Bitrix24 MCP Server: Multi-tenant Remote

Bitrix24 MCP Server — Multi-tenant Remote

A remote MCP server for Bitrix24 with OAuth login: each user enters their own webhook, and the server keeps it only inside an encrypted token

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Tools create, update and complete tasks in a live Bitrix24 portal
  • Each user hands the server their own webhook through the OAuth flow
All reasons and checks
Russian stack

alexseysol/bitrixmcp

Install

Manual install

openssl rand -base64 32

Generates the ENCRYPTION_KEY for .env before the first run.

This is third-party code. Review the repository files before installing.

What it does

The server is deployed once through Docker Compose and serves any number of users: each one goes through an OAuth-like login, enters their own Bitrix24 webhook, and the server encrypts it with AES-256-GCM directly into the issued token, storing nothing in a database. It exposes 17 task tools: filtered listing, create, update, start, pause, complete, defer, renew, delegate, comments and counters, plus user search and listing. It has rate limiting on auth and calls, mandatory PKCE for OAuth and an HTTPS-only mode.

Who it is for. For teams that want one shared Bitrix24 MCP server for everyone, without storing other people's webhooks on their own side.

Good fit when

  • You need to connect Bitrix24 to Claude.ai for several people without sharing one webhook
  • It matters that the server keeps no one else's tokens in a database
  • Task management is enough: create, statuses, comments, counters

Not a fit when

  • You need CRM deals, disk access or calls: the server covers only tasks and users
  • You have no server and domain to deploy it with Docker Compose and Traefik

Example request

Show my overdue Bitrix24 tasks and create a new one due Friday

Limitations

There is no ready public address: you deploy the server yourself on your own HTTPS domain. Only 17 tools exist, all about tasks and users, with no CRM or disk. Each user must create their own Bitrix24 webhook with task and user scopes. The source is not published to a package registry, only as a repository.

How to disable. Remove the connector from Claude.ai (Settings → Connectors) and stop the server container with docker compose down.

MCP

Transport
http
Authentication
OAuth
Environment variables
Environment variables
ENCRYPTION_KEY
required, secret
AES-256 key for encrypting webhooks in the token, at least 16 characters
BASE_URL
required
Public HTTPS address of the deployed server, without a trailing slash
PORT
Server port, defaults to 3000

Security check

  • Tools create, update and complete tasks in a live Bitrix24 portal
  • Each user hands the server their own webhook through the OAuth flow

README in short

The README describes the security model: the server stores no webhooks, all state lives in the client's encrypted token. It gives a step-by-step deploy via .env and Docker Compose with Traefik, instructions for adding a custom connector in Claude.ai and creating a Bitrix24 webhook. It lists all 17 tools and environment variables in a table, with a section on rate limiting, PKCE and stripping tokens from logs.

FAQ

Where is my Bitrix24 webhook stored?

Nowhere on the server: it is encrypted with AES-256-GCM inside your OAuth token and decrypted only when a tool runs.

Can it work with CRM deals?

No, the tool set is limited to tasks, users and the whoami helper.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIBitrix24 MCP Server: Multi-tenant Remote

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.