http1c: MCP server framework for 1C
http1c
A native component that runs a full MCP server inside 1C: tools, resources and prompts are written in BSL, while a DLL handles the protocol
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- The demo execute tool runs arbitrary 1C code on the server or thin client
- Authentication is off by default; anyone reaching the port gets access to every tool
Install
Manual install
build/build-http1c-dll-release.shBuilds the native component and packages the add-in, requires Visual Studio Build Tools 2019+.
This is third-party code. Review the repository files before installing.
What it does
http1c splits responsibility into two layers: the native component (DLL) handles the MCP transport over Streamable HTTP and SSE, session management, Bearer-token authentication, pagination and notifications, while the 1C side in BSL describes the specific tools, resources and prompts and handles calls via ExternalEvent. It ships with a demo external data processor with example tools: execute (running arbitrary code), evaluate, query, openForm and getStatus. Optionally, a built-in semantic search (RAG) subsystem runs on a Rust rcore engine with hybrid (dense plus keyword) retrieval that indexes any 1C content with no external services, plus a ready MCPRagSearch integration for Vanessa Automation that exposes VA's whole MCP contract along with search over its step catalog and knowledge base.
Who it is for. For 1C developers who want to expose their configuration's business logic to agents over MCP without dealing with HTTP, JSON-RPC and SSE themselves.
Good fit when
- You need an MCP server over your own 1C configuration with custom BSL tools
- You need semantic search over documentation, code, catalog descriptions or logs with no external vector store
- You write Vanessa Automation tests and want an agent to rely on the real step catalog via search rather than inventing steps
Not a fit when
- You have no Windows and no Visual Studio Build Tools to build the native component
- You need ready-made functionality rather than something you describe yourself: this is a framework, not a set of ready tools
- You are not ready to explicitly restrict the execute tool, which runs arbitrary 1C code
Example request
Open the Nomenclature catalog form and find, by meaning, the Vanessa steps for verifying new element creationLimitations
The native component can only be built on Windows with MSVC. The HTTP server is intentionally local-only, binding to 127.0.0.1. The authors themselves describe the demo's execute and evaluate tools as powerful server capabilities to be used only in a trusted local environment. A full build with semantic search (rcore.dll) requires Rust, and GPU acceleration via DirectML depends on a Windows system library.
How to disable. Detach the component in the http1c.epf form (StopListen) or close the processing, and remove the server from your client's mcp.json.
MCP
- Transport
- sse, http
- Authentication
- API key
Security check
- The demo execute tool runs arbitrary 1C code on the server or thin client
- Authentication is off by default; anyone reaching the port gets access to every tool
README in short
The README describes in detail the architecture and division of responsibility between the DLL and 1C, the full list of native methods and ExternalEvent events, supported MCP protocol methods, the demo processing's reference tools, resources and prompts, Bearer authentication setup, the design and rationale of the RAG semantic search subsystem on rcore with a table of design decisions, the differences between lite and full builds, Vanessa Automation integration via the MCPRagSearch plugin, Windows build requirements, and known limitations.
FAQ
Is semantic search mandatory to build?
No, by default the lite version without the Rust core is built; search can be added separately with the -DRCORE_FASTEMBED=ON flag.
Do you need to write C++ code for new tools?
No, new tools, resources and prompts are described in BSL and registered with the component; the transport layer does not need to be touched.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything