1C Bugboard MCP
bugboard-mcp
An unofficial Rust MCP server for projects, bugs, subscriptions and votes in the 1C Bugboard, using your existing browser session
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Uses the cookie of a real authenticated user session as a secret
- Subscribe and vote tools change the state of the account in Bugboard
Install
Manual install
mise installInstalls the project's pinned toolchain.
This is third-party code. Review the repository files before installing.
What it does
The server gives an MCP client access to the 1C Bugboard: projects and versions, recent and subscribed bugs, bugs you voted for, and search by bug number or full text with details and reference-redacted history. All list and search results return opaque handles that only work within the current MCP session, so Bugboard links themselves are never passed to the client. Write operations, subscribe, unsubscribe, vote and unvote, each check the current state first, skip a no-op action, and confirm the result. The server does not automate a browser or collect credentials itself; it uses the cookie of an already authenticated session.
Who it is for. For people who work with the 1C Bugboard and want an agent to access their projects, bugs and subscriptions without browser automation.
Good fit when
- You need to find a bug by number or text and see its history
- You need a list of subscribed bugs or bugs you have voted for
- You need to subscribe, unsubscribe or vote for a bug from a conversation with an agent
Not a fit when
- You have no active authenticated 1C Bugboard session and its cookie
- You need pagination beyond the first page of search results: the README says this will only be added after its request shape is verified
- The server would run outside a trusted local network: the HTTP endpoint has no separate client authorization
Example request
Find bug number 12345 in the 1C Bugboard and show its current historyLimitations
The server is unofficial and experimental, needs the cookie of an active 1C Bugboard session in BUGBOARD_COOKIE or an external env file, and it must be refreshed manually after it expires. The HTTP MCP endpoint has no separate client authorization, so publishing the port externally is unsafe; the README requires binding to loopback only. Search pagination is not implemented yet, with results limited to 1 through 50. It is licensed source-available under Apache-2.0 with Commons Clause 1.0, not an OSI-approved open-source license, and the tool itself may not be resold.
How to disable. Stop the server process or container and remove its address from your MCP client configuration.
MCP
- Transport
- http, stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| BUGBOARD_COOKIE required, secret | Cookie of an active authenticated 1C Bugboard session, used directly by the server, which does not perform its own login. |
| BUGBOARD_SESSION_ENV | Path to an external env file holding the cookie outside the repository, an alternative to the direct variable. |
Security check
- Uses the cookie of a real authenticated user session as a secret
- Subscribe and vote tools change the state of the account in Bugboard
README in short
The English README describes giving an MCP client access to 1C Bugboard projects, versions, bugs, history, subscriptions and votes through the cookie of an existing session. It explains opaque handles, state-checked safe write operations, running via mise in HTTP or stdio modes, building and publishing a Docker image to ghcr.io, tool input requirements, and a security section that explicitly forbids publishing the port beyond loopback. Source-available Apache-2.0 with Commons Clause license.
FAQ
Does the server log into Bugboard itself?
No, it uses the cookie of an already authenticated browser session and does not collect or store a password.
What happens when you subscribe to a bug you're already subscribed to?
The tool checks the current state, sees the action is unnecessary, and skips it as a no-op instead of erroring.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything