Pyrus MCP server with access tiers
pyrus-mcp
A Pyrus MCP server built on the official pyrus-api library: 41 API methods and three access tiers that hide disallowed tools
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- In modes above read-only it can create and change tasks in the live Pyrus account
- The security key grants access to all account data within its permissions
Install
Manual install
uvx --from git+https://github.com/brain-boost-academy/pyrus-mcp pyrus-mcpThe consumer install method from the README.
This is third-party code. Review the repository files before installing.
What it does
The server wraps the official pyrus-api library and gives an agent access to all 41 Pyrus API methods over stdio. The key feature: filtering happens when tools are registered, not at request time. If the access mode disallows a method, it is simply absent from the tool list, so the agent cannot call it even by accident. Three tiers are available, from read-only to full control, set by an environment variable at startup.
Who it is for. For teams that care about limiting exactly what an agent can do in Pyrus, rather than relying on its care at runtime.
Good fit when
- You need full coverage of the official Pyrus API methods, not just tasks
- You need to reliably hide dangerous operations from the agent rather than just warn it
- Non-commercial use under the PolyForm Strict license works for you
Not a fit when
- You need commercial use, source modification or redistribution: the PolyForm Strict 1.0.0 license forbids this outside the listed organization categories
- You do not have Python 3.14: the server specifically requires it
Example request
Connect Pyrus in read-only mode and show all my open tasksLimitations
The PolyForm Strict 1.0.0 license only allows non-commercial use with no source modification or redistribution, except for the listed organization categories such as charities, education and government. A different mode requires a separate arrangement with the rights holder. Python 3.14 is required. Installing via uvx --from git+ re-resolves dependencies without consulting uv.lock, so the upper version bounds in pyproject.toml matter.
How to disable. Stop the server process and remove it from your MCP client configuration.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| PYRUS_LOGIN required | The Pyrus login email. |
| PYRUS_SECURITY_KEY required, secret | The Pyrus security key. |
| PYRUS_MCP_MODE | The server's access tier, non-destructive by default. |
Security check
- In modes above read-only it can create and change tasks in the live Pyrus account
- The security key grants access to all account data within its permissions
README in short
The Russian README explains the security model in detail: tools are filtered at registration time rather than at runtime, so a disallowed method is unavailable to the model in principle. It states the PolyForm Strict 1.0.0 license with its list of allowed organization categories, an environment-variable table (PYRUS_LOGIN, PYRUS_SECURITY_KEY, PYRUS_PERSON_ID, PYRUS_ACCESS_TOKEN, PYRUS_MCP_MODE), and a warning about dependency resolution when installing via uvx --from git+.
FAQ
How do I limit the agent to read-only?
Keep the default non-destructive mode or set PYRUS_MCP_MODE explicitly; disallowed methods never appear in tools/list.
Can the server be used in a commercial product?
No, the PolyForm Strict 1.0.0 license forbids that, except for specific non-commercial and government organization categories.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail