Bitrix24 MCP server for Open WebUI

Bitrix24 MCP Server

A Bitrix24 MCP server with 32 tools for companies, contacts, leads, deals and invoices over HTTP with JSON-RPC, deployable on Railway

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Delete tools for companies, contacts, leads, deals and invoices run with no confirmation
  • Issuing invoices directly affects the client's financial documents
All reasons and checks
Russian stack

ibrahim-dvp/bitrix-mcp

Install

Manual install

npm install && npm run build && npm start

Before running, set BITRIX_BASE_URL and BITRIX_TOKEN in .env.

This is third-party code. Review the repository files before installing.

What it does

The server implements MCP over HTTP with its own JSON-RPC handler at paths like /mcp/v1/initialize, /mcp/v1/tools/list and /mcp/v1/tools/call, rather than through a ready-made SDK transport. It covers five CRM entities with the same six-operation pattern each: list, get by id, search, create, update, delete, plus a separate invoice tool for adding line items and a shared tool for reading an entity's field schema. The code has hardcoded custom field IDs for the Italian tax system, such as a VAT number and a PEC code, left over from the original client; on a Russian portal these fields simply stay unused.

Who it is for. For people using Open WebUI as an MCP client who want full CRUD on Bitrix24 companies, contacts, leads, deals and invoices.

Good fit when

  • You need an HTTP-transport MCP server for Open WebUI, not just Claude
  • You need full CRUD across five CRM entities at once
  • Deploying on Railway works for you

Not a fit when

  • You need tasks, projects or business processes: the server only covers CRM entities
  • The hardcoded Italian tax-system fields in the invoice code examples get in the way
  • You need a confirmation step before deleting a record: the code has none

Example request

Find the Acme company in Bitrix24 and issue it an invoice for a service worth 1000 euros

Limitations

Deleting companies, contacts, leads, deals and invoices happens with no confirmation step. The invoice custom fields are hardcoded for the Italian tax system and need editing for another country. The ALLOWED_ORIGINS variable defaults to all origins. There is a single author, no stars, and an MIT license.

How to disable. Stop or delete the Railway deployment and remove the server from your Open WebUI configuration.

MCP

Transport
http
Authentication
not required
Environment variables
Environment variables
BITRIX_BASE_URL
required, secret
The base webhook URL without the token, e.g. https://domain.bitrix24.com/rest/USER_ID
BITRIX_TOKEN
required, secret
The secret webhook token
ALLOWED_ORIGINS
The list of allowed CORS origins; defaults to a wildcard, meaning all origins

Security check

  • Delete tools for companies, contacts, leads, deals and invoices run with no confirmation
  • Issuing invoices directly affects the client's financial documents

README in short

The README describes a production-ready server for Open WebUI with HTTP and SSE transport, lists 32 tools across six entities in tables, gives install, build and run instructions, an Open WebUI integration example, Railway deployment steps via GitHub or the CLI, and an environment variable table. A separate section covers the Italian tax-system custom fields.

FAQ

Is there confirmation before deleting a record?

No, the bitrix_*_delete tools run immediately on call with no intermediate confirmation.

Do the hardcoded invoice fields work for a Russian portal?

No, they are tied to the Italian tax system; for another country you need to redefine them in src/tools/invoice.ts.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIBitrix24 MCP server for Open WebUI

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.