Unofficial read-only Planfix MCP server
planfix-mcp
An unofficial Planfix MCP server with 93 read operations via the web client interface: tasks, comments, webhooks, integrations
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- The work account's login and password are stored in a plaintext file
- The unofficial web-interface workaround can break on a Planfix update or be flagged as unwanted automation
Install
Manual install
{
"mcpServers": {
"planfix": {
"command": "/abs/path/to/planfix-mcp/.venv/bin/python",
"args": ["/abs/path/to/planfix-mcp/run.py"]
}
}
}README entry for a venv install; there is an alternative block using uv run for uv-based setups.
This is third-party code. Review the repository files before installing.
What it does
The server logs into Planfix through Playwright-driven Chromium, captures the session, and then makes HTTP requests to the same interface the web client uses, rather than the official REST API. It offers 93 read operations across 15 domain areas: tasks, comments, technical logs, webhooks and integrations, employees and more. The author explicitly warns the operations are considered non-mutating but could theoretically have side effects like marking something as read. Login happens automatically on the first request and can take a while; session data is kept only in the process's memory.
Who it is for. For people who need deep audit and analysis of Planfix data, including technical logs and webhooks not exposed by the official REST API.
Good fit when
- You need to trace an incident through a task's status, assignee and comment history
- You need an audit of Planfix configuration changes over a period: who changed what and when
- You need an inventory of integrations and webhooks, flagging duplicates and disabled ones
Not a fit when
- You need to write data into Planfix: the server only reads
- You cannot store a work account's login and password in a plaintext .env: that is exactly how the server keeps them
- Your Planfix version's UI differs a lot from the one the server was tested against: it depends on the web interface, not a stable API
Example request
Build a timeline of changes for task number 123: statuses, assignees, deadlines and commentsLimitations
This is an unofficial project unrelated to Planfix, using the web client's own interface instead of the documented REST API, so functionality depends on the Planfix version and can break on an update. Login and password are stored in a plaintext .env file (chmod 600 is the only protection). Request rate defaults to one per second. The author recommends reviewing the code before use and explicitly disclaims responsibility for possible side effects.
How to disable. Remove the server from your MCP client config and delete the .env file with the credentials.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| PF_DOMAIN required | Planfix account domain, host only, no https://. |
| PF_USERNAME required, secret | Planfix user login, stored in .env in plaintext. |
| PF_PASSWORD required, secret | Planfix user password, stored in .env in plaintext. |
Security check
- The work account's login and password are stored in a plaintext file
- The unofficial web-interface workaround can break on a Planfix update or be flagged as unwanted automation
README in short
The Russian README with an English version warns about the project's unofficial status and possible side effects of non-mutating commands, describes logging in via Chromium then closing the browser and making session-based HTTP requests, gives Python 3.14 and Playwright install instructions, a sample .env with domain, login and password, and config for Cursor and Claude Desktop.
FAQ
Does the server use the official Planfix API?
No, it logs in through Chromium and works over the same interface the web client uses, not the documented REST API.
Can it create or change tasks?
No, the README describes all 93 operations as read-only, though it warns about possible indirect side effects.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail