MCP for reading Bitrix24 straight from the database

bitrix_mcp

A read-only MCP server that reads Bitrix24 deals, contacts and companies with SELECT queries against the database, bypassing the REST API

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • The bitrix_query tool runs arbitrary SELECT statements, including against unrelated tables
  • It gives direct access to the structure and data of the live CRM database
All reasons and checks
Russian stack

javohir0913/mcp-sap-bitrix

Install

Manual install

pip install -r requirements.txt

Run inside the bitrix_mcp folder after creating a venv.

This is third-party code. Review the repository files before installing.

What it does

Instead of Bitrix24's usual REST methods, the server sends validated SELECT queries to its MySQL database through a custom query API and a BITRIX_API_KEY. It provides ten tools: connection check, deal list and detail, title search, contact and company lists, stage-by-stage deal statistics, table listing and a specific table's structure, plus a free-form bitrix_query for arbitrary SELECT statements. Every free-text parameter is stripped of quotes, semicolons and comments, and any write statement (INSERT, UPDATE, DELETE, DROP and others) is rejected by the validator. The same repository also holds a separate, similar MCP server for SAP, unrelated to the Russian stack.

Who it is for. For developers who need fast read-only access to Bitrix24 CRM data, bypassing the REST API's limits and restrictions.

Good fit when

  • You need a deal query or report that is awkward to build with REST methods
  • You need to inspect the structure of non-standard CRM tables and fields
  • It matters that the agent can never write anything back

Not a fit when

  • You have no direct access to the portal's MySQL database or a custom query API over it
  • You need to create or change Bitrix24 records: the server only reads
  • You only have a regular webhook, not a separate key for a vetted query API

Example request

Show deals in the NEW stage and calculate statistics across all stages

Limitations

The README is in Uzbek. The server does not use a standard Bitrix24 webhook: it needs your own query API with a BITRIX_API_KEY, which most portals do not have set up. Each query returns at most 500 rows. The read-only restriction is enforced only at the application level; the README does not describe a database-level read-only user.

How to disable. Remove the bitrix_mcp server from your MCP client config and revoke BITRIX_API_KEY on your query API's side.

MCP

Transport
stdio
Authentication
API key
Environment variables
Environment variables
BITRIX_API_KEY
required, secret
Access key for the portal's own query API

Security check

  • The bitrix_query tool runs arbitrary SELECT statements, including against unrelated tables
  • It gives direct access to the structure and data of the live CRM database

README in short

The Uzbek README describes a read-only MCP server over Bitrix24's sitemanager MySQL database: venv-based install, wiring into Claude Code and Claude Desktop, a table of ten tools and security rules (SELECT only, parameter sanitizing, regex-checked table names, the key read only from an environment variable, all diagnostics to stderr). It includes example request phrasings and a troubleshooting section.

FAQ

Can the server change Bitrix24 data?

No, the validator only allows SELECT; every write statement is rejected before the query is sent.

Do I need a regular Bitrix24 webhook?

No, you need access to the portal's separate query API and a BITRIX_API_KEY, not a standard incoming webhook.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIMCP for reading Bitrix24 straight from the database

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.