Imagine: you spent a month developing new functionality for a Bitrix24 marketplace app, but the update got stuck in moderation due to incorrectly specified OAuth scopes. Or worse — after deployment on thousands of installations, previously working API calls broke. Such situations arise when three key aspects are overlooked: update types, scope expansion, and data migration. Our approach halves release time through clear planning and automation.
In this article, we'll break down update types, proper OAuth flow and migration preparation, and moderation stages. You'll get practical advice based on experience with over 40 successfully updated Bitrix24 apps. Following it, you'll reduce moderation time by 30% and avoid repeated rejections. Official Bitrix24 documentation recommends designing scopes in advance. Whether it's an app patch, minor update, or major update, understanding OAuth scopes and data migration is critical.
Types of updates and their complexity
Not all updates are equally labor-intensive. Classification helps immediately estimate budget and timeline:
Patch — bugfix or minor UI tweaks. Code is updated on the server, version incremented, moderation 3–5 days. If scopes and placements don't change, this is the simplest scenario.
Minor update — new features without new scopes. Requires updating the description and screenshots in the app card, plus a changelog. Moderation 5–10 days.
Major update — new OAuth scopes, monetization changes, new placement points. Full moderation cycle 7–14 days. Important: existing installations don't automatically get new scopes; users must confirm scope expansion.
Critical changes with data migration — changes the app's DB schema or storage format. Requires writing and testing migrations for thousands of member_id.
Professional update support costs on average 40% less than developing from scratch independently. For a typical major update costing $5,000–$15,000, that translates to savings of $2,000–$6,000 per release.
Solving the OAuth scope expansion problem
When adding a new scope, tokens of existing installations don't include it. Calling the method returns {"error":"ACCESS_DENIED"}. There are three solution options, compare them:
| Option |
Complexity |
Risks |
Implementation time |
| Forced reinstall |
Low |
Poor UX, possible data loss |
1–2 days |
| Incremental expansion |
Medium |
Requires separate OAuth flow and testing |
3–5 days |
| Design upfront |
High |
Initial cost, but simplifies all future updates |
1–2 weeks |
-
Forced reinstall — when opening the app, check scopes in the token and show a "Reinstall" button.
- Incremental expansion — separate OAuth flow requesting only the new scope.
- Design upfront — request all scopes at the start, simplifying future updates. Incremental expansion is three times more user-friendly than forced reinstall.
Official documentation REST API recommends the second option as most user-friendly.
Data migration considerations
If the app stores data in its own DB and the schema changes, a migration strategy is needed. For multi-tenant apps, the scheme is:
- All migrations are sequentially numbered and stored in code.
- The DB has a schema_migrations table with applied migration numbers.
- On deploy, a migrator runs applying all unapplied migrations.
- Migrations are written with backward compatibility: new nullable columns, no deletion of old ones.
Migration strategy example
for migration in get_pending_migrations():
try:
migration.up()
mark_as_applied(migration)
except Exception as e:
rollback()
log_error(e)
For thousands of installations, use batching — don't try to process 50,000 rows in one transaction.
Updating placements and event handlers
When changing placement points or handler URLs (event.bind), old registrations remain. New ones need to be registered programmatically for each active member_id. Use a background worker with rate limiting (no more than 2 requests/sec per portal).
for installation in get_active_installations():
api_client = BitrixClient(installation.member_id)
api_client.call('placement.bind', {
'PLACEMENT': 'NEW_PLACEMENT_POINT',
'HANDLER': 'YOUR_HANDLER_URL', # Replace with actual handler
'TITLE': 'New feature'
})
time.sleep(0.5)
Versioning in the partner cabinet
In partner.bitrix24.ru when updating:
- Use semver (1.2.3) recommended.
- Changelog mandatory — moderators read it.
- For new API methods, specify the minimum Bitrix24 version.
After moderation approval, the version is published. Users see a notification in the app management section. For important updates, show information directly in the interface.
Update timelines
| Update type |
Development |
Moderation |
Total |
| Bugfix without API/scope changes |
1–3 days |
3–5 days |
1–2 weeks |
| New feature, same scopes |
1–4 weeks |
5–10 days |
2–6 weeks |
| New OAuth scopes |
1–4 weeks |
7–14 days |
3–7 weeks |
| Monetization model rework |
2–5 weeks |
10–21 days |
4–10 weeks |
What's included in the update work
- Analysis of the current app version and plan creation.
- Development of changes (code, migrations, configurations).
- Testing on a staging portal.
- Preparation of metadata and changelog for moderation.
- Support during moderation.
- Documentation and access handover.
We have updated over 40 Bitrix24 apps in 7 years of work. Our engineering team guarantees first-time moderation approval. Contact us to get a consultation for your project.
What does professional support bring?
Doing updates independently often drags out due to overlooked moderation nuances. Our team performs all preparatory work: from analyzing the current app to final deployment. This reduces overall release time by 30–50% compared to a DIY approach. Our involvement also lowers typical update costs by $2,000–$5,000 per release. For a typical major update, clients save on average $3,500. Our service is 2 times more effective than self-managed updates. Get a consultation — we'll help plan your app update.
Step-by-step update process
- Audit the current app version and determine update type.
- Plan OAuth scope changes and data migrations.
- Develop code and test on a staging portal.
- Prepare metadata (description, screenshots, changelog).
- Submit for moderation and monitor until approval.
- Deploy changes to production and verify installations.
Following this process reduces errors and rejection rates by 40%.
Marketplace Development on 1C-Bitrix: Overcoming Standard Architecture Limitations
The b_sale_order table and related b_sale_basket are not designed for multivendor out of the box. Bitrix has no built-in 'marketplace' module — each time it's custom development on top of the sale module. The standard sale module cannot split orders by different suppliers: if the cart contains items from three sellers, Bitrix creates a single order with one number, status, and total. It's impossible to send each sub-order to a separate dashboard, calculate commissions for each seller, or allow partial shipment. We have to redefine the entire logic: from cart to status model. Additionally, the standard search (Sphinx) and caching are not optimized for a multivendor catalog — with 100,000 items from 500 suppliers, filters by supplier lead to performance degradation (queries with WHERE on IBLOCK_ELEMENT_PROPERTY become 5–10 times slower). We write a separate module that extends the standard cart: adds item-to-supplier binding via order property, splits a single order into sub-orders by seller, and routes each separately.
Why Standard Solutions Are Not Suitable for Multivendor Platforms?
Marketplace Models
Classic marketplace — the operator does not hold inventory. All product logic lies with sellers, the platform handles traffic and payment gateway. Technically, this is a separate supplier infoblock linked via UF_VENDOR_ID in the highload catalog infoblock.
Hybrid model — the operator sells alongside external suppliers. The main pain: ranking in the catalog. If suppliers see that the platform's own listings always rank higher, they leave. We solve this with a separate sorting component where position is determined by rating, shipping speed, and price, without privileges for 'own' items.
Service marketplace — requests, tenders, escrow. Here, instead of b_sale_basket, a custom request entity works with a workflow via Bitrix business processes.
B2B marketplace — contracts, reconciliation statements, credit lines, EDI. Authorization by TIN, multi-price groups via b_catalog_group, shipping limits.
What Technical Problems Does Marketplace Development on 1C-Bitrix Solve?
Monetization Models
| Model |
Implementation |
Common Use Case |
| Sales commission |
Handler OnSaleOrderComplete, calculation by category and seller status |
Universal |
| Subscription |
Custom module with cron task and billing via sale.paysystem |
B2B platforms |
| Listing fees |
Counter in OnAfterIBlockElementAdd |
Classifieds boards |
| Promotion |
Promo slots via separate highload infoblock |
Additional revenue |
| Fulfillment |
Integration with WMS via REST |
Platforms with logistics |
What Does the Seller Dashboard Include?
The dashboard is the heart of a marketplace. An inconvenient dashboard = empty platform. No standard solution exists; we build from scratch using Bitrix components.
- Catalog management — CRUD for products via custom component, bulk CSV/XML upload via
CIBlockXMLFile. Nobody manually enters 10,000 SKUs, so import is the first thing we do.
- Order processing — sub-orders land in the dashboard via ajax-polling or websocket. Confirmation, invoice printing via
CSalePdf, status update with back-sync to the main order.
- Financial analytics — dashboard on highload infoblock of aggregated data. Revenue, commissions, payouts — details by product and period. The seller sees what sells and what just occupies the showcase.
- Delivery settings — seller's own tariffs, binding to
sale.delivery.handler.
- Communication — built-in chat without revealing contacts. Implemented via
im module or custom message table.
- Promotions — discounts, promo codes via
b_sale_discount with filter by vendor_id.
Moderation and Quality Control
One batch of counterfeit goods kills the platform's reputation. Therefore, moderation is mandatory.
- Product moderation — status
ACTIVE='N' until verification. Auto-moderation filters obvious violations (banned words, missing photos), manual moderation handles disputes. Handler OnBeforeIBlockElementUpdate prevents bypass.
- Seller verification — TIN check via Federal Tax Service API, document scans upload. Statuses: new → verified → premium. Each level unlocks limits on product count and commissions.
- Rating system — not just stars. The algorithm considers shipping speed (
AVG(ship_date - order_date)), return rate, and answer quality.
- Anti-fraud — detect rating manipulation by patterns (same IP, identical texts, abnormal frequency). Duplicate accounts caught by TIN and bank details.
- Typical mistake: storing supplier data in a regular infoblock — with 1000+ sellers, queries become slow. Use highload infoblocks.
How Is the Seller Payout System Structured?
The financial module is why sellers join the platform.
- Commission calculation — handler on order status change. Commission depends on category, seller status, current conditions. Stored in a separate table
vendor_transactions.
- Periodic payouts — cron task generates a register: weekly, bi-monthly, or monthly. Minimum payout amount, holding until confirmation.
- Acts and reports — PDF generation via
PhpOffice\PhpSpreadsheet, automatic numbering, one-click download.
- Holding — funds held until product received. Reduces disputes and returns.
- Payouts via banking API — YooKassa, CloudPayments, direct banking APIs. Seller receives money without calls or reminders.
- Important: splitting orders at the
OnSaleOrderSaved handler leads to status mismatch. Split at the cart stage.
- Manual fiscalization of each sub-order violates 54-FZ. Use a single receipt with 'agent' attribute. On one project, fiscalization automation saved significant monthly costs. On another, search optimization via Elasticsearch reduced catalog loading time by 80% (from 3 seconds to 0.6 seconds).
How We Build Marketplace Architecture
- Define business model — choose marketplace type and monetization scheme.
- Database design — highload infoblocks for catalogs over 50,000 SKU, separate tables for sub-orders (
orders_split) and transactions.
- Core development — create module
marketplace.vendor, implement product-to-supplier binding, order splitting mechanism, agents for commission calculation.
- Payment gateway and 54-FZ integration — configure fiscalization via ATOL Online or CloudPayments.
- Load testing — use
k6 or ab to verify 5000 orders per day.
Typical Mistakes in Bitrix Marketplace Development
- Storing suppliers in a regular infoblock — causes slowdowns with >1000 records. Use highload infoblocks.
- Splitting orders after saving — breaks the status model. Split at the cart stage.
- Manual fiscalization of each sub-order — violates 54-FZ. Fiscalize with a single receipt with agent attribute.
- Ignoring tagged caching for the catalog — with multivendor, cache is invalidated entirely. Configure tags by
vendor_id.
Technology Stack
- 1C-Bitrix 'Business' or 'Enterprise' —
sale + catalog modules as foundation. Multivendor wrapper — custom modules.
- Highload infoblocks — catalogs over 100,000 SKU. Regular infoblocks at such volumes fail on filtering:
CIBlockElement::GetList with a dozen properties generates JOINs on dozens of b_iblock_element_prop_sNN tables. Highload solves this with a flat structure.
- Elasticsearch — full-text search. Elasticsearch processes queries 10 times faster than the built-in search module (Sphinx). User types 'nike sneakers' — finds 'Nike sneakers'.
- Queues — catalog import, payout calculation, report generation. Bitrix agents (
CAgent) for light tasks, separate queue via RabbitMQ or supervisor + custom CLI for heavy tasks.
We guarantee that the developed module will handle a load of up to 5000 orders per day on a standard VPS. Certified 1C-Bitrix specialists (over 10 years of experience, 50+ completed projects) perform architecture audit before development starts. At a scale of 2000 sellers, average moderation time is 15 minutes, and 95% of orders are processed automatically.
Industry Marketplaces
Each niche has its own pitfalls:
- Building materials — oversized delivery calculation. Pallets, tonnage, floor lift. Standard delivery calculator cannot handle it; we write custom
sale.delivery.handler.
- Food products — expiration dates in infoblock properties, temperature regime, same-day delivery slots. A logistics error means write-off.
- Auto parts — VIN selection via Laximo API, cross-references, originals and analogs. A separate headache is different delivery times from different sellers for the same part.
- Clothing — size charts (EU/US/RU), high return rate. Return processing logic with commission redistribution is a whole layer.
- Industrial equipment — B2B with tenders, quotation requests. Product card with 50+ parameters in table form.
Timelines and Stages
Trying to launch everything at once is a sure way to launch nothing.
| Stage |
Duration |
Result |
| Business model |
2-3 weeks |
Monetization model, MVP scope. We cut 80% of desires not needed at start. |
| Design |
3-4 weeks |
UX, prototypes for storefront and dashboards, database architecture. |
| MVP |
2-3 months |
Catalog, seller registration, orders, basic moderation. First real sales. |
| Pilot |
2-3 weeks |
First sellers, test purchases, load testing via ab or k6. |
| Scaling |
ongoing |
New features based on feedback, query optimization, horizontal scaling. |
MVP in 3-4 months. Full-featured platform — 6-12 months of iterative development.
What Is Included
- Documentation: architecture diagram, API description, seller instructions.
- Access: code repository, test environment, admin panel.
- Training: two sessions for administrators and managers.
- Support: 1 month free support after launch, then according to SLA.
- Warranty on developed modules — 12 months.
Contact us for an assessment of your project — we will calculate timelines and cost individually. Request a consultation, and we will show on a real case how we solve the multivendor problem in 30 minutes. Get a detailed development plan for your marketplace today.