Read-only MCP server for 1C-Bitrix
MCP-сервер для 1С-Битрикс (только чтение)
A 1C-Bitrix module with 35 read-only MCP tools: catalog, orders, reports, code files and SQL, with per-group access rights
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- With the orders and forms groups enabled, it reads customer personal data: name, phone, address
- The sql and files groups, once enabled, allow access to arbitrary database tables and the site's source code
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/mcp-server-dlya-1s-bitriks-tolko-chtenieDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run in a terminal
claude mcp add --transport http bitrix 'https://САЙТ/mcp/' --header 'Authorization: Bearer <your AUTHORIZATION>'Or add to the file .mcp.json, in the project
{
"mcpServers": {
"bitrix": {
"type": "http",
"url": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"bitrix": {
"url": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Run in a terminal
code --add-mcp '{"name":"bitrix","type":"http","url":"https://САЙТ/mcp/","headers":{"Authorization":"Bearer <your AUTHORIZATION>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"bitrix": {
"type": "http",
"url": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.codex/config.toml, for all projects
[mcp_servers.bitrix]
url = "https://САЙТ/mcp/"
http_headers = { Authorization = "Bearer <your AUTHORIZATION>" }If the file already exists, append the block to the end.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"bitrix": {
"httpUrl": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"bitrix": {
"serverUrl": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"bitrix": {
"type": "streamableHttp",
"url": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"bitrix": {
"type": "streamable-http",
"url": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"bitrix": {
"type": "remote",
"url": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"bitrix": {
"url": "https://САЙТ/mcp/",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Clone shelezyaka/bitrix-mcp into local/modules/itb.mcp with web-server ownership, install the module via Marketplace, Installed Solutions, issue a token on the Tokens tab, and connect with claude mcp add --transport http bitrix https://SITE/mcp/ --header "Authorization: Bearer YOUR_TOKEN".
Other ways from the author
git clone https://github.com/shelezyaka/bitrix-mcp.git local/modules/itb.mcpClone under the web server user (chown www-data or bitrix), then install the module via the admin Marketplace, Installed Solutions.
This is third-party code. Review the repository files before installing.
What it does
This installable 1C-Bitrix module runs an MCP server over Streamable HTTP at a separate entry point, /mcp/index.php, without hooking into storefront page handlers. The code has no database write command at all, only SELECT. Tools are split into eight groups, each toggled separately in module settings and granted separately per token: catalog (product search and cards, prices, per-warehouse stock), orders (search, cards, statuses, stats, customers, discounts), reports (sales, top products, abandoned carts, slow movers, stock shortages, zero-result search phrases), form submissions, API introspection of the install itself (classes, methods, source, events, agents, highload blocks), code file reading with hard folder and extension boundaries, and arbitrary SELECT against the database, with tables containing passwords, keys and payment-gateway credentials closed off by column name from the schema rather than a hardcoded list. A token is shown once at issue, rights are granted by explicitly enabling a group per token, and every request is logged, including rejected ones.
Who it is for. For boxed 1C-Bitrix store owners who want a safe, read-only AI agent view into their catalog, orders and reports with no risk of breaking anything.
Good fit when
- You need safe agent access to the catalog, prices and stock with no write risk
- You need reports on sales, top products, abandoned carts and stock shortages
- You need to introspect your own install's code: classes, methods, event handlers, agents
Not a fit when
- You need the agent to write data: the module is physically incapable of writing to the database
- Your portal is cloud Bitrix24, not a boxed 1C-Bitrix site with the iblock module
- You have no admin ready to carefully configure iblock whitelists and permission groups
Example request
Show products with less stock than a week of sales needs, and what visitors searched for but did not findLimitations
Requires 1C-Bitrix 22 or newer, PHP 8.2+ and the iblock module; field-tested on Bitrix 26.650.0 and PHP 8.5. Orders, reports, forms, files and SQL are disabled by default and must be deliberately opened by an admin. The sql and files groups, once enabled, allow arbitrary reading of site code and tables, so the README explicitly warns against opening them unless needed. The local/modules/ folder is reachable over HTTP unlike bitrix/modules/, so it needs a separate web server rule to block it.
How to disable. Revoke all tokens on the Tokens tab and remove the module via Marketplace, Installed Solutions.
MCP
- Transport
- http
- Authentication
- API key
Security check
- With the orders and forms groups enabled, it reads customer personal data: name, phone, address
- The sql and files groups, once enabled, allow access to arbitrary database tables and the site's source code
README in short
The detailed README explains how it differs from ready-made solutions (a separate entry point rather than an OnProlog handler, an iblock whitelist, a token shown only once), step-by-step install into local/modules/itb.mcp with a warning about the folder being reachable over HTTP, token and per-group permission setup, a full list of 35 tools across eight groups with examples of what each returns and its PII warnings, file-read and SQL boundaries in an allowed-versus-forbidden table, two catalog read engines (legacy and ORM) with speed measurements, ready prompt scenarios, and a list of Bitrix-independent tests. MIT license.
FAQ
Can the module change anything on the site?
No, there is no write command in the code at all, the only database instruction the module can send is SELECT.
How does the module protect passwords and keys in the SQL group?
It closes any table whose database schema has a column named like PASSWORD, SECRET, API_KEY or ACCESS_TOKEN rather than relying on a hardcoded list, and additionally closes system tables like b_user and b_option.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail