amoCRM MCP with protection against destructive writes
Я Мебель — amoCRM MCP
An amoCRM API v4 connector with two-tier write protection: edits behind a WRITE_ENABLED flag, deletions need a separate flag plus confirm=true
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- With WRITE_ENABLED=true the agent can create and edit deals, contacts, tasks and files
- With DANGEROUS_WRITE_ENABLED on, the agent can delete records, though only with explicit confirm on each call
Install
Manual install
uvicorn server:app --host 0.0.0.0 --port $PORT --proxy-headers --forwarded-allow-ips="*"The start command, already set in render.yaml.
This is third-party code. Review the repository files before installing.
What it does
The server deploys to Render and gives an agent broad coverage of the amoCRM API v4: account diagnostics, deals with listing, search, a card view, creation and batch operations, contacts and companies, tasks, notes, entity links, custom fields, tags, webhooks, sources, catalogs, customers, unsorted leads, and files with uploads through the official chunked API. Generic amo_api_get, amo_api_post, amo_api_patch and amo_api_delete tools cover rare v4 endpoints without a dedicated function. Writes are only allowed with WRITE_ENABLED=true, and deletion and other destructive actions additionally require DANGEROUS_WRITE_ENABLED=true on the server plus an explicit confirm=true on that specific tool call.
Who it is for. For teams on ChatGPT or another MCP client who want broad amoCRM access but with explicit safeguards against accidental deletion or bulk edits.
Good fit when
- You need broad amoCRM API v4 coverage, including files, catalogs and webhooks, not just basic deals and contacts
- Protection against accidental deletion matters: two independent flags plus confirm on every dangerous call
- You are setting up attribution tracking and need to check fields like metrika_client_id, yclid and UTM tags in lead cards
Not a fit when
- You only use Kommo, the international version without .amocrm.ru domains
- You are not ready to manage environment variables on Render and want to work without a cloud deploy
Example request
Check the connection with amo_health_check, then find duplicate deals for one lead and show their UTM tagsLimitations
Deployment targets Render specifically; the README does not describe other hosting options. Initial setup requires approval of a private integration in amoMarket, which takes time. The project was originally built for a specific company, Я Мебель, but the code is parameterized through environment variables and works for any amoCRM account.
How to disable. Disconnect the connector in ChatGPT or your MCP client settings and stop the service on Render.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| AMOCRM_BASE_URL required | amoCRM account address in the form https://subdomain.amocrm.ru |
| AMOCRM_ACCESS_TOKEN required, secret | amoCRM private integration long-lived token |
| MCP_SECRET required, secret | Secret for the Authorization header when a client connects to /mcp |
| WRITE_ENABLED | Allows ordinary writes: creating and editing entities |
| DANGEROUS_WRITE_ENABLED | Together with confirm=true on a call, allows deletion and other destructive operations; defaults to false |
Security check
- With WRITE_ENABLED=true the agent can create and edit deals, contacts, tasks and files
- With DANGEROUS_WRITE_ENABLED on, the agent can delete records, though only with explicit confirm on each call
README in short
The README describes the ChatGPT-through-MCP-on-Render architecture to the amoCRM API v4, lists tool groups by entity, explains the two-tier write protection, gives steps for creating a private integration in amoMarket, environment variables for Render, a safe read-only first check sequence, and a separate section on setting up attribution tracking with metrika_client_id, yclid and UTM fields.
FAQ
How do I enable deleting deals?
You need both DANGEROUS_WRITE_ENABLED=true on the server and confirm=true in the tool call itself; both are disabled by default.
Does this work with Kommo?
The README targets amoCRM with an .amocrm.ru domain; Kommo needs a different server.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail