kommo-mcp
A self-hosted, dependency-free Node.js MCP server with 41 tools for Kommo (amoCRM): leads, pipelines, tasks, a live conversation queue, and salesbot
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- The token grants Kommo account administrator rights
- Tools create and bulk-update leads and can trigger a salesbot on a lead
Install
Manual install
git clone https://github.com/RonaldoESantosRevOps/kommo-mcp.git
cd kommo-mcp
npm installInstalling dependencies before setting up the token.
This is third-party code. Review the repository files before installing.
What it does
The server wraps Kommo's REST API v4, the international brand for amoCRM, into 41 tools: account, pipelines, users, custom fields, lead/contact/company search, task lists, tags, loss reasons, catalog elements, an event audit log with stages and authors translated to names, a real-time conversation queue, an Inbox, creating and updating leads with tags, bulk updates in slices, tasks and notes, contacts and companies, links, pipeline statuses, webhooks, custom fields, catalog elements, file uploads, triggering a salesbot on a lead, and a generic authenticated passthrough kommo_request restricted to *.kommo.com hosts. Every tool carries MCP readOnlyHint and destructiveHint annotations, so a client can allow reads and block writes at the protocol level.
Who it is for. For sales teams on Kommo or amoCRM who need a self-hosted server with no middlemen and a clear split between reads and writes.
Good fit when
- You want a self-hosted option with no third-party cloud proxy, just your machine talking to the Kommo API
- You need a real-time conversation queue and an Inbox section, not just lead cards
- You want the client to be able to technically block destructive operations via MCP annotations
Not a fit when
- You want a one-click install with no Node.js and no long-lived token of your own
- You are not on Claude Code: the README and examples focus on it, though the server is MCP-standard and works elsewhere
Example request
Show the open conversation queue in Kommo and leads that have not moved in over seven daysLimitations
The README is in Portuguese. The access token grants Kommo account administrator rights and is stored in .env next to the server. It requires Node.js 18 or newer and an account with administrator rights to issue a long-lived token. The kommo_run_salesbot tool triggers a bot on a lead, and the README explicitly asks to confirm this action before calling it.
How to disable. Remove the server with claude mcp remove kommo or delete it from your MCP client config, then delete the .env file with the token.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| KOMMO_SUBDOMAIN required | The Kommo account subdomain, the part of the URL before .kommo.com. |
| KOMMO_TOKEN required, secret | A long-lived private integration token with crm scope and account administrator rights. |
Security check
- The token grants Kommo account administrator rights
- Tools create and bulk-update leads and can trigger a salesbot on a lead
README in short
The Portuguese README lists 41 tools by category (read, audit, service, leads, tasks and notes, contacts and companies, pipelines, webhooks, custom fields, catalog, automation, generic) and a response format with summarized and raw data. It gives instructions for getting a long-lived Kommo token, .env setup, a smoke test checking tool count and annotations, registering in Claude Code at three visibility scopes, and a troubleshooting section.
FAQ
Does this work with the Russian amoCRM?
Yes, Kommo is the international brand of the same platform as amoCRM, and the server uses the same REST API v4.
Can I stop the agent from changing data?
Yes, every tool is tagged readOnlyHint or destructiveHint, and an MCP client can set permissions based on those annotations.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail