Kommo MCP Server for SDR agents
Kommo MCP Server
A multi-tenant Kommo (amoCRM) MCP built on Fastify with confirmation for multi-record operations and pipeline caching
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Tools change leads and add notes and tasks in a real Kommo account
- The composite Bearer token carries access data for several client accounts at once
Install
Manual install
npm install && npm run build && npm startRequires an .env with MCP_PASSWORD, PORT and HOST, copied from .env.example.
This is third-party code. Review the repository files before installing.
What it does
The Fastify-based server exposes seven tools for working with Kommo leads: listing and searching leads, updating a lead, adding notes and tasks, and listing pipelines, stages and custom fields with 10-minute and one-hour caching respectively. A single Bearer token carries three parts at once: the server password, the subdomain and the Kommo access token, so one server can serve different accounts. A separate approval system via MCP sampling asks the user for confirmation when an operation, such as adding a note to a specific person, matches two or more leads.
Who it is for. For agencies serving several Kommo accounts from one server, and for automation scenarios built with n8n.
Good fit when
- You need one server for several Kommo accounts without redeploying it
- You need confirmation before an operation when several records match the request
- The scenario is built in n8n with start-session, update, add-note, end-session steps
Not a fit when
- You need a broad tool set: this one has only seven tools, focused on leads, notes, tasks and reference data
- You need contacts and companies as separate entities: this server operates through leads
Example request
Add a note to the lead Lucas Cardoso about rescheduling the call to tomorrowLimitations
2 stars, last pushed in December 2025. MCP_PASSWORD is mandatory and the server refuses to start without it. The Kommo access token travels as part of the Bearer token on every request rather than being stored in the server's own environment, so the client must supply it.
How to disable. Stop the Fastify server process and remove it from your MCP client configuration.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| MCP_PASSWORD required, secret | The server's mandatory password, the first part of the composite Bearer token. |
| PORT | The HTTP server port, defaults to 3000. |
Security check
- Tools change leads and add notes and tasks in a real Kommo account
- The composite Bearer token carries access data for several client accounts at once
README in short
The Portuguese README describes a multi-tenant Fastify MCP over JSON-RPC 2.0 on HTTP, a mandatory MCP_PASSWORD, the composite Bearer token format, a table of seven tools noting Zod validation, cache lifetimes for pipelines and fields, an n8n usage scenario, and separate USAGE.md and APPROVAL-SYSTEM.md files.
FAQ
How does the server know which Kommo account to use?
From the subdomain encoded in the second part of the request's composite Bearer token.
What if several leads share the same name for an operation?
The server asks for confirmation via MCP sampling before executing; see APPROVAL-SYSTEM.md for details.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail