Bitrix24 MCP Server: Multi-tenant Remote
Bitrix24 MCP Server — Multi-tenant Remote
A remote MCP server for Bitrix24 with OAuth login: each user enters their own webhook, and the server keeps it only inside an encrypted token
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Tools create, update and complete tasks in a live Bitrix24 portal
- Each user hands the server their own webhook through the OAuth flow
Install
Manual install
openssl rand -base64 32Generates the ENCRYPTION_KEY for .env before the first run.
This is third-party code. Review the repository files before installing.
What it does
The server is deployed once through Docker Compose and serves any number of users: each one goes through an OAuth-like login, enters their own Bitrix24 webhook, and the server encrypts it with AES-256-GCM directly into the issued token, storing nothing in a database. It exposes 17 task tools: filtered listing, create, update, start, pause, complete, defer, renew, delegate, comments and counters, plus user search and listing. It has rate limiting on auth and calls, mandatory PKCE for OAuth and an HTTPS-only mode.
Who it is for. For teams that want one shared Bitrix24 MCP server for everyone, without storing other people's webhooks on their own side.
Good fit when
- You need to connect Bitrix24 to Claude.ai for several people without sharing one webhook
- It matters that the server keeps no one else's tokens in a database
- Task management is enough: create, statuses, comments, counters
Not a fit when
- You need CRM deals, disk access or calls: the server covers only tasks and users
- You have no server and domain to deploy it with Docker Compose and Traefik
Example request
Show my overdue Bitrix24 tasks and create a new one due FridayLimitations
There is no ready public address: you deploy the server yourself on your own HTTPS domain. Only 17 tools exist, all about tasks and users, with no CRM or disk. Each user must create their own Bitrix24 webhook with task and user scopes. The source is not published to a package registry, only as a repository.
How to disable. Remove the connector from Claude.ai (Settings → Connectors) and stop the server container with docker compose down.
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| ENCRYPTION_KEY required, secret | AES-256 key for encrypting webhooks in the token, at least 16 characters |
| BASE_URL required | Public HTTPS address of the deployed server, without a trailing slash |
| PORT | Server port, defaults to 3000 |
Security check
- Tools create, update and complete tasks in a live Bitrix24 portal
- Each user hands the server their own webhook through the OAuth flow
README in short
The README describes the security model: the server stores no webhooks, all state lives in the client's encrypted token. It gives a step-by-step deploy via .env and Docker Compose with Traefik, instructions for adding a custom connector in Claude.ai and creating a Bitrix24 webhook. It lists all 17 tools and environment variables in a table, with a section on rate limiting, PKCE and stripping tokens from logs.
FAQ
Where is my Bitrix24 webhook stored?
Nowhere on the server: it is encrypted with AES-256-GCM inside your OAuth token and decrypted only when a tool runs.
Can it work with CRM deals?
No, the tool set is limited to tasks, users and the whoami helper.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail