Read-only MCP server for 1C-Bitrix

MCP-сервер для 1С-Битрикс (только чтение)

A 1C-Bitrix module with 35 read-only MCP tools: catalog, orders, reports, code files and SQL, with per-group access rights

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • With the orders and forms groups enabled, it reads customer personal data: name, phone, address
  • The sql and files groups, once enabled, allow access to arbitrary database tables and the site's source code
All reasons and checks
Russian stack

shelezyaka/bitrix-mcp

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/mcp-server-dlya-1s-bitriks-tolko-chtenie

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run in a terminal

claude mcp add --transport http bitrix 'https://САЙТ/mcp/' --header 'Authorization: Bearer <your AUTHORIZATION>'

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "bitrix": {
      "type": "http",
      "url": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Install in Cursor

The button opens the agent and offers to add the server. If nothing happens, copy the config below.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "bitrix": {
      "url": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Install in VS Code

The button opens the agent and offers to add the server. If nothing happens, copy the config below.

Run in a terminal

code --add-mcp '{"name":"bitrix","type":"http","url":"https://САЙТ/mcp/","headers":{"Authorization":"Bearer <your AUTHORIZATION>"}}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "bitrix": {
      "type": "http",
      "url": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the servers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.codex/config.toml, for all projects

[mcp_servers.bitrix]
url = "https://САЙТ/mcp/"
http_headers = { Authorization = "Bearer <your AUTHORIZATION>" }

If the file already exists, append the block to the end.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "bitrix": {
      "httpUrl": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "bitrix": {
      "serverUrl": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "bitrix": {
      "type": "streamableHttp",
      "url": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "bitrix": {
      "type": "streamable-http",
      "url": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "bitrix": {
      "type": "remote",
      "url": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the mcp key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "bitrix": {
      "url": "https://САЙТ/mcp/",
      "headers": {
        "Authorization": "Bearer <your AUTHORIZATION>"
      }
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Keys and settings

AUTHORIZATIONsecret, required

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Checked against the repository on Sep 25, 2026, commit c40f619.

Text for your agent

Clone shelezyaka/bitrix-mcp into local/modules/itb.mcp with web-server ownership, install the module via Marketplace, Installed Solutions, issue a token on the Tokens tab, and connect with claude mcp add --transport http bitrix https://SITE/mcp/ --header "Authorization: Bearer YOUR_TOKEN".

Other ways from the author
git clone https://github.com/shelezyaka/bitrix-mcp.git local/modules/itb.mcp

Clone under the web server user (chown www-data or bitrix), then install the module via the admin Marketplace, Installed Solutions.

This is third-party code. Review the repository files before installing.

What it does

This installable 1C-Bitrix module runs an MCP server over Streamable HTTP at a separate entry point, /mcp/index.php, without hooking into storefront page handlers. The code has no database write command at all, only SELECT. Tools are split into eight groups, each toggled separately in module settings and granted separately per token: catalog (product search and cards, prices, per-warehouse stock), orders (search, cards, statuses, stats, customers, discounts), reports (sales, top products, abandoned carts, slow movers, stock shortages, zero-result search phrases), form submissions, API introspection of the install itself (classes, methods, source, events, agents, highload blocks), code file reading with hard folder and extension boundaries, and arbitrary SELECT against the database, with tables containing passwords, keys and payment-gateway credentials closed off by column name from the schema rather than a hardcoded list. A token is shown once at issue, rights are granted by explicitly enabling a group per token, and every request is logged, including rejected ones.

Who it is for. For boxed 1C-Bitrix store owners who want a safe, read-only AI agent view into their catalog, orders and reports with no risk of breaking anything.

Good fit when

  • You need safe agent access to the catalog, prices and stock with no write risk
  • You need reports on sales, top products, abandoned carts and stock shortages
  • You need to introspect your own install's code: classes, methods, event handlers, agents

Not a fit when

  • You need the agent to write data: the module is physically incapable of writing to the database
  • Your portal is cloud Bitrix24, not a boxed 1C-Bitrix site with the iblock module
  • You have no admin ready to carefully configure iblock whitelists and permission groups

Example request

Show products with less stock than a week of sales needs, and what visitors searched for but did not find

Limitations

Requires 1C-Bitrix 22 or newer, PHP 8.2+ and the iblock module; field-tested on Bitrix 26.650.0 and PHP 8.5. Orders, reports, forms, files and SQL are disabled by default and must be deliberately opened by an admin. The sql and files groups, once enabled, allow arbitrary reading of site code and tables, so the README explicitly warns against opening them unless needed. The local/modules/ folder is reachable over HTTP unlike bitrix/modules/, so it needs a separate web server rule to block it.

How to disable. Revoke all tokens on the Tokens tab and remove the module via Marketplace, Installed Solutions.

MCP

Transport
http
Authentication
API key

Security check

  • With the orders and forms groups enabled, it reads customer personal data: name, phone, address
  • The sql and files groups, once enabled, allow access to arbitrary database tables and the site's source code

README in short

The detailed README explains how it differs from ready-made solutions (a separate entry point rather than an OnProlog handler, an iblock whitelist, a token shown only once), step-by-step install into local/modules/itb.mcp with a warning about the folder being reachable over HTTP, token and per-group permission setup, a full list of 35 tools across eight groups with examples of what each returns and its PII warnings, file-read and SQL boundaries in an allowed-versus-forbidden table, two catalog read engines (legacy and ORM) with speed measurements, ready prompt scenarios, and a list of Bitrix-independent tests. MIT license.

FAQ

Can the module change anything on the site?

No, there is no write command in the code at all, the only database instruction the module can send is SELECT.

How does the module protect passwords and keys in the SQL group?

It closes any table whose database schema has a column named like PASSWORD, SECRET, API_KEY or ACCESS_TOKEN rather than relying on a hardcoded list, and additionally closes system tables like b_user and b_option.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIRead-only MCP server for 1C-Bitrix

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.