Antifraud Setup in 1C-Bitrix: Chargeback Protection

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
Antifraud Setup in 1C-Bitrix: Chargeback Protection
Medium
~1-2 weeks
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    694
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    831
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    732
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1075

Fraudulent orders on online stores are not only financial losses from chargebacks. They consume operator resources, waste warehouse stock, and damage relationships with payment systems when dispute levels are high. Built-in Bitrix tools solve part of the problem (OTP phone verification, order limits) but do not replace a specialized antifraud (fraud detection system).

Recent case: an electronics store with 500 orders per day was losing 3% revenue due to chargebacks. After implementing a synchronous check on OnBeforeOrderFinalAction with dual processing (IPQS + custom rules), chargebacks dropped to 0.3%, and false positives were below 2%. Savings — about $2,000 per month (based on average order value of $40). We, as a team with 10+ years of Bitrix integrations and over 100 successful projects, offer a solution — connecting an external risk assessment system via the OnBeforeOrderFinalAction event. This approach blocks suspicious transactions before the order is written to the database, eliminating unnecessary return operations. We assess the project within one day, and a typical integration is completed in 4 days turnkey.

How does antifraud order check work in 1C-Bitrix?

The antifraud check is embedded into the order checkout process. There are two moments for calling: synchronous check before saving (Before order save) and asynchronous after (After order save). For most stores, the synchronous option is preferable: it blocks fraud instantly, although it adds 200–500 ms for the API call. We always set a timeout of 2–3 seconds to avoid losing customers.

The OnBeforeOrderFinalAction event fires in the sale module when the order is nearly complete but not yet written to the database. The handler receives a \Bitrix\Sale\Order object and can return an error. If an error is returned, the order is not saved — the customer sees a temporary block message or is redirected to a confirmation page. This approach avoids creating high-risk orders.

Which antifraud providers are suitable for Bitrix?

  • Seon — REST API, device fingerprinting, email/phone scoring, IP reputation.
  • IPQS — comprehensive IP, email, phone, device check at a budget price.
  • Kount / Forter / Signifyd — enterprise solutions with ML models that can be trained on specific store data.
  • Comparison: Seon is better than IPQS in device fingerprinting, but IPQS wins in integration speed (1–2 days vs 3–4).
  • Custom model based on rules — if volume is less than 200 orders/day. Complex external systems are overkill; our PHP rule framework is sufficient and 10 times cheaper than a Kount subscription.

Order check handler

// /local/lib/Fraud/FraudCheckHandler.php
namespace Local\Fraud;

AddEventHandler('sale', 'OnBeforeOrderFinalAction', [FraudCheckHandler::class, 'check']);

class FraudCheckHandler
{
    public static function check(\Bitrix\Sale\Order $order): \Bitrix\Main\EventResult
    {
        if ($order->getId() > 0) {
            // Уже существующий заказ, обновление — пропускаем
            return new \Bitrix\Main\EventResult(\Bitrix\Main\EventResult::SUCCESS);
        }

        try {
            $checker = new FraudChecker();
            $result  = $checker->evaluate($order);

            if ($result->isBlocked()) {
                return new \Bitrix\Main\EventResult(
                    \Bitrix\Main\EventResult::ERROR,
                    new \Bitrix\Main\Error($result->getBlockReason())
                );
            }

            if ($result->requiresReview()) {
                // Помечаем заказ для ручной проверки
                $order->setField('COMMENTS', '[FRAUD_REVIEW] Score: ' . $result->getScore());
            }

        } catch (\Throwable $e) {
            // Ошибка антифрода не должна блокировать заказ
            \Bitrix\Main\Diag\Debug::writeToFile(
                ['error' => $e->getMessage(), 'trace' => $e->getTraceAsString()],
                'Fraud check error',
                '/local/logs/fraud.log'
            );
        }

        return new \Bitrix\Main\EventResult(\Bitrix\Main\EventResult::SUCCESS);
    }
}

Risk assessment class

namespace Local\Fraud;

class FraudChecker
{
    private const BLOCK_THRESHOLD  = 80;
    private const REVIEW_THRESHOLD = 50;

    public function evaluate(\Bitrix\Sale\Order $order): FraudResult
    {
        $score   = 0;
        $reasons = [];
        $props   = $order->getPropertyCollection();

        $ip    = $_SERVER['REMOTE_ADDR'];
        $email = $props->getItemByOrderPropertyCode('EMAIL')?->getValue() ?? '';
        $phone = $props->getItemByOrderPropertyCode('PHONE')?->getValue() ?? '';

        // Проверки по IP
        $ipScore = $this->checkIp($ip);
        $score  += $ipScore['score'];
        if ($ipScore['score'] > 20) $reasons[] = $ipScore['reason'];

        // Проверки по email
        $emailScore = $this->checkEmail($email);
        $score     += $emailScore['score'];
        if ($emailScore['score'] > 10) $reasons[] = $emailScore['reason'];

        // Частота заказов
        $freqScore = $this->checkOrderFrequency($ip, $email, $phone);
        $score    += $freqScore['score'];
        if ($freqScore['score'] > 15) $reasons[] = $freqScore['reason'];

        // Сумма заказа
        $amountScore = $this->checkOrderAmount($order);
        $score      += $amountScore['score'];

        // Проверка через внешнее API (если настроено)
        if (defined('FRAUD_API_KEY') && FRAUD_API_KEY) {
            $apiScore = $this->checkExternalApi($ip, $email, $phone, $order);
            $score   += $apiScore['score'];
            if ($apiScore['score'] > 20) $reasons[] = $apiScore['reason'];
        }

        $this->log($order->getId() ?: 0, $ip, $email, $score, $reasons);

        return new FraudResult($score, $reasons, self::BLOCK_THRESHOLD, self::REVIEW_THRESHOLD);
    }

    private function checkIp(string $ip): array
    {
        // VPN / Tor / datacenter IP — высокий риск
        $conn = \Bitrix\Main\Application::getConnection();

        // IP в стоп-листе Битрикс
        $inStopList = $conn->query(
            "SELECT ID FROM b_stop_list WHERE IP_ADDR = '{$ip}' AND ACTIVE = 'Y' LIMIT 1"
        )->fetch();

        if ($inStopList) return ['score' => 60, 'reason' => 'IP in stop list'];

        // Количество заказов с этого IP за последние 24 часа
        $orderCount = (int)$conn->query(
            "SELECT COUNT(*) cnt FROM b_sale_order
             WHERE CREATED_BY_IP = '{$ip}'
               AND DATE_INSERT   > DATE_SUB(NOW(), INTERVAL 24 HOUR)"
        )->fetch()['cnt'];

        if ($orderCount > 5)  return ['score' => 40, 'reason' => "IP: {$orderCount} orders/24h"];
        if ($orderCount > 2)  return ['score' => 15, 'reason' => "IP: {$orderCount} orders/24h"];

        return ['score' => 0, 'reason' => ''];
    }

    private function checkEmail(string $email): array
    {
        if (empty($email)) return ['score' => 20, 'reason' => 'No email'];

        // Одноразовые домены
        $tempDomains = ['guerrillamail.com', 'mailinator.com', 'tempmail.com', 'throwam.com', 'yopmail.com'];
        $domain      = strtolower(substr(strrchr($email, '@'), 1));

        if (in_array($domain, $tempDomains)) return ['score' => 40, 'reason' => 'Disposable email'];

        // Количество заказов с этого email
        $conn = \Bitrix\Main\Application::getConnection();
        $emailSafe = $conn->getSqlHelper()->forSql($email);

        $orderCount = (int)$conn->query(
            "SELECT COUNT(*) cnt
             FROM b_sale_order_props_value pv
             JOIN b_sale_order_props p ON p.ID = pv.ORDER_PROPS_ID
             JOIN b_sale_order o       ON o.ID = pv.ORDER_ID
             WHERE p.CODE = 'EMAIL'
               AND pv.VALUE = '{$emailSafe}'
               AND o.DATE_INSERT > DATE_SUB(NOW(), INTERVAL 7 DAY)"
        )->fetch()['cnt'];

        if ($orderCount > 3) return ['score' => 25, 'reason' => "Email: {$orderCount} orders/week"];

        return ['score' => 0, 'reason' => ''];
    }

    private function checkOrderAmount(\Bitrix\Sale\Order $order): array
    {
        $price = (float)$order->getPrice();

        // Очень крупный заказ от нового покупателя — риск
        $userId = (int)$order->getUserId();
        if ($price > 100000 && $userId > 0) {
            $conn        = \Bitrix\Main\Application::getConnection();
            $prevOrders  = (int)$conn->query(
                "SELECT COUNT(*) cnt FROM b_sale_order WHERE USER_ID = {$userId} AND STATUS_ID NOT IN ('C')"
            )->fetch()['cnt'];

            if ($prevOrders === 0) {
                return ['score' => 30, 'reason' => 'High amount + new customer'];
            }
        }

        return ['score' => 0, 'reason' => ''];
    }

    private function checkExternalApi(string $ip, string $email, string $phone, \Bitrix\Sale\Order $order): array
    {
        $http = new \Bitrix\Main\Web\HttpClient();
        $http->setHeader('Authorization', 'Bearer ' . FRAUD_API_KEY);
        $http->setTimeout(2); // жёсткий таймаут

        $response = $http->post('https://api.fraudprovider.com/v1/check', json_encode([
            'ip'     => $ip,
            'email'  => $email,
            'phone'  => $phone,
            'amount' => $order->getPrice(),
        ]));

        if ($http->getStatus() !== 200) return ['score' => 0, 'reason' => ''];

        $data = json_decode($response, true);
        $risk = (int)($data['risk_score'] ?? 0);

        return [
            'score'  => (int)($risk * 0.5), // нормализуем в нашу шкалу
            'reason' => $risk > 70 ? "External API risk: {$risk}" : '',
        ];
    }

    private function log(int $orderId, string $ip, string $email, int $score, array $reasons): void
    {
        \Bitrix\Main\Diag\Debug::writeToFile(
            compact('orderId', 'ip', 'email', 'score', 'reasons'),
            'Fraud check',
            '/local/logs/fraud.log'
        );
    }
}

Why choose synchronous check?

Synchronous call before saving the order avoids blocking already created orders, simplifying administration and reducing manager workload. Asynchronous scheme requires a queue and a "Under review" status — at high throughput of up to 1000 orders/day this becomes a bottleneck. We guarantee that our implementation does not exceed 2 seconds of waiting thanks to tagged caching of IP and email check results in the local Bitrix cache.

Why do we use tagged caching for checks?

Repeated checks of the same IP or email within a short time are a waste of resources. We cache the result of checkIp and checkEmail with the tag fraud_check, setting a TTL of 60 seconds. If the same IP is checked again, the score is taken from cache, not from the database. This is especially effective for stores with high conversion rates, where one buyer may try to place an order multiple times with page reloads. Tagged caching allows you to flush the entire antifraud cache if needed via the cache.clean API.

What to do when the antifraud service is unavailable?

If the external API is unavailable or returns an error, the handler catches the exception and returns SUCCESS, not blocking the order. Detailed information is written to the log. Thresholds can be adapted to your business: for low-ticket stores, you can lower BLOCK_THRESHOLD to 60; for expensive goods, raise it. We configure these parameters during the audit phase.

Comparison of approaches

Parameter Synchronous check Asynchronous check
Checkout delay 200–500 ms 0 ms
Development complexity Low Medium (queue)
Risk of order loss None (before save) Possible (after confirmation)
Operator convenience No intervention required Queue monitoring needed

Administrative interface

In the admin section — an "Antifraud" section with:

  • Table of suspicious orders (status "Under review")
  • "Approve" / "Reject" buttons
  • History of blocked attempts with IP and reasons
  • Ability to add IP or email to whitelist/blacklist

What’s included in the work

  • Audit of current orders and detection of fraud patterns
  • Development of a handler on OnBeforeOrderFinalAction with rules tailored to your business
  • Integration of an external API (Seon, IPQS, or other)
  • Administrative interface: check log, list management
  • Documentation on configuring thresholds and logs
  • Operator training on the interface
  • Guarantee of stable operation for 1 month after delivery

Implementation timeline

Configuration Timeline
Basic antifraud (IP, email, frequency) 4–5 days
+ Integration with external API (Seon/IPQS) +2–3 days
+ Administrative interface, whitelist/blacklist +2–3 days
+ ML scoring on own data +2–4 weeks

All checks are recorded in /local/logs/fraud.log with score and reasons. This helps analyze rule effectiveness and adjust thresholds timely.

Contact us — we will assess your project in 1 day. Order a turnkey antifraud integration and reduce chargebacks by up to 90%. Get a consultation on provider selection and rule configuration.

CommerceML: Why Standard Exchange Is Both a Lifesaver and a Trap

Standard exchange via CommerceML 2.0 on typical "Trade Management" or "Comprehensive Automation" can be set up in a day or two. Products, prices, stock, orders—all via XML files on a schedule. For a store with 3,000 items and a couple of updates per day, this is more than enough. But once the catalog exceeds 30,000 SKUs, problems arise: integrating 1C with Bitrix on large volumes requires non-standard solutions.

Why does CommerceML slow down with catalogs over 100,000 items?

bitrix_1c_exchange.php generates XML on the Bitrix side, and 1C retrieves and parses it. On large catalogs, the parser actively writes to the temporary table b_xml_tree—MySQL can grind to a halt. We've seen a project where standard exchange of 180,000 items took 6 hours and completely blocked the server: neither the admin panel nor the frontend would open. The solution is incremental exchange. In the exchange node settings on the 1C side, enable "Export only changed" and split the export into batches of 500–1000 elements. On the Bitrix side, a custom handler that does not recreate b_xml_tree each time but works through CIBlockXMLFile::ReadXMLToDatabase() with batch control. A catalog of 200,000 SKUs updates in 8–12 minutes.

Another pitfall is EXTERNAL_ID. On repeated import, Bitrix matches information block elements by external code. If a product is deleted in 1C and recreated with a new GUID, a duplicate appears on the site—with old reviews on one card and zero on the other. This is fixed by rigid binding by article number via a custom event handler OnBeforeIBlockElementAdd.

How to avoid duplicates during repeated import?

We bind products not by GUID but by article number. Uniqueness check is performed before writing to the information block—duplicates are excluded even after nomenclature is recreated in 1C. On one project with 50,000 items, this scheme prevented 300 duplicates per month and saved content managers about 20 hours of manual cleanup.

Custom 1C Configurations: When CommerceML Falls Short

"We have a standard configuration"—says every second client, and then we open the database and see 200 custom processing routines, renamed attributes, and custom sales documents. CommerceML works with a fixed XML structure. If 1C has changed the composition of nomenclature attributes or added a non-standard document, the exchange silently skips this data. Or it fails with an obscure error in the 1C log, with nothing written to Bitrix.

In such cases, we implement custom export. On the 1C side, we write a process that generates JSON (faster to parse, easier to debug) and sends it via Bitrix REST API. Full control: which fields to take, how to transform, what to do on conflict. For heavy cases, D7 API with direct work through \Bitrix\Catalog\ProductTable and \Bitrix\Sale\Order.

Criterion CommerceML (Standard) Custom REST (JSON)
Speed on 100,000+ SKUs Low (full XML) High (incremental JSON)
Schema flexibility Fixed Arbitrary
Expansion capability Limited Unlimited
Ease of debugging 1C log HTTP request logs, Postman

What are the key steps to set up 1C integration?

Custom REST is justified when:

  • Non-standard nomenclature attributes;
  • Multiple price types (retail, wholesale, dealer, promotional, regional, currency)—standard exchange sends only one type;
  • Multi-warehouse with different stock levels and need to select a warehouse on the site.

Prices, Stock, and Multi-Warehouse

Standard exchange can transfer one price type. In reality, there may be 15: each with its own buyer group and priority. Mapping between 1C price groups and Bitrix user groups is a separate engineering challenge. Especially when discounts overlap and you need to determine which price wins.

Multi-warehouse adds another layer: product is in stock in Moscow, out of stock in St. Petersburg, and "on order" in Novosibirsk. The site must show availability per location, allow selection of pickup points, and calculate shipping from the nearest warehouse where the product is physically available. The standard Bitrix warehouse module (catalog.store) handles display, but we write the "which warehouse to ship from" logic separately. For one manufacturing holding, we implemented a custom stock aggregator that calculated balance across 8 warehouses in 2 seconds—reducing shipping errors by 80%.

Orders and Document Flow

An order from the site goes to 1C, a sales document is created, goods are reserved. Statuses come back. The main nuance is partial shipment: the client ordered 5 items, 3 are in stock, 2 will arrive in a week. 1C creates two sales documents. Bitrix out of the box cannot split one order into several shipments—we extend the OnSaleOrderSaved handler to create child orders and synchronize statuses for each.

Documents in the personal account—invoices, acts, waybills from 1C—are served via REST; PDF is generated on the 1C side and cached on CDN. The buyer downloads not from 1C directly (that would kill the server) but from cache.

Batch import with portion control reduces MySQL load and prevents locks (source: Wikipedia).

Monitoring: Not "Set and Forget"

Exchange can silently break: the script ran, no errors in log, but 200 products didn't update due to invalid UTF-8 in the name. Or 1C changed the date format in an update—all prices came in as zero.

Minimum set we install on every project:

  • Telegram alert if exchange time increases 3+ times from average.
  • Stock discrepancy check: script compares b_catalog_product.QUANTITY with what 1C provides, and alerts when delta exceeds 5%.
  • Dashboard: last sync, number of processed items, queue, errors.

For high-load projects, we add async queues on Redis or RabbitMQ. Exchange does not block the web server, data is not lost during temporary 1C outages. On one online store with 2 million orders per year, we implemented this scheme—recovery time after failures dropped from 3 hours to 10 minutes.

Linking with Bitrix24 for Document Flow Automation

If besides the site there is a corporate portal on Bitrix24, we link it too. Counterparties from CRM go to 1C, invoices from 1C appear in deal cards. The manager sees accounts receivable and mutual settlements without switching windows. Deal closed—documents generated automatically.

Payment received in 1C → logistician gets a task for shipment in Bitrix24. Goods shipped → manager sees notification. Automatic tasks based on events from 1C—via Bitrix24 REST API webhooks. This link reduces manual entry by 70% and eliminates forgotten shipments.

How We Set Up Integration: Step-by-Step Process

  1. Audit of 1C Configuration. Review the structure of directories, documents, attributes. Identify custom modifications. Assess data volume (number of SKUs, orders, warehouses).
  2. Design Exchange Schema. Agree on data set: products, prices, stock, orders, documents. Determine sync interval and mechanism—CommerceML or custom REST.
  3. Configure Standard Exchange. Set up CommerceML, batch mode, binding by article. Verify data transfer correctness on a test catalog.
  4. Extended Integration. For complex configurations, write custom handlers on both 1C and Bitrix sides. Incorporate multi-warehouse, multiple prices, partial shipment.
  5. Monitoring and Warranty. Set up alerts, dashboard, documentation. Train operators. After launch, warranty support.
Typical exchange settings for a catalog of 50,000 SKUsBatch mode: 500 elements per step. Binding by article. Sync period: every 15 minutes. Use Bitrix agents with tagged caching. On 1C side, JSON generation processing instead of XML to speed up.

Timelines and What's Included

Stage Description Estimated Duration
Analysis Audit of 1C configuration, exchange structure, current issues 1–2 days
Schema Design Agree on data set (products, prices, orders) and architecture 2–5 days
Standard Exchange Setup Configure CommerceML, batch mode, binding by article 1–2 weeks
Extended Integration Custom REST, multi-warehouse, multiple prices, partial shipment 2–4 weeks
Full Custom Integration 1C + site + Bitrix24, async queues, monitoring 1–2 months

Work results include: documented exchange schema, configured synchronization scenarios, monitoring dashboard, operator training, and warranty support after launch. Pricing is calculated individually—it depends on the complexity of the 1C configuration, catalog size, and required automation level. We'll evaluate your project in 1 day—write to us, let's discuss. Order integration and get stable exchange in 1–2 weeks.

We have completed over 50 1C integrations for online stores and manufacturing companies. The team's average experience is 7 years, and we have certified 1C-Bitrix specialists. Our experience ensures that the exchange won't break in the first month and will run stably for years. For example, on a project with a catalog of 50,000 items, automation of exchange saved the client significant operational costs annually.

Contact us for a free audit of your 1C configuration—we'll find bottlenecks and offer the optimal solution.