RiserFlow
A self-hosted MCP backend for AI shopping in your own store: catalog, cart, orders and Bitrix export
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Creates real orders in the store and exports them to Bitrix
- Stores and encrypts customer personal data, including profile and preferences
Install
Manual install
git clone https://github.com/riserlabs/riserflow.git && cd riserflow && npm installThen configure .env, run the Prisma migrations, and start npm run dev along with the order-export worker.
This is third-party code. Review the repository files before installing.
What it does
RiserFlow is a multi-tenant Next.js and Prisma backend that gives an AI agent (ChatGPT, Claude, OpenClaw or a custom bot) access to your own online store instead of Amazon or another marketplace. Through MCP endpoints an agent searches products (with vector search via pgvector), builds and changes a cart, works with a customer profile and preference memory, and creates real orders. A Bitrix integration module syncs the catalog and exports orders through a BullMQ queue with idempotent order creation via an idempotencyKey. Personal data is encrypted with AES-256-GCM, HMAC fingerprints are used for matching, logs mask sensitive fields, and every endpoint checks an x-mcp-token with a timing-safe comparison. It ships a ready OpenClaw extension with provider and route configuration.
Who it is for. For Bitrix-based store owners who want AI agents to place real orders in their own catalog rather than through third-party marketplaces.
Good fit when
- You need your own MCP backend for shopping in your store, not a third-party marketplace
- You need order export to Bitrix with idempotency and a queue
- You need customer PII protection when an AI agent handles orders
Not a fit when
- You lack resources to run PostgreSQL with pgvector, Redis and a BullMQ queue
- You need a ready integration without your own infrastructure: this is a self-hosted backend, not a cloud service
- Your store is not on Bitrix, and no other CMS adapters exist yet
Example request
Find a black t-shirt in my size in the store catalog, add it to the cart and place the orderLimitations
Requires a full deployment: PostgreSQL 14+ with the pgvector extension, Redis, Prisma migrations and a queue worker for order export. Right now there is only a Bitrix adapter; the README lists other adapters as coming. The repository's committed tree includes a node_modules folder, which bloats the clone.
How to disable. Stop the npm run dev process and the order-export worker, and remove the deployed database and Redis queue.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| MCP_SERVER_TOKEN required, secret | The token that guards every MCP endpoint via the x-mcp-token header |
| BITRIX_BASE_URL required | The Bitrix portal address for catalog and order integration |
| BITRIX_MCP_TOKEN required, secret | The Bitrix access token used for order export |
| PII_AES_KEY_B64 required, secret | The AES-256 key for encrypting personal data in production |
| PII_HMAC_KEY required, secret | The HMAC key for deterministic PII fingerprints |
Security check
- Creates real orders in the store and exports them to Bitrix
- Stores and encrypts customer personal data, including profile and preferences
README in short
The README describes RiserFlow as an open-source MCP server and OpenClaw skill connecting AI agents to a store's own backend instead of marketplaces. It lists key features (multi-tenancy, idempotent orders, PII protection, vector search), the stack (Next.js 16, Prisma 7.5, PostgreSQL, BullMQ, Redis), the project structure, the list of MCP endpoints, a step-by-step Quick Start with environment variables, an example OpenClaw plugin config, and a security section covering encryption and token checks. Apache-2.0 license.
FAQ
Do orders really land in Bitrix?
Yes, the integration module exports orders through a BullMQ queue; the README shows a demo where an order appears in Bitrix after a chat purchase.
How is customer PII protected?
AES-256-GCM encryption at rest, HMAC fingerprints for matching without storing plaintext, log masking, and optional PII redaction after order export.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail