Bitrix24 MCP with two access tiers

bitrix24-mcp

A Bitrix24 MCP server with two separate endpoints: full admin access and a restricted staff tier gated by guard.cjs

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • The admin endpoint can call any Bitrix24 method without limits
  • The generic bitrix_call gives direct REST API access
  • Secrets are passed in a header or URL with no rotation
All reasons and checks
Russian stack

labprav-ops/bitrix24-mcp

Install

Manual install

npm install && node index.js

Before running, set BITRIX_WEBHOOK_URL, BITRIX_ADMIN_WEBHOOK_URL and MCP_SHARED_SECRET in the environment.

This is third-party code. Review the repository files before installing.

What it does

Built on Express and the official Model Context Protocol SDK, the server exposes two endpoints over one tool set. /mcp uses a personal admin webhook and calls Bitrix24 directly, while /mcp-staff goes through a separate webhook and is checked by guard.cjs, which allows or rejects a method by policy. Tools cover CRM deals (list, get, create) and a generic bitrix_call for any REST API method, and for staff the tool descriptions state what is actually allowed rather than promising unlimited access. The secret is passed via an X-MCP-Secret header or a key query parameter, since the Claude connector cannot always send arbitrary headers.

Who it is for. For a Bitrix24 portal owner who wants full MCP access for themselves and a restricted operation set for staff.

Good fit when

  • You want to split agent access: full for yourself, restricted for the team
  • You need a generic bitrix_call for methods without a dedicated tool
  • Your agent connector cannot send custom headers, so you need query-parameter auth

Not a fit when

  • You need detailed docs: the repo has no README, and behavior is visible only in the code
  • You want a ready CRM tool set without deploying your own server
  • You need a documented guard.cjs policy that states exactly which methods it allows

Example request

Show open deals and create a new one for contact Ivanov

Limitations

The repository has no README; this description was written by reading index.js, guard.cjs and public/index.html. There is no license or tests, a single author, and no stars. The guard.cjs staff policy is not documented separately and should be read in the code before relying on it with real staff.

How to disable. Stop the service and remove the server block from your MCP client config.

MCP

Transport
http
Authentication
API key
Environment variables
Environment variables
BITRIX_WEBHOOK_URL
required, secret
Webhook for the staff tier, used through guard.cjs
BITRIX_ADMIN_WEBHOOK_URL
required, secret
Personal admin webhook with full rights for /mcp
MCP_SHARED_SECRET
required, secret
Secret for authorizing the personal /mcp endpoint
MCP_STAFF_SHARED_SECRET
secret
Separate secret for the /mcp-staff endpoint

Security check

  • The admin endpoint can call any Bitrix24 method without limits
  • The generic bitrix_call gives direct REST API access
  • Secrets are passed in a header or URL with no rotation

README in short

There is no separate README. The index.js code shows two endpoints with different access models, with Russian comments explaining each environment variable and both ways to pass the secret. package.json describes the project as an MCP server connecting Claude to Bitrix24 via a two-way webhook.

FAQ

How does /mcp differ from /mcp-staff?

/mcp calls Bitrix24 directly with the full admin webhook, while /mcp-staff goes through guard.cjs, which checks the method against a policy before calling it.

How do I pass the secret if my connector cannot send headers?

Add it as a ?key=<secret> query parameter on the endpoint URL.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIBitrix24 MCP with two access tiers

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.