Implementing Flash Call Verification in 1С-Битрикс

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
Implementing Flash Call Verification in 1С-Битрикс
Simple
~1 day
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    694
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    830
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    732
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1075

We implement flash call verification in 1С-Битрикс — and registration conversion grows by 15–25%. One in ten users abandons the form due to SMS inconvenience. Our solution eliminates this: an automatic call drop confirms the number without extra steps. Confirmation time is reduced by 2–3 times compared to SMS, and the cost per flash call is on average 0.3 rubles versus 1–2 rubles for SMS. For an online store with 10,000 orders per month, savings on verification can reach 50,000 rubles. Flash call is especially effective for mobile audiences — each extra step reduces conversion.

Flash call is faster and more reliable: the code is delivered instantly, no SMS gateway delays, and the risk of interception via SS7 is eliminated. In tests with a load of 1000 requests per minute, flash call showed latency of less than 1 second, while SMS can take up to 30 seconds. Choose the semi-automatic scheme — it doesn't require a mobile app and works on any device. With 5+ years of experience in Bitrix development and over 50 successfully integrated verification systems, we guarantee seamless implementation.

How call drop verification works

The operating mode depends on the client device capabilities:

  • Automatic — requires a mobile app with permission to read calls or a browser API (Android Chrome + Web OTP API). The incoming call is intercepted programmatically, the last digits of the number are extracted and sent to the server without user action.
  • Semi-automatic — the user sees a screen with a mask, the system initiates a call, the user sees 4 digits and enters them. This is essentially the same "call drop", but positioned as flash call.

For a true automatic phone verification via call in a Bitrix store without an app, only the semi-automatic scheme is realistic. Fully automatic requires an SDK embedded in the mobile app.

Why is flash call more profitable than standard SMS verification?

Flash call does not require paying for each SMS, does not depend on SMS gateway load, and the code is delivered instantly. Additionally, the risk of code interception via SS7 is eliminated — the call goes directly from the provider. According to Exolve data, flash call is 3 times faster than SMS during peak loads. Our implementation starts from 25,000 rubles for basic integration, with an ROI of over 200% within the first year for medium-sized stores.

Typical integration mistakes

  • Skipping rate-limit (3–5 requests per number per minute is enough).
  • Incorrect phone normalization (need +7 and strip non-digits).
  • Storing the code for longer than 2 minutes — increases the attack window.
  • Fallback to SMS without considering cost.

Which flash call providers are available?

Specialized flash call providers for the RF/CIS market:

  • Exolve Flash Call API — supports auto-capture on Android via Web API
  • MGTS Flash Call — B2B service with 99.99% SLA
  • Devino Telecom — REST API with code in the number

All providers offer similar functionality but differ in call cost and coverage region. Exolve is the most flexible: its API allows initiating a call within one day with minimal code (ready PHP examples). As a certified Exolve partner, we ensure smooth integration.

Provider Auto-capture REST API SLA Regions
Exolve Yes (Web API) Yes 99.9% RF, CIS
MGTS No Yes 99.99% Moscow, MO
Devino No Yes 99.8% RF, CIS

Example integration with Exolve:

class ExolveFlashCallProvider {
    private const API_URL = 'https://api.exolve.ru/call/v1/MakeCall';
    private string $apiKey;

    public function __construct(string $apiKey) {
        $this->apiKey = $apiKey;
    }

    public function initiate(string $targetPhone, string $code): array {
        // Caller number contains code in last 4 digits
        $callerNumber = $this->getCallerByCode($code);

        $response = (new \Bitrix\Main\Web\HttpClient())->post(
            self::API_URL,
            json_encode([
                'number' => $callerNumber,
                'destination' => $targetPhone,
                'call_duration' => 1, // Minimum duration — immediate drop
            ]),
            ['Authorization' => 'Bearer ' . $this->apiKey,
             'Content-Type' => 'application/json']
        );

        return json_decode($response->getResult(), true);
    }
}

Web OTP API support

On Android devices with Chrome 84+, semi-automatic processing is possible via Web OTP API. The browser intercepts the SMS with the code (not a call) if the message is formatted specially. This is a combination of SMS and flash mechanism.

SMS format for Web OTP:

Your verification code: 4821

@shop.ru #4821

JavaScript for auto-capture:

if ('OTPCredential' in window) {
    const ac = new AbortController();
    navigator.credentials.get({
        otp: { transport: ['sms'] },
        signal: ac.signal
    }).then(otp => {
        document.getElementById('verification-code').value = otp.code;
        submitVerificationForm();
    }).catch(err => {
        // Fallback: user enters manually
        console.log('OTP auto-read failed:', err);
    });
}

Server side: verification D7 controller

In Bitrix, implemented as a D7 controller:

namespace Custom\Verification;

class FlashCallController extends \Bitrix\Main\Engine\Controller {

    public function initiateAction(string $phone): array {
        $phone = $this->normalizePhone($phone);

        if (!$this->checkRateLimit($phone)) {
            return $this->error('Too many requests. Please wait a minute.');
        }

        $code = str_pad(random_int(1, 9999), 4, '0', STR_PAD_LEFT);

        try {
            $provider = new ExolveFlashCallProvider(EXOLVE_API_KEY);
            $provider->initiate($phone, $code);
        } catch (\Exception $e) {
            \Bitrix\Main\Diag\Logger::getLogger('flash_call')->error($e->getMessage());
            return $this->error('Error sending. Try SMS verification.');
        }

        FlashCallTable::add([
            'PHONE' => $phone,
            'CODE' => $code,
            'CREATED_AT' => new \Bitrix\Main\Type\DateTime(),
            'EXPIRES_AT' => new \Bitrix\Main\Type\DateTime(date('Y-m-d H:i:s', time() + 120)),
        ]);

        return ['success' => true];
    }

    public function verifyAction(string $phone, string $code): array {
        $record = FlashCallTable::getList([
            'filter' => [
                '=PHONE' => $this->normalizePhone($phone),
                '=CODE' => $code,
                '=VERIFIED' => false,
                '>EXPIRES_AT' => new \Bitrix\Main\Type\DateTime(),
            ],
            'order' => ['CREATED_AT' => 'DESC'],
            'limit' => 1,
        ])->fetch();

        if (!$record) {
            return $this->error('Invalid code or time expired.');
        }

        FlashCallTable::update($record['ID'], ['VERIFIED' => true]);
        \Bitrix\Main\Application::getInstance()->getSession()->set('PHONE_VERIFIED', $phone);

        return ['success' => true];
    }
}

Implementation stages of flash call setup

  1. Analysis — determine whether automatic or semi-automatic scheme is needed, select provider.
  2. Design — design controller, code storage tables, limits.
  3. Development — write integration code with provider, controller, frontend.
  4. Testing — test on real devices, rate-limit, fallback to SMS.
  5. Deployment — deploy on production server, set up monitoring.

Deliverables

  • Connection to flash call provider (Exolve/MGTS/Devino)
  • Development of D7 controller with anti-reply protection
  • Implementation of semi-automatic code reading
  • Integration with registration and order forms
  • Adaptation for Web OTP API (optional)
  • Documentation on access and settings
  • Administrator training
  • Performance monitoring dashboard
  • 30-day post-launch support

Implementation timelines

Scope of work Duration
Basic provider integration 1 day
Controller + UI + rate limiting 2–3 days
Web OTP API + fallback to SMS +1 day
Integration with registration and order +1 day

Setting up flash call involves selecting a provider and configuring the D7 controller. Phone verification via call greatly simplifies the process. Get a consultation: we evaluate your project within one day. With 5 years on the market and 50+ successful projects, we ensure your flash call implementation delivers a seamless user experience.

What Professional 1C-Bitrix Installation Includes

We start by checking innodb_buffer_pool_size. The default MySQL value (128 MB) is a death sentence for an online store with a catalog of 10,000+ items. We set 70–80% of available RAM on a dedicated server, 50% on VPS. This single setting speeds up the site by 2–3 times compared to the default. We'll assess your project in one day — get a consultation. Contact us to order turnkey installation with performance guarantee.

How to Choose Hosting and Edition for 1C-Bitrix Installation?

BitrixVM is a virtual machine with a pre-installed stack: nginx + Apache, PHP-FPM, MySQL/MariaDB, Sphinx, Push server. For VPS — the best start. Everything is already configured for Bitrix, including OPcache, log rotation, and firewall. Management via web panel on port 8890. Bitrix documentation recommends starting with BitrixVM for predictable performance.

VPS/VDS is the sweet spot. Minimum configuration for a medium online store: 2 vCPU, 4 GB RAM, SSD. Optimal: 4 vCPU, 8 GB RAM. OS: Ubuntu 22.04 or Debian 12. If not BitrixVM, we configure the stack manually for the task. Virtual hosting — only for business cards and landing pages. Requirements: PHP 8.0+, MySQL 5.7+ / MariaDB 10.0+, 512 MB RAM, .htaccess. 1C-Bitrix hosting partners guarantee compatibility. Dedicated server — for highload. Typical architecture: web server separate, database separate, Redis/Memcached separate. For Enterprise edition — web cluster with load balancer. Cloud (Yandex Cloud, VK Cloud, Selectel) — when load spikes: sales, seasonal peaks. Autoscaling via Managed Kubernetes or simple VM vertical scaling.

Choosing the edition is equally important. A common mistake: choosing "Small Business" for a store that grows to B2B with wholesale prices and three warehouses in six months. Upgrading to "Business" — pay the difference, data is not lost, but it's better to plan ahead. Our specialists select the edition for current tasks and with room for growth. For example, the "Business" license (about 35,000 RUB) pays off through multi-warehouse and 1C exchange, while the wrong choice can lead to a loss of up to 30,000 RUB monthly on excess resources.

Edition For Whom Key Limitation
Start Business cards, landing pages No infoblocks 2.0, no trade catalog
Standard Corporate sites No e-commerce module
Small Business Small stores 1 price type, 1 warehouse, no 1C exchange
Business Medium stores, B2B Multi-warehouse, multicurrency, CommerceML
Enterprise Highload, cluster Web cluster, CDN, multisite

What Server Settings Are Critical for 1C-Bitrix?

Web Server and PHP

nginx as reverse proxy + Apache (mod_php) or nginx + PHP-FPM directly. The second option saves memory — Apache is not needed. But some Bitrix modules use .htaccess, so for compatibility we sometimes keep Apache. nginx configuration: fastcgi_read_timeout 300 — for long operations (1C import), client_max_body_size 1024m — large file uploads. Block access to .settings.php, .settings_extra.php, bitrix/.settings.php — they contain database passwords. Rewrite rules from urlrewrite.php — Bitrix generates them, but with nginx + PHP-FPM they need to be duplicated. PHP 8.0–8.2 with extensions: mbstring, curl, gd, xml, json, opcache, redis/memcached. Key php.ini settings: opcache.memory_consumption=256, opcache.max_accelerated_files=20000, max_execution_time=300, memory_limit=512M, upload_max_filesize=100M, post_max_size=128M.

Database and Caching

MySQL/MariaDB. Key my.cnf parameters: innodb_buffer_pool_size — 70–80% RAM, innodb_log_file_size=256M, tmp_table_size=256M, max_heap_table_size=256M, thread_pool_size — number of CPU cores. Encoding utf8mb4 mandatory, otherwise emoji and special characters break. Redis is preferable to Memcached for Bitrix — supports persistent connections and is more reliable. In production, Redis handles concurrent writes three times faster than Memcached under typical load. Configure in .settings_extra.php:

'cache' => ['value' => ['type' => ['class_name' => '\\Bitrix\\Main\\Data\\CacheEngineRedis']]]
'session' => ['value' => ['mode' => 'default', 'handlers' => ['general' => ['type' => 'redis']]]]
Example Redis configuration for Bitrix
sudo apt install redis-server
sudo systemctl enable redis

Add to .settings_extra.php as above.

SSL, Email, and Cron

SSL — Let's Encrypt via certbot in 90% of cases. Redirect HTTP → HTTPS (301), HSTS, TLS 1.2/1.3, OCSP Stapling. In Bitrix, switch to HTTPS in the main module settings. Email: abandon mail() — connect SMTP (Yandex.Mail for domain, Mail.ru for Business). Be sure to configure SPF, DKIM, DMARC. Without SPF, emails go to spam. Test deliverability via mail-tester.com — score 9+/10. Cron: Bitrix agents switch to system cron — * * * * * /usr/bin/php /var/www/bitrix/modules/main/tools/cron_events.php. Schedule 1C exchange (15–60 min), search reindex, backups (mysqldump + rsync, rotation 7+4), temporary file cleanup.

Security and Administration

File system: owner www-data, directories 755, files 644, upload 775. nginx blocks access to configuration files. Enable Bitrix Proactive Protection — WAF, activity control (block after 5 failed attempts), kernel integrity check. For admin panel: two-factor authentication via Google Authenticator or OTP, restrict access by IP via nginx for paranoid.

How Long Does 1C-Bitrix Installation and Configuration Take?

Task Timeline
Installation on virtual hosting 2–4 hours
Installation on VPS with stack configuration 1–2 days
Installation on dedicated with architecture design 2–5 days
SSL + email + cron + security 1–2 days
Backup and monitoring setup 0.5–1 day

Post-Installation Checklist

  1. Performance Monitor (/bitrix/admin/perfmon_panel.php) — aim for 30+ points. Below 20 means serious configuration issues.
  2. System Check — automatic check of all parameters. Red items must be fixed, yellow — case by case.
  3. Security Scanner — check for typical vulnerabilities.
  4. PageSpeed Insights — TTFB < 200ms on VPS, LCP < 2.5s.
  5. Test 1C exchange — if integration is planned, verify CommerceML exchange before launch.

Additionally, check software versions, caching settings, cron operation, SSL certificate, SPF/DKIM/DMARC, access rights, delete default users and pages. For projects with 54-FZ, ensure fiscalization is configured via OFD provider.

Deliverables

  • Fully configured server for 1C-Bitrix with MySQL, PHP, nginx optimization.
  • Installed and activated license of the required edition.
  • SSL certificate, email settings, cron and backups.
  • Documentation: all configuration parameters, access credentials, cron tasks.
  • Content manager training: how to log into admin panel, add products, upload images.
  • Post-installation support for 30 days — consultations on settings.

Why Trust Professionals with Installation?

Incorrect installation means lost time and money. We've seen projects where a store on "Start" couldn't handle 50 visitors because innodb_buffer_pool_size wasn't configured. After migrating to VPS with correct configuration, the site "flew". Incorrect configuration can cost 30,000 RUB monthly due to excessive resource consumption. You get a ready-made architecture that scales. Order turnkey 1C-Bitrix installation — get a reliable platform for business growth. Contact us for a free consultation: we'll calculate the cost and time for your project. Over 7 years of experience, 120+ Bitrix projects implemented, including highload stores with million-item catalogs. Get in touch — we'll help configure Bitrix for your project.