Multi-tenant Kommo CRM MCP server
Kommo CRM MCP Server (multi-tenant)
A centralized Kommo MCP server for an agency with several client accounts: tokens live on the VPS, the agent finds the account by client_slug
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- A single server holds tokens for several client Kommo accounts at once
- The Antigravity connection method runs JS code fetched live from GitHub, with no version check
Install
Manual install
Deploy dist/bridge/index.mjs from the clarkstamina-max/kommo-mcp repository on your own VPS through Easypanel, set KOMMO_<SLUG>_DOMAIN and KOMMO_<SLUG>_TOKEN for each client, then in Claude Web add a custom connector pointing at your own SSE endpoint like https://your-domain/sse, naming client_slug on every Kommo tool call.
This is third-party code. Review the repository files before installing.
What it does
The server runs as a single instance on a VPS and serves several Kommo accounts at once instead of just one. Adding a new client needs no restart: an admin sets a KOMMO_<SLUG>_DOMAIN and KOMMO_<SLUG>_TOKEN pair in the VPS environment variables, and the agent then reaches that client through a slug generated from its name. The bundle includes a kommo-expert skill with rules for a specific agency's workflow, requiring the client_slug to be given explicitly on every tool call so accounts do not get mixed up. Connecting to the server's SSE endpoint is documented for Claude Web through its connectors menu, and separately for the Antigravity environment.
Who it is for. For agencies and freelancers running Kommo for several clients at once who want one server instead of a separate install per client.
Good fit when
- You run several client Kommo accounts and want one shared server instead of one install per client
- You are ready to run your own VPS and add client tokens through environment variables
- You want a ready skill enforcing the rule that every call must name the client
Not a fit when
- You have a single Kommo account, and multi-tenancy would only add complexity
- You are not ready to run your own VPS with Easypanel or an equivalent
Example request
Show overdue tasks for the cliente_alfa client in KommoLimitations
The README is written for one specific agency with a placeholder domain, agencia-exemplo.com; running your own instance means rewriting that address and standing up your own VPS. One of the documented connection methods has the agent run code that fetches and executes the dist/bridge/index.mjs file live from the main branch of GitHub, with no version pin or checksum: convenient, but it means every update to the author's branch instantly changes code running for all clients, so pinning a version is worth considering before production use. The admin panel is only documented for Easypanel.
How to disable. Remove the SSE server address from Claude Web connectors or your MCP client config; on the VPS side, stop the service in Easypanel.
MCP
- Transport
- sse
- Authentication
- API key
| Environment variables | |
|---|---|
| KOMMO_<SLUG>_DOMAIN required | A specific client's Kommo account domain, e.g. clientea.kommo.com |
| KOMMO_<SLUG>_TOKEN required, secret | The client's long-lived token, matching the same slug |
Security check
- A single server holds tokens for several client Kommo accounts at once
- The Antigravity connection method runs JS code fetched live from GitHub, with no version check
README in short
The Portuguese README describes the server as centralized for an agency with multi-tenancy through VPS environment variables, gives two ways for the team's AI to connect: a ready config snippet for Antigravity with a live GitHub code fetch, and Claude Web's connectors menu with a direct SSE address, plus admin steps for adding a new client in Easypanel via KOMMO_<SLUG>_DOMAIN and KOMMO_<SLUG>_TOKEN variables.
FAQ
Do I need to restart the server when adding a client?
No, the README states that after saving the environment variables and deploying in Easypanel, the agent can reach the new client_slug right away.
Is the live code-fetch connection method safe?
The README describes that method for the Antigravity environment, but it runs code with no version pin; for production, connecting directly via a fixed SSE URL is the safer option.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail