BitrixMCP: a deterministic Bitrix24 server
BitrixMCP
A Python MCP server for Bitrix24 with no internal LLM: a static method catalog, a read-or-write access policy, and per-user OAuth for confirmed writes
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- In read,write mode with dry_run off, it can create and update deals, tasks and activities
- OAuth mode stores decryptable employee access tokens on the server
Install
Manual install
uv sync && uv run python main.pyBefore running, copy .env.example to .env and set BITRIX_WEBHOOK_URL.
This is third-party code. Review the repository files before installing.
What it does
The server gives the client model tools to search and describe Bitrix24 methods from a built-in static catalog rather than by hitting the network, plus a bitrix_call fallback for any allowed method. Reading CRM, tasks, activities, employees and telephony goes through an inbound webhook. Writes work in two ways: through the webhook under a BITRIX_ALLOWED_ACCESS policy, or through per-user OAuth when the server is deployed as a shared service for multiple people, for example in LibreChat. In OAuth mode, webhook writes are blocked and changes are only allowed for the record's owner unless an admin is explicitly configured. Every curated write tool defaults to dry_run enabled.
Who it is for. For teams that need a shared Bitrix24 MCP server for multiple employees with separate read and write access and explicit change confirmation.
Good fit when
- You need a team MCP server, not a single-user one, with per-user OAuth identity
- You want to restrict the agent to read-only access via BITRIX_ALLOWED_ACCESS
- You want a static Bitrix24 method catalog instead of hitting the network for API descriptions
Not a fit when
- You want a simple personal server without an OAuth app and token encryption
- You cannot register a local Bitrix24 app for OAuth-based writes
Example request
Show my open Bitrix24 deals and list which CRM methods are actually available through this webhookLimitations
The project is young with no stars, and the README explicitly lists recent breaking changes to the tools. A full OAuth setup requires registering a local Bitrix24 app, a Fernet encryption key, and handling a special X-Bitrix-User-Email header from the client. The method catalog is built from an external b24-rest-docs repository, so its freshness depends on that source. No license is specified in the repository.
How to disable. Stop the docker compose stack or the python main.py process and remove the server from your MCP client configuration.
MCP
- Transport
- stdio, http
- Authentication
- API key
| Environment variables | |
|---|---|
| BITRIX_WEBHOOK_URL required, secret | The Bitrix24 portal inbound webhook URL |
| BITRIX_ALLOWED_ACCESS | Access policy: read, or read,write, or read,write,destructive |
| MCP_BEARER_TOKEN secret | A shared bearer token for public deployments, required when OAuth is enabled |
| BITRIX_OAUTH_CLIENT_ID secret | The Bitrix24 local app client ID for per-user OAuth |
| BITRIX_OAUTH_CLIENT_SECRET secret | The Bitrix24 local app client secret for per-user OAuth |
| BITRIX_TOKEN_ENCRYPTION_KEY secret | A Fernet key for encrypting OAuth tokens in SQLite |
Security check
- In read,write mode with dry_run off, it can create and update deals, tasks and activities
- OAuth mode stores decryptable employee access tokens on the server
README in short
The README describes a deterministic server with no internal LLM: the client model finds methods itself via bitrix_search_methods and bitrix_describe_method or calls bitrix_call directly. It separately covers curated tools for CRM, tasks, activities, employees and telephony, the BITRIX_ALLOWED_ACCESS access policy, a per-user OAuth scheme with Fernet token encryption, and a list of recent breaking changes from the previous version.
FAQ
Can the server change CRM data right away?
Curated write tools default to dry_run=true, and write access overall is controlled by the BITRIX_ALLOWED_ACCESS variable.
Is OAuth mandatory?
No, the normal mode works with a single inbound webhook. OAuth is only needed for writes attributed to specific employees in a shared deployment.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail