not property definitions.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium riskNo VPN needed292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium riskNo VPN needed139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AIMCP for Bitrix infoblocks and highload blocks

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.