Universal 1C MCP Server (Read-Only)
A strictly read-only MCP server on a 1C HTTP service: 39 tools for metadata, queries, accounting and reports on any configuration
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Exposes accounting balances, journal entries and counterparty/user personal data according to permissions
- The optional get_query_examples tool writes anonymized query templates to the event log when its flag is enabled
Install
Manual install
Create an MCP extension in the Configurator, load the 17 common modules and the MCP_HTTPService HTTP service from src/CommonModules and src/HTTPServices of the Vishez86/1c-mcp-server repo as one atomic set, publish the database on a web server, then connect an MCP client to https://<server>/<base>/hs/mcp/rpc over Streamable HTTP.
This is third-party code. Review the repository files before installing.
What it does
The server implements MCP 2025-11-25 on top of a 1C extension and gives an LLM agent 39 tools that never change persistent data: metadata and event subscription discovery, safe queries with pre-flight field and tabular-section checks before the query engine runs, built-in query-language documentation by platform version, accounting tools (a chart of accounts and subconto map, balances, subconto aging, comparing two balance sets, journal entries), fast item stock balances, reading all register kinds, document movements, data composition schema reports, object history from the event log, a database passport that makes zero data calls, and a registry of allowed legal sources (only pravo.gov.ru, no general web search fallback). Every response carries an authorization context and a non-cacheable flag, the current 1C user's rights and metadata allowlist/denylist apply on every call, and all calls are audited with a correlation_id. The server is not tied to any specific standard configuration: it works on top of UT, ERP, BP and others on platform 8.3.10+.
Who it is for. For 1C teams, finance staff and analysts who need safe read-only agent access to metadata, queries, accounting and reports of any 1C configuration, with no risk of changing data.
Good fit when
- You need read-only agent access to an arbitrary 1C configuration without guessing a specific product's API
- You need accounting balances, turnovers, subconto aging and comparing two balance sets without hand-writing a query
- You need a legal-source access policy that forbids the agent from general web search for legal norms
Not a fit when
- You need to write data: the server is strictly read-only, with a single exception for accumulating anonymized query templates, which is also opt-in and disabled by default
- Your 1C platform is older than 8.3.10: the get_query_examples tool uses ХешированиеДанных and СхемаЗапроса, only available from that version
Example request
Show accounts receivable by counterparty older than 90 days as of end of May on account 62Limitations
Installation is manual: the extension and 17 common modules must be created and loaded in the Configurator following a detailed guide, with no ready installer or .cfe, and the modules must be published atomically as a whole set, or some tools fail with internal_error. Accessing it from cloud clients like Claude web requires publishing the database over HTTPS on the public internet. The repository does not state a code usage license.
How to disable. Disable or remove the MCP extension in the database via the extensions list in the Configurator, and remove the server from the MCP client config.
MCP
- Transport
- http
- Authentication
- API key
Security check
- Exposes accounting balances, journal entries and counterparty/user personal data according to permissions
- The optional get_query_examples tool writes anonymized query templates to the event log when its flag is enabled
README in short
The README gives a table of all 39 tools with their purpose, describes each in detail: parameters, a call example, the output schema and limitations, including a pre-flight rejection of a query before the 1C engine runs, with did_you_mean hints. It separately covers the legal-source policy (only pravo.gov.ru, no general web search), the text_only/structured_only/both response modes, the built-in query-language knowledge base with versioned documentation and a BSL-index generator from markdown sources. It states the minimum platform version 8.3.10 and gives the project structure with the extension's common modules.
FAQ
Can the server change database data?
No, all tools are read-only; the one exception is optionally accumulating anonymized templates of successful queries in the event log, gated by a separate flag and disabled by default.
Does the server work with any 1C configuration?
Yes, it is universal and does not depend on a specific configuration like UT, ERP or BP, but it requires platform 8.3.10 or newer.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything