Bitrix Framework code indexer
Bitrix MCP
A local, token-free MCP indexer for 1C-Bitrix projects: symbols, events, ORM, a dependency graph and optional DB access
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- The optional bitrix_tinker tool executes arbitrary PHP code with write access on the local machine
- Optional DB access, with the write flag enabled, changes project data directly in MySQL
Install
Manual install
npm install -g @mb4it/bitrix-mcpOr without installing: npx @mb4it/bitrix-mcp init.
This is third-party code. Review the repository files before installing.
What it does
The server indexes a local Bitrix Framework or 1C-Bitrix project: your own code, templates and components, the Bitrix core (if a bitrix/ folder exists), and the official docs via SQLite full-text search, with optional semantic search through a Python service. It gives an agent search over functions, classes, methods, events, components and constants across the project and core, dedicated tools for ORM entities, iblocks, highload blocks, options and agents, and a dependency graph with neighbor traversal and change-impact radius. It needs neither a Bitrix module nor a token: access is limited only to whichever local folders are exposed. Separately, entirely opt-in, two powerful modes can be enabled: direct MySQL access to the project (credentials parsed from bitrix/.settings.php, read-only by default, writes behind a separate flag) and bitrix_tinker, which executes arbitrary PHP with the full Bitrix kernel loaded, a Laravel Tinker analog with full code execution and write access on the local machine.
Who it is for. For developers on large Bitrix Framework projects who need precise code and core search instead of grep and guessing method signatures.
Good fit when
- You need precise search for event handlers, ORM entities or module usage across the project and core
- You need to assess the impact radius of a change before refactoring
- You need a local, private index with no Bitrix module install and no token
Not a fit when
- You need live CRM or catalog REST data, not project code
- You have no trusted local dev environment: DB access and bitrix_tinker give full database access and code execution
Example request
Check the index status, then find how this project registers sale module event handlersLimitations
Requires Node.js 22.12+ (uses node:sqlite) and npm 10+, plus Python 3.11+ for optional semantic search. The first docs index clones the official Bitrix documentation repo and needs network access, which can be disabled via an environment variable. Database access and bitrix_tinker are off by default and must be deliberately enabled only in a trusted local environment, never on shared or production machines.
How to disable. Remove the package with npm uninstall -g @mb4it/bitrix-mcp and the server entry from your MCP client config; delete the .bitrix-mcp index folder if needed.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| BITRIX_ROOT | The Bitrix project root for core indexing |
| BITRIX_MCP_DB_ENABLED | Enables optional MySQL access tools for the project, off by default |
| BITRIX_MCP_TINKER_ENABLED | Enables bitrix_tinker with full PHP code execution, off by default |
Security check
- The optional bitrix_tinker tool executes arbitrary PHP code with write access on the local machine
- Optional DB access, with the write flag enabled, changes project data directly in MySQL
README in short
The README lists the capabilities (symbol and LiveAPI search, project, template and core indexing, docs search, a dependency graph and impact radius), requirements and install via npm or npx, a quick start with the init command and agent selection, everyday CLI indexing commands, a grouped list of MCP tools, environment variables, separate sections on optional database access and bitrix_tinker with an explicit full-code-execution warning, and links to detailed per-topic docs. MIT license.
FAQ
Does it need a token or a Bitrix module?
No, the server is entirely local and works with the project's files directly, access is limited only to the folders it is exposed to.
How risky is bitrix_tinker?
It is full PHP code execution with the whole Bitrix kernel loaded and write access, and the README explicitly warns to enable it only in a trusted local dev environment, never on production machines.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything