INFATON MCP Server

A 1C-extension MCP server with 93 tools for reading, writing, posting and administering ERP, Trade Management, UPP and Accounting

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • execute_code runs arbitrary BSL code in privileged mode
  • post_document, unpost_document and delete_object change document posting and delete objects
  • import_data and run_scheduled_job can mass-change data or trigger scheduled jobs
All reasons and checks
Russian stack

infaton/mcp35

Install

Manual install

{
  "mcpServers": {
    "1c-erp": {
      "command": "npx",
      "args": ["infaton-mcp"],
      "env": {
        "ONEC_URL": "https://your-server/base/hs/mcp/",
        "ONEC_USER": "Username",
        "ONEC_PASSWORD": "Password"
      }
    }
  }
}

No repository cloning required, needs the INFATON_MCP.cfe extension already installed in the base.

This is third-party code. Review the repository files before installing.

What it does

The server installs as a configuration extension (CFE) and starts an HTTP service speaking JSON-RPC 2.0 right inside a 1C base. Tools are grouped by purpose: metadata, reading data, CRUD over catalogs and documents, running arbitrary code and queries, administration (users, event log, locks), integrations and exchanges, batch operations, and accounting and audit (account balances, postings, access rights, duplicate search, print forms). It connects to agents through a Node.js stdio wrapper, index.mjs (via npx or a local run), or directly over HTTP with Basic Auth. It works with ERP 2.5, UPP 1.3, Accounting 3.0, Trade Management 11 and Complex Automation 2 on platform 8.3.20 and newer.

Who it is for. For teams building AI agents and chat interfaces over a live 1C:ERP base who are ready to explicitly restrict the set of available tools.

Good fit when

  • You need a broad set of ready tools for an agent over ERP, Trade Management or Accounting, rather than writing your own from scratch
  • You are ready to create a separate technical 1C user with limited rights for the agent
  • You need work with postings, balances and print forms, not just catalog reads

Not a fit when

  • You cannot restrict agent access with the ONEC_ALLOWED_TOOLS list: without it, execute_code and delete_object stay available
  • You cannot set up HTTPS for the HTTP service: Basic Auth over plain HTTP sends the login and password almost in the clear
  • You only need to view data with no risk of changes to postings and documents

Example request

Show account 41.01 balances and turnover for the first quarter of 2026 via INFATON MCP

Limitations

The README itself calls execute_code, delete_object, run_scheduled_job, import_data, post_document and unpost_document dangerous tools and recommends disallowing them through ONEC_ALLOWED_TOOLS when a scenario does not need them. Basic Auth without HTTPS sends credentials as base64, which is not real protection. There is no built-in granular per-tool authorization inside 1C itself; restriction only works at the server's environment variable level.

How to disable. Remove the INFATON_MCP extension from the 1C base via the Configurator and remove the 1c-erp server from your MCP client config.

MCP

Transport
stdio, http
Authentication
API key
Environment variables
Environment variables
ONEC_URL
required
Address of the extension's HTTP service in the 1C base.
ONEC_USER
required
1C technical user name for Basic Auth.
ONEC_PASSWORD
required, secret
Password for the 1C technical user.
ONEC_ALLOWED_TOOLS
Comma-separated list of allowed tools, used to restrict dangerous operations.

Security check

  • execute_code runs arbitrary BSL code in privileged mode
  • post_document, unpost_document and delete_object change document posting and delete objects
  • import_data and run_scheduled_job can mass-change data or trigger scheduled jobs

README in short

The README describes the repository contents, a version history from 35 to 93 tools, a full tool catalog across eight groups with tables, two quick-start options (npx or direct HTTP), an architecture diagram from the AI assistant to the 1C base, a compatibility table with configurations and platforms, and a separate security section requiring HTTPS, a dedicated technical user, and a list of dangerous tools recommended for restriction.

FAQ

How do you make a read-only configuration?

Set ONEC_ALLOWED_TOOLS to a list of read tools without create_object, update_object, post_document and other mutating operations; an example is in the README.

Does the server need a separate 1C client to run?

No, it runs as the configuration extension's HTTP service, no separate client is launched.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium riskNo VPN needed292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium riskNo VPN needed139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AIINFATON MCP Server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.