Bitrix24 MCP server with per-employee OAuth

bitrix-mcp-server

A company-wide Bitrix24 MCP server where every employee signs in through their own OAuth, so every agent action is attributed to the actual user

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • The server stores each employee's Bitrix24 OAuth tokens on its own side
  • The tools visible in the code only read data, but the full tool list is not documented in a README
All reasons and checks
Russian stack

smitluka/mcp-server-bitrix24

Install

Manual install

Text for your agent

Deploy the server on your own hosting using the deploy/Caddyfile and deploy/bitrix-mcp.service configs, provision an employee with npm run add-employee, then connect your MCP client with that employee's personal API key.

This is third-party code. Review the repository files before installing.

What it does

The server builds its own OIDC provider on the oidc-provider library on top of Express and ties each employee to a personal API key and their own Bitrix24 OAuth tokens. Unlike a typical MCP server with one shared webhook for the whole company, requests to Bitrix24 here run as a specific employee: an add-employee script provisions a new user and links their account. The visible tools cover searching and getting a lead, plus listing the current employee's own tasks filtered by status with pagination. Code comments call out two real Bitrix24 REST API gotchas: tasks.task.list with no responsible-id filter can return other people's tasks when the token has elevated rights, and without manually paging through results a list silently gets capped at 50 items.

Who it is for. For companies where several employees share one Bitrix24 MCP server and it matters who did what, instead of everyone acting through one shared webhook.

Good fit when

  • You need one Bitrix24 server for the whole team but split by employee rather than a shared webhook
  • Lead search and viewing your own tasks is enough
  • You can deploy the server on your own hosting with Caddy and systemd

Not a fit when

  • You want a simple personal server without deploying an OIDC provider
  • You need deals, contacts, companies or creating records: only leads and task reading are visible in the code

Example request

Find Bitrix24 leads with Stroymarket in the title and show my open tasks

Limitations

There is no README in the repository; this description is based on the code structure. Visible tools are few: lead search and card, and a list of your own tasks, so CRM coverage is noticeably narrower than other Bitrix24 servers in this batch. It needs your own server for deployment: the repository ships a Caddy config and a systemd unit, so the project expects self-hosting rather than a one-command run. There is a single author and no stars.

How to disable. Stop the bitrix-mcp systemd service and remove the server from your MCP client configuration.

MCP

Transport
http
Authentication
OAuth

Security check

  • The server stores each employee's Bitrix24 OAuth tokens on its own side
  • The tools visible in the code only read data, but the full tool list is not documented in a README

README in short

There is no README. Based on package.json and the code structure: the server runs on Express and the MCP SDK, with its own OIDC provider built on oidc-provider and jose for JWT, an employee and token store, HTTP configuration for Caddy and systemd, and lead and task tools with comments noting Bitrix24 REST API pagination and filtering quirks.

FAQ

Are agent actions visible as a specific employee's actions?

Yes, that is the project's point: each employee signs in through their own Bitrix24 OAuth rather than a shared webhook for the whole company.

Is there install documentation?

There is no README, but the repository has a Caddy config, a systemd unit and an add-employee script that together outline the deployment process.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIBitrix24 MCP server with per-employee OAuth

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.