Bitrix24 Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Bitrix24 Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Production-grade MCP server for Bitrix24 Cloud — 45 tools, safe by default.
>
Профессиональный MCP-сервер для Bitrix24 — 45 инструментов, безопасно по умолчанию.
Русский · English · Install · Docs · Buy
This repository is the public front of a commercial product. It contains the README you're reading, install guides, changelogs, the published threat model, and our security-disclosure policy. Source code is proprietary and ships as a signed V8-bytecode bundle through the channels listed under Install. See NOTICE.md for the rationale.bitrix24-mcp — сервер Model Context Protocol, подключающий Claude Desktop к вашему облачному Bitrix24. Один раз устанавливаете, авторизуете через входящий вебхук Bitrix24 (или OAuth-приложение Bitrix24.Market) — Claude получает 45 инструментов по CRM (контакты, компании, сделки, лиды, товары), Задачам, Пользователям, Мессенджеру и Календарю.
Дальше Claude делает то, что умеет лучше всего — рассуждает над неструктурированными запросами вроде «покажи все сделки больше 50 млн ₸ с просроченной датой закрытия в этом квартале, самые крупные три — отправь email менеджерам и поставь задачу на follow-up» — и вызывает REST API Bitrix24 от вашего имени, с вашим подтверждением.
Типовые «ИИ-интеграции с CRM» оптимизируют под демо. Мы оптимизируем под тот вечер, когда вы показали это CEO и он сказал «отлично, теперь запусти на реальном tenant'е». Именно здесь rate-лимиты, аудит-логи, обработка ошибок записи и гигиена токенов решают, останется продукт в вашем стеке или нет.
45 инструментов — каждый:
*_delete, *_update с массовыми селекторами) декларируют destructive: true в манифесте. Claude Desktop показывает диалог подтверждения.~/.bitrix24-mcp/audit.log (timestamp, инструмент, пользователь, rate-limit remaining, длительность, результат). Локально, права -rw-------.Покрытие: CRM (контакты / компании / сделки / лиды / товары / активности + cross-type поиск), Задачи (create / assign / stage / comment / attach / time-log), Пользователи (list / get / by-department), IM (chat / DM / recent), Календарь (list / CRUD / respond). Полный справочник — docs/TOOLS.md на landing'е после установки.
keytar). Никогда в конфиг-файле, env или логах.*.bitrix24.kz / *.bitrix24.ru / *.bitrix24.com (ваш tenant) и license.rcs.kz (валидация лицензии раз в 24 ч, fail-open после 14-дневного grace).Модель угроз и 10-attack harness — docs/threat-model.md (synced с tests/phase4-7/ATTACK-REPORT.md каждый релиз).
[email protected], SLA 1 рабочий день (Almaty, UTC+5).libsecretРекомендуется: скачать .mcpb-бандл с rcs.kz/bitrix24-mcp и установить в Claude Desktop одним кликом. Пошаговая инструкция — docs/install/claude-desktop.md.
Для продвинутых:
npm install -g @rcs-kz/bitrix24-mcpКонфиг в claude_desktop_config.json описан в install-гайде.
[email protected] + PGP-ключ опубликован в SECURITY.md. Ответ в течение 24 часов, фикс в 7 дней, кредит репортеру (если не просил иное).RCS (1С:франчайзинг Казахстан) — алматинский партнёр 1С с 10+ годами работы по enterprise ERP-интеграциям в Казахстане, России, Узбекистане.
[email protected]bitrix24-mcp is a Model Context Protocol server that connects Claude Desktop to a Bitrix24 Cloud tenant. Install once, authorise against a Bitrix24 inbound webhook (or Bitrix24.Market OAuth app) — Claude gains 45 tools spanning CRM (contacts, companies, deals, leads, products), Tasks, Users, Instant Messaging, and Calendar.
Claude then does what Claude does best — reasoning over unstructured requests like "Summarise every deal over 50 M KZT that slipped its close date this quarter, email the three biggest to the account owner, and create a follow-up task for each" — and calls the Bitrix24 REST API on your behalf, with your approval.
Generic "connect AI to CRM" tools optimise for demo-ability. We optimise for the evening after the demo, when rate limits, audit trails, failed-write recovery, and auth-token hygiene decide whether the product stays in your stack.
45 tools, all of them:
*_delete, *_update with mass-selectors) declare destructive: true in the manifest. Compliant clients surface a confirmation dialog.~/.bitrix24-mcp/audit.log with timestamp, tool, caller, rate-limit remaining, duration, result. User-readable only.Coverage: CRM (contacts, companies, deals, leads, products, activities + cross-type search), Tasks (create, assign, move stages, comment, attach files, log time), Users (list, get, by-department), IM (chat, DM, recent), Calendar (list, CRUD, respond). Exhaustive reference: docs/TOOLS.md on the landing page after install.
keytar). Never in a config file, never in env vars, never echoed in logs.*.bitrix24.{kz,ru,com} (your tenant) and license.rcs.kz (24 h license check, fail-open after a 14-day grace period).Full threat model and 10-attack harness: docs/threat-model.md.
| Tier | Price | What you get |
|---|---|---|
| Solo | 0 ₸ / forever | 100 calls/day · 1 portal · personal use only |
| Pro | 25 900 ₸/mo (~$50) | Unlimited · 3 portals · 24h support · commercial use · 14-day trial |
🛒 Direct checkout (Pro): rcs-kz.lemonsqueezy.com/checkout/buy/5a8de75c...
🆓 Free Solo activation (5 seconds, no credit card):
curl -X POST https://bitrix24-mcp-license.shahruh.workers.dev/freemium \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","product":"bitrix24-mcp"}'Subscription via Lemon Squeezy (Merchant of Record — RU/KZ cards work). Cancel anytime in 1 click.
CHANGELOG.mddocs/threat-model.mdio.github.rcs-kz/bitrix24-mcpThis repository is licensed under CC BY-ND 4.0 (documentation) — see LICENSE. The software itself (the npm package, .mcpb bundle, and all related artifacts) is governed by the Commercial EULA; source is proprietary.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.