Kommo MCP server with token auto-refresh
Kommo MCP Server
A Kommo (amoCRM) MCP server with a ready npm package and automatic access-token refresh
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Tools create and change deals, contacts, companies and tasks in a real account
- Access and refresh tokens are stored in the MCP client configuration
Install
Manual install
npm install -g kommo-mcp-serverThe recommended method from the README.
This is third-party code. Review the repository files before installing.
What it does
The server wraps the Kommo REST API v4 with roughly thirty tools: leads, contacts, companies, tasks, pipelines, users, notes, custom fields, tags, global search and webhooks. A separate create_lead_complex tool creates a lead together with a contact and a company in one request. If a refresh token, client id and client secret are configured, the server refreshes an expired access token automatically with no manual step. On a 429 response from Kommo, the server waits and retries on its own.
Who it is for. For people who want to install a Kommo MCP with one npx command and not track token expiry by hand.
Good fit when
- You want a one-command npx install with no build from source
- Your access token expires and you need automatic refresh via a refresh token
- You need to create complex deals with a contact and company in a single request
Not a fit when
- You need to send messages to customers through Kommo: the README states the server does not do this
- The README's promotional block about a separate community and a free widget is unrelated to the MCP itself and can be ignored
Example request
Create a deal for Big Company Project worth $100,000 with contact John Smith and company Big Company IncLimitations
2 stars. Part of the README promotes the author's separate community in Brazil and a messaging widget, which are unrelated to what the MCP itself does. Kommo rate limits are handled by automatic wait-and-retry, but the README recommends custom batch processing for high volume.
How to disable. Remove the kommo entry from your MCP client configuration, for example claude_desktop_config.json.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| KOMMO_SUBDOMAIN required | Your Kommo account subdomain, e.g. mycompany from mycompany.kommo.com. |
| KOMMO_ACCESS_TOKEN required, secret | Access token from a private integration or OAuth2. |
| KOMMO_REFRESH_TOKEN secret | Refresh token for automatically renewing an expired access token. |
| KOMMO_CLIENT_ID | The integration's client ID, needed alongside the refresh token. |
| KOMMO_CLIENT_SECRET secret | The integration's client secret, needed alongside the refresh token. |
Security check
- Tools create and change deals, contacts, companies and tasks in a real account
- Access and refresh tokens are stored in the MCP client configuration
README in short
The README lists lead, contact, company, task, pipeline, user, note, custom field, tag, search and webhook management, gives npm and source install instructions, Claude Desktop config for macOS and Windows plus Claude Code CLI, natural-language usage examples, and a section on rate limits and token refresh. It also has a promotional block about a separate Brazilian Kommo community unrelated to the server itself.
FAQ
What is needed for automatic token refresh?
Set KOMMO_REFRESH_TOKEN, KOMMO_CLIENT_ID and KOMMO_CLIENT_SECRET in the config alongside the access token.
Can the server send messages to customers?
No, the README explicitly excludes this and points to the author's separate product for it.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail