Bitrix24 MCP server for Open WebUI
Bitrix24 MCP Server
A Bitrix24 MCP server with 32 tools for companies, contacts, leads, deals and invoices over HTTP with JSON-RPC, deployable on Railway
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Delete tools for companies, contacts, leads, deals and invoices run with no confirmation
- Issuing invoices directly affects the client's financial documents
Install
Manual install
npm install && npm run build && npm startBefore running, set BITRIX_BASE_URL and BITRIX_TOKEN in .env.
This is third-party code. Review the repository files before installing.
What it does
The server implements MCP over HTTP with its own JSON-RPC handler at paths like /mcp/v1/initialize, /mcp/v1/tools/list and /mcp/v1/tools/call, rather than through a ready-made SDK transport. It covers five CRM entities with the same six-operation pattern each: list, get by id, search, create, update, delete, plus a separate invoice tool for adding line items and a shared tool for reading an entity's field schema. The code has hardcoded custom field IDs for the Italian tax system, such as a VAT number and a PEC code, left over from the original client; on a Russian portal these fields simply stay unused.
Who it is for. For people using Open WebUI as an MCP client who want full CRUD on Bitrix24 companies, contacts, leads, deals and invoices.
Good fit when
- You need an HTTP-transport MCP server for Open WebUI, not just Claude
- You need full CRUD across five CRM entities at once
- Deploying on Railway works for you
Not a fit when
- You need tasks, projects or business processes: the server only covers CRM entities
- The hardcoded Italian tax-system fields in the invoice code examples get in the way
- You need a confirmation step before deleting a record: the code has none
Example request
Find the Acme company in Bitrix24 and issue it an invoice for a service worth 1000 eurosLimitations
Deleting companies, contacts, leads, deals and invoices happens with no confirmation step. The invoice custom fields are hardcoded for the Italian tax system and need editing for another country. The ALLOWED_ORIGINS variable defaults to all origins. There is a single author, no stars, and an MIT license.
How to disable. Stop or delete the Railway deployment and remove the server from your Open WebUI configuration.
MCP
- Transport
- http
- Authentication
- not required
| Environment variables | |
|---|---|
| BITRIX_BASE_URL required, secret | The base webhook URL without the token, e.g. https://domain.bitrix24.com/rest/USER_ID |
| BITRIX_TOKEN required, secret | The secret webhook token |
| ALLOWED_ORIGINS | The list of allowed CORS origins; defaults to a wildcard, meaning all origins |
Security check
- Delete tools for companies, contacts, leads, deals and invoices run with no confirmation
- Issuing invoices directly affects the client's financial documents
README in short
The README describes a production-ready server for Open WebUI with HTTP and SSE transport, lists 32 tools across six entities in tables, gives install, build and run instructions, an Open WebUI integration example, Railway deployment steps via GitHub or the CLI, and an environment variable table. A separate section covers the Italian tax-system custom fields.
FAQ
Is there confirmation before deleting a record?
No, the bitrix_*_delete tools run immediately on call with no intermediate confirmation.
Do the hardcoded invoice fields work for a Russian portal?
No, they are tied to the Italian tax system; for another country you need to redefine them in src/tools/invoice.ts.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail