Bitrix24 for Iva
iva-bitrix24
A read-only Bitrix24 plugin for the Iva agent, with a strict method allowlist and button-confirmed updates
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- Technically cannot create, change or delete Bitrix24 data
- Reads task discussion and employee profiles within the webhook's granted scope
Install
Manual install
curl -fsSL https://raw.githubusercontent.com/mamysh/iva-bitrix24/main/install.sh | bashThe Russian setup wizard, run under the Iva user on a server where Iva already runs.
This is third-party code. Review the repository files before installing.
What it does
The plugin gives the Iva agent thirteen read-only Bitrix24 tools: connection and webhook-scope checks, a task list and card with safe filters and overdue detection, change history, field metadata, task discussion (the new task chat or the legacy comment model), project and people search, departments, attachment metadata without downloads, a checklist and task relations. The REST method name and its parameters are chosen by the plugin's code, not by the model; arbitrary REST API calls are not possible, and the plugin cannot create, change, close or delete tasks. Responses are normalized and trimmed: extra Bitrix24 fields never leak out, and partial pages are explicitly marked. The plugin's own update runs only from a button in a Telegram chat with Iva plus a one-time token, with no commands or SHA to type.
Who it is for. For Iva agent users who want a safe overview of Bitrix24 tasks with no risk of changing or deleting anything.
Good fit when
- You need strictly read-only access to Bitrix24 tasks from Iva, with no write risk
- You need overdue tasks, change history and discussion in one place
- You need a plugin with an explicitly documented security model and method allowlist
Not a fit when
- You need to create, change or close tasks: the current version cannot do that
- You need CRM data (deals, leads, contacts), not just tasks
- You do not use the Iva agent: the plugin is built specifically for it
Example request
Show my overdue Bitrix24 tasks and the latest comments on the oldest oneLimitations
The current release is strictly read-only: Bitrix24 write operations are technically absent. It only works with the Iva agent version 0.4.0 or newer and needs Linux with systemd for the plugin's lifecycle. The project is not an official Bitrix24 product and is not affiliated with it.
How to disable. Remove the plugin with Iva's own command, or revoke the Bitrix24 webhook created for it.
MCP
- Transport
- stdio
- Authentication
- API key
Security check
- Technically cannot create, change or delete Bitrix24 data
- Reads task discussion and employee profiles within the webhook's granted scope
README in short
The README describes in detail the current read-only status, a table of fifteen tools (thirteen Bitrix24 reads plus two or three maintenance tools for updates), an extensive security-boundary section covering the method allowlist, response normalization and corruption handling, requirements (Iva 0.4.0+, Node.js 24 for development, Linux with systemd), three install paths (the setup wizard, iva plugin add, or its own Marketplace), and a development section with npm run check including a secrets scan. MIT license.
FAQ
Can Iva call an arbitrary Bitrix24 REST method?
No, the method name and parameters are hardcoded in the plugin, the model cannot supply its own method or parameters.
How does the plugin update itself?
Only via a confirmation button in the Iva chat after a version and GitHub Actions status check, no SHA or commands to type.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail