Kommo MCP Server
An MCP with 23 tools, resources and prompts for Kommo, amoCRM's international product: deals, contacts, pipelines, Salesbot
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Tools create and change deals, contacts, tasks and can start a Salesbot
- Without MCP_CONFIRM_WRITES, write operations run without extra confirmation
Install
Manual install
git clone https://github.com/Miguelgbastos/Kommo-MCP.git && cd Kommo-MCP && npm install && cp env.example .env && npm run build && npm startQuick start from the README; the server comes up at http://127.0.0.1:3001/mcp.
This is third-party code. Review the repository files before installing.
What it does
The server wraps the Kommo REST API (the international product from the Russian company amoCRM) into a modern MCP: 23 tools for deals, contacts, companies, tasks, pipelines, notes, loss reasons, and starting or stopping a Salesbot, 5 resources such as a sales report and a dashboard, and 4 ready prompts for sales and pipeline analysis. A separate ask_kommo tool takes a natural-language question. It supports both stdio and Streamable HTTP transports, enforces Origin and token checks when not running on localhost, and has an MCP_CONFIRM_WRITES mode that requires an explicit confirm=true before write operations.
Who it is for. For sales teams on Kommo or amoCRM who want a full tool set with protection against accidental write operations.
Good fit when
- You want a ready MCP with CI-tested code and both stdio and HTTP transport
- You need protection against accidental writes: MCP_CONFIRM_WRITES requires confirmation
- You need not just raw CRUD but ready prompts for pipeline and loss-reason analysis
Not a fit when
- You need a ready npm package: at the time of review it was not published yet, only a build from source
- You need to send messages through Kommo: the README states the server does not do this
- You have no Kommo access token, private integration or OAuth2
Example request
Show me last month's sales report and compare pipelines by loss reasonLimitations
14 stars at the time of review, no npm package published yet, and the README and part of the docs are in Portuguese (a separate README.en.md exists). Requires Node.js 22.13 or newer. It does not send messages to customers; for that the README points to a separate community and widget. Outside localhost the server refuses to start without MCP_AUTH_TOKEN.
How to disable. Stop the server process or Docker container and remove the kommo entry from your MCP client configuration.
MCP
- Transport
- stdio, http
- Authentication
- API key
| Environment variables | |
|---|---|
| KOMMO_BASE_URL required | Your Kommo account URL, https://<subdomain>.kommo.com. |
| KOMMO_ACCESS_TOKEN required, secret | Access token from a private integration or OAuth2. |
| MCP_AUTH_TOKEN secret | Protects /mcp; required when the server listens beyond localhost. |
| MCP_CONFIRM_WRITES | Requires confirm=true on tools that change data. |
Security check
- Tools create and change deals, contacts, tasks and can start a Salesbot
- Without MCP_CONFIRM_WRITES, write operations run without extra confirmation
README in short
The README lists 23 tools, 5 resources and 4 prompts, an environment variable table with defaults, setup instructions for Cursor, Claude Desktop and Docker, the health and readiness HTTP endpoints, the project structure, and a troubleshooting section covering common 401, 403, 429 and 503 errors. License is MIT, with CI, CONTRIBUTING.md and SECURITY.md.
FAQ
Can I protect against an accidental bulk edit?
Yes, the MCP_CONFIRM_WRITES=true flag requires confirm=true on write-tool calls.
Does it work with plain amoCRM or only Kommo?
The server targets the Kommo API v4, the same underlying amoCRM product hosted on the kommo.com domain for international customers.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail