Bitrix24 MCP with two access tiers
bitrix24-mcp
A Bitrix24 MCP server with two separate endpoints: full admin access and a restricted staff tier gated by guard.cjs
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- The admin endpoint can call any Bitrix24 method without limits
- The generic bitrix_call gives direct REST API access
- Secrets are passed in a header or URL with no rotation
Install
Manual install
npm install && node index.jsBefore running, set BITRIX_WEBHOOK_URL, BITRIX_ADMIN_WEBHOOK_URL and MCP_SHARED_SECRET in the environment.
This is third-party code. Review the repository files before installing.
What it does
Built on Express and the official Model Context Protocol SDK, the server exposes two endpoints over one tool set. /mcp uses a personal admin webhook and calls Bitrix24 directly, while /mcp-staff goes through a separate webhook and is checked by guard.cjs, which allows or rejects a method by policy. Tools cover CRM deals (list, get, create) and a generic bitrix_call for any REST API method, and for staff the tool descriptions state what is actually allowed rather than promising unlimited access. The secret is passed via an X-MCP-Secret header or a key query parameter, since the Claude connector cannot always send arbitrary headers.
Who it is for. For a Bitrix24 portal owner who wants full MCP access for themselves and a restricted operation set for staff.
Good fit when
- You want to split agent access: full for yourself, restricted for the team
- You need a generic bitrix_call for methods without a dedicated tool
- Your agent connector cannot send custom headers, so you need query-parameter auth
Not a fit when
- You need detailed docs: the repo has no README, and behavior is visible only in the code
- You want a ready CRM tool set without deploying your own server
- You need a documented guard.cjs policy that states exactly which methods it allows
Example request
Show open deals and create a new one for contact IvanovLimitations
The repository has no README; this description was written by reading index.js, guard.cjs and public/index.html. There is no license or tests, a single author, and no stars. The guard.cjs staff policy is not documented separately and should be read in the code before relying on it with real staff.
How to disable. Stop the service and remove the server block from your MCP client config.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| BITRIX_WEBHOOK_URL required, secret | Webhook for the staff tier, used through guard.cjs |
| BITRIX_ADMIN_WEBHOOK_URL required, secret | Personal admin webhook with full rights for /mcp |
| MCP_SHARED_SECRET required, secret | Secret for authorizing the personal /mcp endpoint |
| MCP_STAFF_SHARED_SECRET secret | Separate secret for the /mcp-staff endpoint |
Security check
- The admin endpoint can call any Bitrix24 method without limits
- The generic bitrix_call gives direct REST API access
- Secrets are passed in a header or URL with no rotation
README in short
There is no separate README. The index.js code shows two endpoints with different access models, with Russian comments explaining each environment variable and both ways to pass the secret. package.json describes the project as an MCP server connecting Claude to Bitrix24 via a two-way webhook.
FAQ
How does /mcp differ from /mcp-staff?
/mcp calls Bitrix24 directly with the full admin webhook, while /mcp-staff goes through guard.cjs, which checks the method against a policy before calling it.
How do I pass the secret if my connector cannot send headers?
Add it as a ?key=<secret> query parameter on the endpoint URL.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail