Bitrix24 MCP with confirmation-gated writes

bitrix24-mcp-server

A self-hosted Bitrix24 MCP with federated OAuth 2.1, encrypted tokens and a two-step confirmation for every write

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • With write_with_confirmation mode enabled, it can create and change CRM entities after confirmation
  • Stores encrypted portal users' OAuth tokens in its own PostgreSQL database
All reasons and checks
Russian stack

ericvanin/bitrix24-mcp-server

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/ericvanin-bitrix24-mcp-server

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

This entry is high risk, so there is no one-click install. Review the code and add the config by hand.

Run in a terminal

claude mcp add --transport http bitrix24 https://your-server.example.com/mcp

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "bitrix24": {
      "type": "http",
      "url": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "bitrix24": {
      "url": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Run in a terminal

code --add-mcp '{"name":"bitrix24","type":"http","url":"https://your-server.example.com/mcp"}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "bitrix24": {
      "type": "http",
      "url": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the servers key.

Run in a terminal

codex mcp add bitrix24 --url https://your-server.example.com/mcp

Or add to the file ~/.codex/config.toml, for all projects

[mcp_servers.bitrix24]
url = "https://your-server.example.com/mcp"

If the file already exists, append the block to the end.

Run in a terminal

gemini mcp add -s user -t http bitrix24 https://your-server.example.com/mcp

Or add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "bitrix24": {
      "httpUrl": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "bitrix24": {
      "serverUrl": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "bitrix24": {
      "type": "streamableHttp",
      "url": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "bitrix24": {
      "type": "streamable-http",
      "url": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "bitrix24": {
      "type": "remote",
      "url": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the mcp key.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "bitrix24": {
      "url": "https://your-server.example.com/mcp"
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Checked against the repository on Sep 25, 2026, commit f6a8118.

Text for your agent

Deploy the server with docker compose up --build and a filled-in .env (APP_URL, DATABASE_URL, BITRIX_CLIENT_ID/SECRET, MCP_AUTH_TOKEN, TOKEN_ENCRYPTION_KEY), then add it with claude mcp add --transport http bitrix24 https://your-server/mcp and complete OAuth via /mcp in Claude Code.

Other ways from the author
cp .env.example .env && npm ci && npm run build && npm start

Needs a filled-in .env with BITRIX_CLIENT_ID/SECRET, DATABASE_URL, MCP_AUTH_TOKEN and TOKEN_ENCRYPTION_KEY.

This is third-party code. Review the repository files before installing.

What it does

The server is self-hosted (Docker Compose or Coolify) with its own Bitrix24 OAuth app and a PostgreSQL database. Each MCP client goes through its own OAuth 2.1 authorization with PKCE and dynamic registration; Bitrix24 tokens are encrypted with AES-256-GCM and refreshed in a concurrency-safe way. Read tools discover a specific portal's schema: CRM entity types including smart processes via crm.type.list, fields, pipelines, stages, users, and items through the universal crm.item.* methods. Writes are deliberately two-step: a prepare tool (create, update, stage move) returns a human-readable summary and a pending operation, which only executes after a separate confirmation call; the operation is atomic and cannot run twice under concurrent requests, and pending operations expire after ten minutes. Every write leaves an audit record with its status. Raw REST calls, deletion, schema administration, robots, business processes and event binding are deliberately not exposed in this release.

Who it is for. For teams that need per-client multi-user authorization and tight control over CRM writes with confirmation on every operation.

Good fit when

  • Several people need to connect each under their own Bitrix24 authorization, not one shared webhook
  • It matters that no CRM write happens without a separate confirmation call
  • You need an audit log of every prepared, completed, failed and cancelled write

Not a fit when

  • You cannot deploy Docker with PostgreSQL and a public HTTPS domain
  • You need raw REST calls, robots, business processes or entity deletion: none of that is here
  • A plain inbound webhook with no OAuth and no database is enough for you

Example request

Prepare moving deal 4821 to the "Paid" stage and show a summary before confirming

Limitations

This is an independent project, not an official Bitrix24 product, and the author recommends testing against a non-production portal first. Requires Node.js 20.11+, PostgreSQL 14+ and your own Bitrix24 OAuth app with a public HTTPS handler URL. Version 0.3.1 accepts hosted *.bitrix24.* cloud domains and exactly one configured custom portal domain; other on-premise domains are currently rejected. Effective access is always limited by the rights of the Bitrix24 user who completed OAuth and the OAuth app's own scopes.

How to disable. Stop the deployed server (docker compose down), remove the OAuth app in the portal, and revoke the MCP_AUTH_TOKEN.

MCP

Transport
http
Authentication
OAuth
Environment variables
Environment variables
BITRIX_CLIENT_ID
required, secret
Your own Bitrix24 OAuth app's client ID
BITRIX_CLIENT_SECRET
required, secret
The Bitrix24 OAuth app's client secret
TOKEN_ENCRYPTION_KEY
required, secret
A stable token encryption key for the lifetime of the database
MCP_AUTH_TOKEN
required, secret
A static bearer token for operator access and recovery, minimum 32 characters

Security check

  • With write_with_confirmation mode enabled, it can create and change CRM entities after confirmation
  • Stores encrypted portal users' OAuth tokens in its own PostgreSQL database

README in short

The README lists what is included (a bring-your-own OAuth app, token encryption, read-only tools, SPA discovery, a schema metadata cache, confirmation-gated write operations, an audit trail, stateless Streamable HTTP with OAuth 2.1), a quick start with environment variables, setting up the Bitrix24 local app, connecting clients (Claude custom connector, Claude Code, Codex, generic static-bearer), a full configuration table, Docker and Coolify instructions, and an architecture diagram. It points to SECURITY.md before production deployment.

FAQ

Can the agent write data without confirmation?

No, the default read_only mode denies both preparation and execution; preparation is allowed only with explicit mode=write_with_confirmation, and the write executes via a separate bitrix_confirm_operation call.

What if two requests try to confirm the same operation at once?

Confirmation is atomic, concurrent requests cannot execute the same operation twice.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIBitrix24 MCP with confirmation-gated writes

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.