Skip to main content
Glama
RCS-kz
by RCS-kz

bitrix24-mcp

Production-grade MCP server for Bitrix24 Cloud — 55 tools, safe by default.

Профессиональный MCP-сервер для Bitrix24 — 55 инструментов, безопасно по умолчанию.

Русский · English · Install · Docs · Buy

This repository is the public front of a commercial product. It contains the README you're reading, install guides, changelogs, the published threat model, and our security-disclosure policy. Source code is proprietary and ships as a signed V8-bytecode bundle through the channels listed under Install. See NOTICE.md for the rationale.


🇷🇺 Русский

Что это

bitrix24-mcp — сервер Model Context Protocol, подключающий Claude Desktop к вашему облачному Bitrix24. Один раз устанавливаете, авторизуете через входящий вебхук Bitrix24 (или OAuth-приложение Bitrix24.Market) — Claude получает 55 инструментов по CRM (контакты, компании, сделки, лиды, товары), Задачам, Пользователям, Мессенджеру и Календарю.

Дальше Claude делает то, что умеет лучше всего — рассуждает над неструктурированными запросами вроде «покажи все сделки больше 50 млн ₸ с просроченной датой закрытия в этом квартале, самые крупные три — отправь email менеджерам и поставь задачу на follow-up» — и вызывает REST API Bitrix24 от вашего имени, с вашим подтверждением.

Почему это существует

Типовые «ИИ-интеграции с CRM» оптимизируют под демо. Мы оптимизируем под тот вечер, когда вы показали это CEO и он сказал «отлично, теперь запусти на реальном tenant'е». Именно здесь rate-лимиты, аудит-логи, обработка ошибок записи и гигиена токенов решают, останется продукт в вашем стеке или нет.

Что внутри

55 инструментов — каждый:

  • Типобезопасен — аргументы валидируются через Zod против строгой JSON-схемы до отправки REST-запроса. Некорректный ввод падает локально с понятной ошибкой, а не мусорным ответом API.

  • Confirm-gated по умолчанию — деструктивные инструменты (*_delete, *_update с массовыми селекторами) декларируют destructive: true в манифесте. Claude Desktop показывает диалог подтверждения.

  • Ограничен по частоте — per-tenant, per-user, per-tool. Массовые операции становятся в очередь с backpressure, а не DDoS-ят ваш Bitrix24.

  • Записывается в аудит-лог — каждый вызов — JSON-строка в ~/.bitrix24-mcp/audit.log (timestamp, инструмент, пользователь, rate-limit remaining, длительность, результат). Локально, права -rw-------.

Покрытие: CRM (контакты / компании / сделки / лиды / товары / активности + cross-type поиск), Задачи (create / assign / stage / comment / attach / time-log), Пользователи (list / get / by-department), IM (chat / DM / recent), Календарь (list / CRUD / respond). Полный справочник — docs/TOOLS.md на landing'е после установки.

Безопасность

  • Webhook / OAuth токены — в keychain ОС (macOS Keychain, Windows Credential Manager, Linux libsecret через keytar). Никогда в конфиг-файле, env или логах.

  • Zero telemetry. Не собираем метрики использования, stack traces, call patterns. Отключать нечего — ничего и не собирается.

  • Декларированный egress. Два хоста видны firewall: *.bitrix24.kz / *.bitrix24.ru / *.bitrix24.com (ваш tenant) и license.rcs.kz (валидация лицензии раз в 24 ч, fail-open после 14-дневного grace).

  • Целостность бандла. Продакшен-бандл — V8-bytecode с SHA-256 fingerprint'ом, проверяемым из 5 независимых check-points. Попытка модификации даёт явный fail.

  • Лицензии на ECDSA P-256. Подпись над tenant-scoped bundle hash + expiry. Украденная лицензия не переносится на другой tenant, срок без приватного ключа RCS не продлевается.

Модель угроз и 10-attack harness — docs/threat-model.md (synced с tests/phase4-7/ATTACK-REPORT.md каждый релиз).

Для кого

  • Клиенты Bitrix24 на Claude Pro / Team / Enterprise, которым надоело переключаться между чатом Claude и CRM.

  • Клиенты RCS (1С:франчайзинг Казахстан) — единый поставщик автоматизаций Bitrix24 поверх уже работающих интеграций 1С.

  • IT / Ops команды, которым нужно согласовать AI-CRM интеграцию и получить внятные ответы про хранение токенов, аудит и rate-лимиты.

Чем это НЕ является

  • Не чат-виджет в Bitrix24. Claude живёт в Claude Desktop (или любом MCP-совместимом клиенте).

  • Не no-code автоматизация. Для визуальных workflow — встроенные автоматизации Bitrix24.

  • Не поддерживает on-premise (коробочный) Bitrix24. Только облако. On-prem — в roadmap, без ETA.

  • Не бесплатный продукт. Мы берём деньги, потому что обновляемся, ведём поддержку и реагируем на изменения REST API Bitrix24 в течение недели. Заброшенный бесплатный инструмент хуже, чем никакой.

Контроль отдела продаж, а не только доступ к CRM

Типовые ИИ-интеграции с Bitrix24 видят карточки и сделки — и на этом заканчиваются. Разговоры с клиентами остаются за кадром: звонки в телефонии, переписка в открытых линиях, заметки менеджеров в таймлайне. А ответ на вопрос «почему сделка не закрылась» живёт именно там.

  • Звонки — сколько сделал и принял каждый менеджер, сколько пропустил, длительность, ссылка на запись разговора.

  • Открытые линии — WhatsApp, Telegram, чат на сайте: переписка с клиентом целиком и время первого ответа.

  • Заметки в CRM — что менеджеры писали по проблемным сделкам, а не только что записано в полях.

  • Отчёт руководителю — собрать сводку и отправить её прямо в чат Bitrix24, а не выгружать в файл.

  • Всё это обычными словами, без конструктора отчётов и без разработки.

Для такого доступа нужны права imopenlines и telephony на стороне портала. Коробочные решения их не запрашивают — поэтому и упираются в потолок на первом же реальном сценарии контроля менеджеров.

Цена

Тариф

Цена

Что входит

Solo

0 ₸, бессрочно

100 вызовов в день · 1 портал · личное использование

Pro

25 900 ₸ / мес

Без лимита вызовов · 3 портала · коммерческое использование · поддержка за сутки · 14 дней пробного периода

Оформить Pro: rcs-kz.lemonsqueezy.com — оплата через Lemon Squeezy (Merchant of Record, карты РФ и РК проходят). Отмена в один клик.

Внутри тарифа — неограниченное число сотрудников портала. Обновления в рамках текущей мажорной версии включены. Поддержка: support@rcs.kz, ответ в течение рабочего дня (Алматы, UTC+5).

Требования

  • Claude Desktop 0.8.0+ (или любой MCP-совместимый клиент)

  • macOS 13+, Windows 10+, либо Linux с libsecret

  • Bitrix24 Cloud tenant с правами администратора (для создания входящего вебхука)

  • Node.js 20 LTS или 22 LTS (только для ручной npm-установки, путь для продвинутых)

Установка

Рекомендуется: скачать .mcpb-бандл с rcs.kz/bitrix24-mcp и установить в Claude Desktop одним кликом. Пошаговая инструкция — docs/install/claude-desktop.md.

Бандл самодостаточен: один файл, ставить Node.js и зависимости не нужно, один и тот же артефакт работает на macOS, Windows и Linux. Ссылку вебхука и лицензионный ключ Claude Desktop спрашивает формой — править claude_desktop_config.json руками не требуется.

Про npm. В реестре сейчас лежит сборка предыдущего поколения — без инструментов по телефонии и открытым линиям. Публикация 2.1.0 готовится; до неё ставьте .mcpb.

Поддержка и SLA

  • Ответ в течение 1 рабочего дня (Пн–Пт, 09:00–18:00 Asia/Almaty, UTC+5).

  • Патч-релизы в течение 5 рабочих дней после воспроизведения бага.

  • Безопасность: security@rcs.kz + PGP-ключ опубликован в SECURITY.md. Ответ в течение 24 часов, фикс в 7 дней, кредит репортеру (если не просил иное).

Вендор

RCS (1С:франчайзинг Казахстан) — алматинский партнёр 1С с 10+ годами работы по enterprise ERP-интеграциям в Казахстане, России, Узбекистане.


Related MCP server: bitrix24-mcp-server

🇬🇧 English

What it is

bitrix24-mcp is a Model Context Protocol server that connects Claude Desktop to a Bitrix24 Cloud tenant. Install once, authorise against a Bitrix24 inbound webhook (or Bitrix24.Market OAuth app) — Claude gains 55 tools spanning CRM (contacts, companies, deals, leads, products), Tasks, Users, Instant Messaging, and Calendar.

Claude then does what Claude does best — reasoning over unstructured requests like "Summarise every deal over 50 M KZT that slipped its close date this quarter, email the three biggest to the account owner, and create a follow-up task for each" — and calls the Bitrix24 REST API on your behalf, with your approval.

Why it exists

Generic "connect AI to CRM" tools optimise for demo-ability. We optimise for the evening after the demo, when rate limits, audit trails, failed-write recovery, and auth-token hygiene decide whether the product stays in your stack.

What's in the box

55 tools, all of them:

  • Type-safe — every argument validated with Zod against a strict JSON schema before the REST call leaves the machine.

  • Confirm-gated by default — destructive tools (*_delete, *_update with mass-selectors) declare destructive: true in the manifest. Compliant clients surface a confirmation dialog.

  • Rate-limited — per-tenant, per-user, per-tool. Bulk imports queue with backpressure instead of DDoS-ing your own Bitrix24.

  • Audit-logged — every call writes a JSON line to ~/.bitrix24-mcp/audit.log with timestamp, tool, caller, rate-limit remaining, duration, result. User-readable only.

Coverage: CRM (contacts, companies, deals, leads, products, activities + cross-type search), Tasks (create, assign, move stages, comment, attach files, log time), Users (list, get, by-department), IM (chat, DM, recent), Calendar (list, CRUD, respond). Exhaustive reference: docs/TOOLS.md on the landing page after install.

Security posture

  • Webhook URL / OAuth tokens in the OS keychain (Keychain / Credential Manager / libsecret via keytar). Never in a config file, never in env vars, never echoed in logs.

  • No telemetry. We do not collect usage metrics, crash reports, or tool-call patterns.

  • Declared network egress. Two hosts, both visible to your firewall: *.bitrix24.{kz,ru,com} (your tenant) and license.rcs.kz (24 h license check, fail-open after a 14-day grace period).

  • Bundle integrity. Production bundle ships as V8 bytecode with SHA-256 fingerprint verified at load time from five independent check-sites.

  • ECDSA-signed licenses. P-256 signature over tenant-scoped bundle hash + expiry. Leaked licenses cannot be retargeted to another tenant.

Full threat model and 10-attack harness: docs/threat-model.md.

Who it's for

  • Bitrix24 customers on Claude Pro / Team / Enterprise who want to stop context-switching between the chat window and the CRM.

  • RCS clients (existing 1С franchise portfolio in Kazakhstan) who want a single trusted vendor for Bitrix24 automation on top of their existing 1С integrations.

  • Ops / IT teams who need to approve an AI-CRM integration and will ask pointed questions about token storage, audit, and rate limiting.

What it is not

  • Not a chat widget embedded inside Bitrix24. Claude lives in Claude Desktop (or any MCP-compatible client).

  • Not a no-code automation tool.

  • Not an on-premise Bitrix24 connector. Cloud tenants only.

  • Not a free tool.

Sales-floor oversight, not just CRM access

Most AI integrations for Bitrix24 can see records and deals, and stop there. The conversations stay invisible: telephony calls, open-line chats with clients, the notes reps leave on a timeline. That is where the answer to "why did this deal stall" actually lives.

  • Calls — how many each rep placed and answered, how many were missed, duration, link to the recording.

  • Open lines — WhatsApp, Telegram, site widget: the full client conversation and time-to-first-response.

  • CRM notes — what reps wrote about stalled deals, not just what the fields say.

  • Report to the head of sales — assemble the digest and post it straight into a Bitrix24 chat.

  • All of it in plain language, with no report builder and no development work.

This requires the imopenlines and telephony scopes on the portal side. Off-the-shelf connectors do not request them — which is why they hit a ceiling on the first real manager-performance scenario.

Pricing

Tier

Price

What you get

Solo

0 ₸ / forever

100 calls/day · 1 portal · personal use only

Pro

25 900 ₸/mo (~$50)

Unlimited · 3 portals · 24h support · commercial use · 14-day trial

🛒 Direct checkout (Pro): rcs-kz.lemonsqueezy.com/checkout/buy/5a8de75c...

🆓 Free Solo activation (5 seconds, no credit card):

curl -X POST https://bitrix24-mcp-license.shahruh.workers.dev/freemium \
  -H "Content-Type: application/json" \
  -d '{"email":"you@company.com","product":"bitrix24-mcp"}'

Subscription via Lemon Squeezy (Merchant of Record — RU/KZ cards work). Cancel anytime in 1 click.

License

This repository is licensed under CC BY-ND 4.0 (documentation) — see LICENSE. The software itself (the npm package, .mcpb bundle, and all related artifacts) is governed by the Commercial EULA; source is proprietary.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivityMaintained
ResponsivenessResponsive

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    A comprehensive MCP server for Bitrix24 CRM integration that enables AI agents to manage contacts, deals, tasks, leads, and companies. It also provides advanced tools for sales team monitoring, performance analytics, and automated CRM search capabilities.
    13
    -
  • A
    license
    B
    quality
    C
    maintenance
    MCP server that gives AI assistants direct access to Bitrix24 portal through an inbound webhook, enabling management of tasks, kanban boards, reports, chats, files, and knowledge base.
    48
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    MCP server for integrating AI assistants with Bitrix24, enabling retrieval and management of CRM entities, tasks, scrum, and knowledge bases through natural language.
    13
    1
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/RCS-kz/bitrix24-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server