Bitrix24 MCP with confirmation-gated writes
bitrix24-mcp-server
A self-hosted Bitrix24 MCP with federated OAuth 2.1, encrypted tokens and a two-step confirmation for every write
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- With write_with_confirmation mode enabled, it can create and change CRM entities after confirmation
- Stores encrypted portal users' OAuth tokens in its own PostgreSQL database
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/ericvanin-bitrix24-mcp-serverDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport http bitrix24 https://your-server.example.com/mcpOr add to the file .mcp.json, in the project
{
"mcpServers": {
"bitrix24": {
"type": "http",
"url": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"bitrix24": {
"url": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Run in a terminal
code --add-mcp '{"name":"bitrix24","type":"http","url":"https://your-server.example.com/mcp"}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"bitrix24": {
"type": "http",
"url": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the servers key.
Run in a terminal
codex mcp add bitrix24 --url https://your-server.example.com/mcpOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.bitrix24]
url = "https://your-server.example.com/mcp"If the file already exists, append the block to the end.
Run in a terminal
gemini mcp add -s user -t http bitrix24 https://your-server.example.com/mcpOr add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"bitrix24": {
"httpUrl": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"bitrix24": {
"serverUrl": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"bitrix24": {
"type": "streamableHttp",
"url": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"bitrix24": {
"type": "streamable-http",
"url": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the mcpServers key.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"bitrix24": {
"type": "remote",
"url": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the mcp key.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"bitrix24": {
"url": "https://your-server.example.com/mcp"
}
}
}If the file already exists, add the server inside the context_servers key.
Deploy the server with docker compose up --build and a filled-in .env (APP_URL, DATABASE_URL, BITRIX_CLIENT_ID/SECRET, MCP_AUTH_TOKEN, TOKEN_ENCRYPTION_KEY), then add it with claude mcp add --transport http bitrix24 https://your-server/mcp and complete OAuth via /mcp in Claude Code.
Other ways from the author
cp .env.example .env && npm ci && npm run build && npm startNeeds a filled-in .env with BITRIX_CLIENT_ID/SECRET, DATABASE_URL, MCP_AUTH_TOKEN and TOKEN_ENCRYPTION_KEY.
This is third-party code. Review the repository files before installing.
What it does
The server is self-hosted (Docker Compose or Coolify) with its own Bitrix24 OAuth app and a PostgreSQL database. Each MCP client goes through its own OAuth 2.1 authorization with PKCE and dynamic registration; Bitrix24 tokens are encrypted with AES-256-GCM and refreshed in a concurrency-safe way. Read tools discover a specific portal's schema: CRM entity types including smart processes via crm.type.list, fields, pipelines, stages, users, and items through the universal crm.item.* methods. Writes are deliberately two-step: a prepare tool (create, update, stage move) returns a human-readable summary and a pending operation, which only executes after a separate confirmation call; the operation is atomic and cannot run twice under concurrent requests, and pending operations expire after ten minutes. Every write leaves an audit record with its status. Raw REST calls, deletion, schema administration, robots, business processes and event binding are deliberately not exposed in this release.
Who it is for. For teams that need per-client multi-user authorization and tight control over CRM writes with confirmation on every operation.
Good fit when
- Several people need to connect each under their own Bitrix24 authorization, not one shared webhook
- It matters that no CRM write happens without a separate confirmation call
- You need an audit log of every prepared, completed, failed and cancelled write
Not a fit when
- You cannot deploy Docker with PostgreSQL and a public HTTPS domain
- You need raw REST calls, robots, business processes or entity deletion: none of that is here
- A plain inbound webhook with no OAuth and no database is enough for you
Example request
Prepare moving deal 4821 to the "Paid" stage and show a summary before confirmingLimitations
This is an independent project, not an official Bitrix24 product, and the author recommends testing against a non-production portal first. Requires Node.js 20.11+, PostgreSQL 14+ and your own Bitrix24 OAuth app with a public HTTPS handler URL. Version 0.3.1 accepts hosted *.bitrix24.* cloud domains and exactly one configured custom portal domain; other on-premise domains are currently rejected. Effective access is always limited by the rights of the Bitrix24 user who completed OAuth and the OAuth app's own scopes.
How to disable. Stop the deployed server (docker compose down), remove the OAuth app in the portal, and revoke the MCP_AUTH_TOKEN.
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| BITRIX_CLIENT_ID required, secret | Your own Bitrix24 OAuth app's client ID |
| BITRIX_CLIENT_SECRET required, secret | The Bitrix24 OAuth app's client secret |
| TOKEN_ENCRYPTION_KEY required, secret | A stable token encryption key for the lifetime of the database |
| MCP_AUTH_TOKEN required, secret | A static bearer token for operator access and recovery, minimum 32 characters |
Security check
- With write_with_confirmation mode enabled, it can create and change CRM entities after confirmation
- Stores encrypted portal users' OAuth tokens in its own PostgreSQL database
README in short
The README lists what is included (a bring-your-own OAuth app, token encryption, read-only tools, SPA discovery, a schema metadata cache, confirmation-gated write operations, an audit trail, stateless Streamable HTTP with OAuth 2.1), a quick start with environment variables, setting up the Bitrix24 local app, connecting clients (Claude custom connector, Claude Code, Codex, generic static-bearer), a full configuration table, Docker and Coolify instructions, and an architecture diagram. It points to SECURITY.md before production deployment.
FAQ
Can the agent write data without confirmation?
No, the default read_only mode denies both preparation and execution; preparation is allowed only with explicit mode=write_with_confirmation, and the write executes via a separate bitrix_confirm_operation call.
What if two requests try to confirm the same operation at once?
Confirmation is atomic, concurrent requests cannot execute the same operation twice.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail