{"_id":"@1c-odata/mcp","_rev":"5-48daa300c208273e8274fcee77b9bd5c","name":"@1c-odata/mcp","dist-tags":{"latest":"0.6.0"},"versions":{"0.4.1":{"name":"@1c-odata/mcp","version":"0.4.1","keywords":["1c","1c-enterprise","odata","odata-v3","mcp","model-context-protocol","claude"],"author":{"name":"Pavel Sokolov"},"license":"MIT","_id":"@1c-odata/mcp@0.4.1","maintainers":[{"name":"hacker-cb","email":"pavel@sokolov.me"}],"homepage":"https://github.com/hacker-cb/1c-odata#readme","bugs":{"url":"https://github.com/hacker-cb/1c-odata/issues"},"bin":{"1c-odata-mcp":"dist/cli.js"},"dist":{"shasum":"eb4fafbca261369e1ed929ee244bcc4f04a8dd5d","tarball":"https://registry.npmjs.org/@1c-odata/mcp/-/mcp-0.4.1.tgz","fileCount":14,"integrity":"sha512-mWZ5lEPVA/HVG9YY4kyGBt/WdsEKrYgnzWFYA2nc+yn4vAQrLUeDa8LbjF8fYqZYe7+OOg8V1KbyPILs9SGq+Q==","signatures":[{"sig":"MEUCIQDZUp9hu2fldrZqNX0zwzm8iGL0VY3Y6BPLLsMum+GdLQIgedV/eAhfw2L/gWu37d1tcoBsOJD+7qhTf6wFVWSpoqU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@1c-odata%2fmcp@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":237892},"type":"module","_from":"file:/home/runner/work/_temp/1c-odata-mcp-0.4.1.tgz","engines":{"node":">=22.21.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"build":"tsdown","test:e2e":"echo no e2e in mcp && exit 0","test:unit":"vitest run --exclude \"test/integration/**\" --exclude \"test/e2e/**\"","typecheck":"tsc --noEmit -p tsconfig.json && tsc --noEmit -p tsconfig.test.json","package:lint":"publint && attw --pack . --ignore-rules no-resolution cjs-resolves-to-esm","test:coverage":"vitest run --exclude \"test/integration/**\" --exclude \"test/e2e/**\" --coverage","test:integration:live":"echo no live integration in mcp && exit 0","test:integration:write":"echo no write integration in mcp && exit 0","test:integration:offline":"vitest run test/integration"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0a7f934c-1138-49e8-acc3-af74d8dcfb81"}},"_resolved":"/home/runner/work/_temp/1c-odata-mcp-0.4.1.tgz","_integrity":"sha512-mWZ5lEPVA/HVG9YY4kyGBt/WdsEKrYgnzWFYA2nc+yn4vAQrLUeDa8LbjF8fYqZYe7+OOg8V1KbyPILs9SGq+Q==","repository":{"url":"git+https://github.com/hacker-cb/1c-odata.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.17.0","description":"MCP server for @1c-odata: read-only schema introspection and data queries against 1С:Enterprise OData V3 bases.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.3","dependencies":{"zod":"^4.4.3","commander":"^15.0.0","@1c-odata/client":"0.4.1","@1c-odata/metadata":"0.4.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"optionalDependencies":{"@napi-rs/keyring":"^1.3.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.4.1_1781600062630_0.09727190920702777","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@1c-odata/mcp","version":"0.5.0","keywords":["1c","1c-enterprise","odata","odata-v3","mcp","model-context-protocol","claude"],"author":{"name":"Pavel Sokolov"},"license":"MIT","_id":"@1c-odata/mcp@0.5.0","maintainers":[{"name":"hacker-cb","email":"pavel@sokolov.me"}],"homepage":"https://github.com/hacker-cb/1c-odata#readme","bugs":{"url":"https://github.com/hacker-cb/1c-odata/issues"},"bin":{"1c-odata-mcp":"dist/cli.js"},"dist":{"shasum":"e578f5ed55455139366c3cab3a3b9b1480e4c457","tarball":"https://registry.npmjs.org/@1c-odata/mcp/-/mcp-0.5.0.tgz","fileCount":14,"integrity":"sha512-JOO7lBq9PlVZBR8eHbCl2b2Koom0x4I0KYxPaYn800R1tB0H/Fx8cfFLhe84Qolcl09vYtC9LMImyhtgrzp+oQ==","signatures":[{"sig":"MEYCIQCrxBfPgUD/1OfHGnWSeY26bVzrtFm8d1ie9DpOJwX4FAIhANR8xdMhxdP2uvaVGjqPuJLMJ8yGCeQl3yJk2uL+zqsc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@1c-odata%2fmcp@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":247317},"type":"module","_from":"file:/home/runner/work/_temp/1c-odata-mcp-0.5.0.tgz","engines":{"node":">=22.21.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"build":"tsdown","test:e2e":"echo no e2e in mcp && exit 0","test:unit":"vitest run --exclude \"test/integration/**\" --exclude \"test/e2e/**\"","typecheck":"tsc --noEmit -p tsconfig.json && tsc --noEmit -p tsconfig.test.json","package:lint":"publint && attw --pack . --ignore-rules no-resolution cjs-resolves-to-esm","test:coverage":"vitest run --exclude \"test/integration/**\" --exclude \"test/e2e/**\" --coverage","test:integration:live":"echo no live integration in mcp && exit 0","test:integration:write":"echo no write integration in mcp && exit 0","test:integration:offline":"vitest run test/integration"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0a7f934c-1138-49e8-acc3-af74d8dcfb81"}},"_resolved":"/home/runner/work/_temp/1c-odata-mcp-0.5.0.tgz","_integrity":"sha512-JOO7lBq9PlVZBR8eHbCl2b2Koom0x4I0KYxPaYn800R1tB0H/Fx8cfFLhe84Qolcl09vYtC9LMImyhtgrzp+oQ==","repository":{"url":"git+https://github.com/hacker-cb/1c-odata.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.17.0","description":"MCP server for @1c-odata: read-only schema introspection and data queries against 1С:Enterprise OData V3 bases.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.3","dependencies":{"zod":"^4.4.3","commander":"^15.0.0","@1c-odata/client":"0.5.0","@1c-odata/metadata":"0.5.0","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"optionalDependencies":{"@napi-rs/keyring":"^1.3.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.5.0_1781903344107_0.9672668046731314","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@1c-odata/mcp","version":"0.6.0","description":"MCP server for @1c-odata: read-only schema introspection and data queries against 1С:Enterprise OData V3 bases.","keywords":["1c","1c-enterprise","odata","odata-v3","mcp","model-context-protocol","claude"],"author":{"name":"Pavel Sokolov"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/hacker-cb/1c-odata.git","directory":"packages/mcp"},"homepage":"https://github.com/hacker-cb/1c-odata#readme","bugs":{"url":"https://github.com/hacker-cb/1c-odata/issues"},"type":"module","bin":{"1c-odata-mcp":"dist/cli.js"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"sideEffects":false,"engines":{"node":">=22.21.0"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","commander":"^15.0.0","zod":"^4.4.3","@1c-odata/client":"0.6.0","@1c-odata/metadata":"0.6.0"},"publishConfig":{"access":"public","provenance":true},"optionalDependencies":{"@napi-rs/keyring":"^1.3.0"},"scripts":{"build":"tsdown","typecheck":"tsc --noEmit -p tsconfig.json && tsc --noEmit -p tsconfig.test.json","test:unit":"vitest run --exclude \"test/integration/**\" --exclude \"test/e2e/**\"","test:coverage":"vitest run --exclude \"test/integration/**\" --exclude \"test/e2e/**\" --coverage","test:integration:offline":"vitest run test/integration","test:integration:live":"echo no live integration in mcp && exit 0","test:integration:write":"echo no write integration in mcp && exit 0","test:e2e":"echo no e2e in mcp && exit 0","package:lint":"publint && attw --pack . --ignore-rules no-resolution cjs-resolves-to-esm"},"_id":"@1c-odata/mcp@0.6.0","_integrity":"sha512-ZMLxlCENz5q1I7EUULoiRDiVKl2OoZppjUADXlTmQVHBZveGjTUFpv/M0367jw6vMqFUNHuAn08ARrnnaXIrYw==","_resolved":"/home/runner/work/_temp/1c-odata-mcp-0.6.0.tgz","_from":"file:/home/runner/work/_temp/1c-odata-mcp-0.6.0.tgz","_nodeVersion":"22.23.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-ZMLxlCENz5q1I7EUULoiRDiVKl2OoZppjUADXlTmQVHBZveGjTUFpv/M0367jw6vMqFUNHuAn08ARrnnaXIrYw==","shasum":"c4bc7947e28c2ad5903be470ea8e87617712172b","tarball":"https://registry.npmjs.org/@1c-odata/mcp/-/mcp-0.6.0.tgz","fileCount":14,"unpackedSize":300878,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@1c-odata%2fmcp@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDqT2SIYaR/360Y8X1q3Rr3tMbPF0dgu8i+dDEUr5UJ9AiEA2tu7DtP/FMzA8Gb06laGTzKcqui1s5m+25H3S8u2bX4="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0a7f934c-1138-49e8-acc3-af74d8dcfb81"}},"directories":{},"maintainers":[{"name":"hacker-cb","email":"pavel@sokolov.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.6.0_1782366625265_0.862599223647591"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-16T07:39:06.143Z","modified":"2026-06-25T05:50:26.141Z","0.4.0":"2026-06-16T07:39:06.414Z","0.4.1":"2026-06-16T08:54:22.744Z","0.5.0":"2026-06-19T21:09:04.252Z","0.6.0":"2026-06-25T05:50:25.468Z"},"bugs":{"url":"https://github.com/hacker-cb/1c-odata/issues"},"author":{"name":"Pavel Sokolov"},"license":"MIT","homepage":"https://github.com/hacker-cb/1c-odata#readme","keywords":["1c","1c-enterprise","odata","odata-v3","mcp","model-context-protocol","claude"],"repository":{"type":"git","url":"git+https://github.com/hacker-cb/1c-odata.git","directory":"packages/mcp"},"description":"MCP server for @1c-odata: read-only schema introspection and data queries against 1С:Enterprise OData V3 bases.","maintainers":[{"name":"hacker-cb","email":"pavel@sokolov.me"}],"readme":"# @1c-odata/mcp\n\nMCP ([Model Context Protocol](https://modelcontextprotocol.io)) server for [1С:Enterprise](https://1c.ru/)\nREST/OData V3 bases, built on [`@1c-odata/client`](../client) and [`@1c-odata/metadata`](../metadata).\n\n**Read-only data access.** It exposes schema introspection and data queries — no create / update / delete of\n1С data. Connections can be managed from the CLI (recommended — the password is typed with no echo) or via the\n`add_connection` / `set_credentials` / `set_label` / `remove_connection` tools. No tool ever returns a stored\npassword.\n\nWorks against any 1С base at runtime via the live `$metadata` (dynamic mode) — no code generation required.\n\n## Tools\n\n| Tool | Purpose |\n|---|---|\n| `server_info` | This server's version, data directory, and connection count. No passwords. |\n| `list_connections` | Configured connections (name, label, base URL, login, timezone, password source). No passwords. |\n| `refresh_metadata` | Drop the cached `$metadata` for a connection and re-download it. |\n| `list_entities` | Entity sets, filtered by kind (catalog / document / register / …) and a name substring. Paginated. |\n| `describe_entity` | One entity: properties (type / nullable / maxLength), keys, navigation properties, value storages, kind. |\n| `list_enums` | Enumeration types and their members. |\n| `query` | Read-only OData query: raw `$filter`, `$select`, `$expand`, `$orderby`, `$top`/`$skip`, optional count. |\n| `get_entity` | Fetch a single entity by `Ref_Key`. |\n| `count` | Count rows matching an optional `$filter`. |\n| `register_query` | Register virtual tables: balance / turnovers / slices / accounting (read-only analytics). |\n| `add_connection` | Add/update a connection (writes config; optional `label` + password; password stored securely, never returned). |\n| `set_credentials` | Change a connection's login and/or password in place (keeps URL/timezone/label; password never returned). |\n| `set_label` | Set or clear a connection's display label (empty clears it → falls back to the name). |\n| `remove_connection` | Remove a connection and delete its stored password. |\n\n## Quick start\n\n### 1. Add a connection (in a terminal)\n\n```console\n$ npx @1c-odata/mcp add my-base\nConnection name: my-base\nBase URL: https://your-1c-host/base/odata/standard.odata/\nLogin: your-user\nPassword: ********            # typed with no echo — never stored in shell history or argv\nServer timezone [Europe/Moscow]: Europe/Moscow\nVerifying connection… OK\n✓ Connection \"my-base\" saved.\n  config:   ~/.config/1c-odata/config.json\n  password: OS keychain\n```\n\nThe installed binary is `1c-odata-mcp` (the name the tool prints in its own hints); the `npx @1c-odata/mcp <cmd>`\nform shown here is the no-install equivalent. Other commands: `list` (no passwords), `remove <name>`,\n`test <name>`, `label <name> [label]` (set/clear the display label), and `set-credentials <name>` (rotate the\nlogin and/or password — e.g. `set-credentials my-base --password-stdin <<<\"$NEW\"`).\n\nNon-interactive (scripts / CI) — pass `--url` to skip the prompts:\n\n```bash\n# password from stdin (not visible in `ps`):\nnpx @1c-odata/mcp add my-base --url https://host/base/odata/standard.odata/ --login user --password-stdin <<<\"$PW\"\n# or store only the non-secret config and supply the password via env at runtime:\nONEC_MY_BASE_PASSWORD=… npx @1c-odata/mcp add my-base --url https://host/base/odata/standard.odata/ --login user\n```\n\nThe interactive `add` (no `--url`) needs a real terminal; in a non-TTY context (CI, an agent) it errors and\npoints you here. An **env-supplied password is verified but not copied to storage** — keep\n`ONEC_<NAME>_PASSWORD` exported in the environment that runs `serve`, not only during `add`.\n\n### 2. Register the server with your MCP client\n\nAdd to your client config — `.mcp.json` (project), `~/.claude.json`, or `claude_desktop_config.json`:\n\n```jsonc\n{\n  \"mcpServers\": {\n    \"1c-odata\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@1c-odata/mcp\", \"serve\"]\n    }\n  }\n}\n```\n\nFor a custom agent that can't reach the OS keychain, ship a predefined data dir and pass each connection's\npassword through the `env` block — reference a variable your shell / secret manager exports rather than a\nliteral secret in a committed file (`${VAR}` expansion is supported by Claude Code; other clients may need the\nvalue inlined or their own secret mechanism):\n\n```jsonc\n{\n  \"mcpServers\": {\n    \"1c-odata\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@1c-odata/mcp\", \"serve\"],\n      \"env\": {\n        \"ONEC_MCP_DATA_DIR\": \"/abs/path/to/agent-data-dir\",\n        \"ONEC_MY_BASE_PASSWORD\": \"${ONEC_MY_BASE_PASSWORD}\"\n      }\n    }\n  }\n}\n```\n\nConnections load lazily — `serve` starts instantly and downloads a base's `$metadata` only on first use, so a\npredefined `config.json` plus `ONEC_<NAME>_PASSWORD` env vars is enough; nothing connects at boot.\n\nThen ask the assistant to `list_connections`, explore the schema, and query data.\n\n## Where data lives\n\nBoth files live in one **agent-independent** data directory, so a connection added once is shared by every\nMCP client (Claude Code, Claude Desktop, Codex, ChatGPT, …) — they all spawn the same `serve` process and\nresolve the same directory. Resolution order (first non-blank wins; the result **must be absolute** — a\nrelative `--data-dir` / `ONEC_MCP_DATA_DIR` is a hard error, not a silent fallback):\n\n1. the `--data-dir <path>` flag,\n2. `$ONEC_MCP_DATA_DIR` (env override — sandboxed / portable / CI),\n3. the per-user default — `~/.config/1c-odata` on macOS **and** Linux (honoring an absolute `$XDG_CONFIG_HOME`)\n   or `%APPDATA%\\1c-odata` on Windows. macOS deliberately uses the XDG `~/.config` path, not\n   `~/Library/Application Support`, for cross-platform / container consistency.\n\n- **`config.json`** — connection descriptors *without* passwords (base URL, login, timezone, optional display\n  label, optional shape). Safe to read / surface to an LLM.\n- **Passwords** — resolved in priority order **env → OS keychain → `credentials.json` (0600)**:\n  - **`ONEC_<NAME>_PASSWORD`** always wins — use it for CI / secret managers / agent configs. The name is the\n    connection name upper-cased with every run of non-`[A-Z0-9]` characters collapsed to a single `_`\n    (leading/trailing `_` stripped): `my-base` → `ONEC_MY_BASE_PASSWORD`, `tvip-trade` →\n    `ONEC_TVIP_TRADE_PASSWORD`, `bp.v3` → `ONEC_BP_V3_PASSWORD`.\n  - **OS keychain** (`@napi-rs/keyring`, an optional dependency) — the entry is namespaced **per data\n    directory**: service `1c-odata:<data-dir basename>:<first 8 hex of sha256(canonical data dir)>`, with the\n    connection name as the account (e.g. service `1c-odata:1c-odata:7149e725`, account `trade`). *Canonical* =\n    the absolute path resolved (`.`/`..` collapsed), lower-cased on Windows. The basename and account are\n    human-readable hints in Keychain Access / Credential Manager; the hash isolates dirs. Two clients on the\n    **same** data dir share the secret; a **different** `--data-dir` / `ONEC_MCP_DATA_DIR` is a separate\n    namespace.\n  - **`credentials.json` (0600)** — the fallback when the keychain is unavailable (headless Linux / CI) or\n    `--insecure-storage` is passed; it lives inside the data dir and is loud about the downgrade. On non-Windows\n    a credentials file with permissions looser than `0600` is **refused on read** (with a `chmod 600` hint) so\n    its plaintext is never loaded.\n\n**Connection names** are an ASCII alias — a letter or digit first, then letters, digits, `-`, `_`\n(`/^[A-Za-z0-9][A-Za-z0-9_-]*$/`); a Cyrillic 1С base name needs such an alias. Because the env-var slug\ncollapses `-` and `_` to the same `_`, two names differing only in `-`/`_` (e.g. `a-b` and `a_b`) would map to\none `ONEC_A_B_PASSWORD` — `add` rejects the colliding second name, so pick a distinct one.\n\n> **Upgrading from ≤ 0.4.x.** Keychain secrets are now namespaced per data directory (see above). A password\n> stored by an earlier version under the old flat `1c-odata` service is **not migrated** and won't be found —\n> `list` reports its source as `none`. Re-add it (`1c-odata-mcp add <name>`) or export `ONEC_<NAME>_PASSWORD`.\n> `config.json`, `credentials.json`, and env passwords are unaffected. Likewise, **moving the data dir**\n> re-hashes the keychain service and orphans keychain-stored secrets — the `credentials.json` file travels with\n> the dir and env passwords are independent, so both survive a move.\n\n## Output size\n\nEvery read tool keeps its result within a byte budget so a large query can't overflow the model's context:\nrow sets are truncated to a usable sample (the response carries `truncated` / `hasMore` and a hint to narrow\nthe request), and an oversized individual field (e.g. a base64 `ValueStorage`) is capped with a marker. One\nrow is always returned even if it alone exceeds the budget, so you still see the shape (narrow with `select`\nor `compact`); `get_entity` instead refuses an over-budget entity and points you to `query` + `$select`. Tune\nit with env vars (all optional):\n\n| Variable | Default | Meaning |\n|---|---|---|\n| `ONEC_MCP_DEFAULT_TOP` | `50` | Page size when a call omits `top`. |\n| `ONEC_MCP_MAX_TOP` | `1000` | Hard ceiling on a call's `top`. |\n| `ONEC_MCP_MAX_BYTES` | `24000` | Per-result byte budget for the returned rows. |\n| `ONEC_MCP_MAX_REGISTER_ROWS` | `100000` | Cap on rows fetched from a register virtual table before client-side paging; beyond it `register_query` returns a `totalCapped` floor. |\n\nPass `compact: true` to `query` / `get_entity` / `register_query` to also drop 1С `*_Type` annotation\ncompanions (and `@odata` noise) and fit more rows per response. Caveat: that also removes composite-type\ndiscriminators such as `Value_Type` / `Ref_Type`, so omit it when you need to know which entity a `*_Key`\nreferences.\n\n## Security\n\n- **No tool ever returns a stored password.** `list_connections` shows only where each password lives.\n- Prefer the CLI for entering a password (no-echo prompt) or the `ONEC_<NAME>_PASSWORD` env var, so the secret\n  never reaches the model's context, the transcript, or `ps`.\n- The MCP `add_connection` / `set_credentials` tools accept an optional `password`, but passing it there places\n  it in the model context/transcript — omit it (and use the CLI/env) unless you accept that trade-off.\n- All tool output and error text is redacted of URL userinfo; `config.json` carries no secrets; the fallback\n  credentials file is `0600` and lives outside the project.\n","readmeFilename":"README.md"}