BitrixMCP: a deterministic Bitrix24 server

BitrixMCP

A Python MCP server for Bitrix24 with no internal LLM: a static method catalog, a read-or-write access policy, and per-user OAuth for confirmed writes

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • In read,write mode with dry_run off, it can create and update deals, tasks and activities
  • OAuth mode stores decryptable employee access tokens on the server
All reasons and checks
Russian stack

aaparin/bitrixmcp

Install

Manual install

uv sync && uv run python main.py

Before running, copy .env.example to .env and set BITRIX_WEBHOOK_URL.

This is third-party code. Review the repository files before installing.

What it does

The server gives the client model tools to search and describe Bitrix24 methods from a built-in static catalog rather than by hitting the network, plus a bitrix_call fallback for any allowed method. Reading CRM, tasks, activities, employees and telephony goes through an inbound webhook. Writes work in two ways: through the webhook under a BITRIX_ALLOWED_ACCESS policy, or through per-user OAuth when the server is deployed as a shared service for multiple people, for example in LibreChat. In OAuth mode, webhook writes are blocked and changes are only allowed for the record's owner unless an admin is explicitly configured. Every curated write tool defaults to dry_run enabled.

Who it is for. For teams that need a shared Bitrix24 MCP server for multiple employees with separate read and write access and explicit change confirmation.

Good fit when

  • You need a team MCP server, not a single-user one, with per-user OAuth identity
  • You want to restrict the agent to read-only access via BITRIX_ALLOWED_ACCESS
  • You want a static Bitrix24 method catalog instead of hitting the network for API descriptions

Not a fit when

  • You want a simple personal server without an OAuth app and token encryption
  • You cannot register a local Bitrix24 app for OAuth-based writes

Example request

Show my open Bitrix24 deals and list which CRM methods are actually available through this webhook

Limitations

The project is young with no stars, and the README explicitly lists recent breaking changes to the tools. A full OAuth setup requires registering a local Bitrix24 app, a Fernet encryption key, and handling a special X-Bitrix-User-Email header from the client. The method catalog is built from an external b24-rest-docs repository, so its freshness depends on that source. No license is specified in the repository.

How to disable. Stop the docker compose stack or the python main.py process and remove the server from your MCP client configuration.

MCP

Transport
stdio, http
Authentication
API key
Environment variables
Environment variables
BITRIX_WEBHOOK_URL
required, secret
The Bitrix24 portal inbound webhook URL
BITRIX_ALLOWED_ACCESS
Access policy: read, or read,write, or read,write,destructive
MCP_BEARER_TOKEN
secret
A shared bearer token for public deployments, required when OAuth is enabled
BITRIX_OAUTH_CLIENT_ID
secret
The Bitrix24 local app client ID for per-user OAuth
BITRIX_OAUTH_CLIENT_SECRET
secret
The Bitrix24 local app client secret for per-user OAuth
BITRIX_TOKEN_ENCRYPTION_KEY
secret
A Fernet key for encrypting OAuth tokens in SQLite

Security check

  • In read,write mode with dry_run off, it can create and update deals, tasks and activities
  • OAuth mode stores decryptable employee access tokens on the server

README in short

The README describes a deterministic server with no internal LLM: the client model finds methods itself via bitrix_search_methods and bitrix_describe_method or calls bitrix_call directly. It separately covers curated tools for CRM, tasks, activities, employees and telephony, the BITRIX_ALLOWED_ACCESS access policy, a per-user OAuth scheme with Fernet token encryption, and a list of recent breaking changes from the previous version.

FAQ

Can the server change CRM data right away?

Curated write tools default to dry_run=true, and write access overall is controlled by the BITRIX_ALLOWED_ACCESS variable.

Is OAuth mandatory?

No, the normal mode works with a single inbound webhook. OAuth is only needed for writes attributed to specific employees in a shared deployment.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIBitrixMCP: a deterministic Bitrix24 server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.