Problem: the standard REST API in 1C-Bitrix on a catalog of 10,000 products generates 5,000+ requests to fetch nested data (prices, stock). A mobile app client loads 400 KB of unnecessary fields. GraphQL solves this with a single request—the client describes the needed fields and gets exactly what was requested. We have been implementing GraphQL on Bitrix for several years; actual traffic savings reach 60%, and response time drops from 3 seconds to 200 ms. With a volume of 500,000 requests per month, CDN savings amount to 2,000–5,000 rubles.
Why GraphQL is Better than REST for Complex Catalogs
The REST endpoint /api/products/123 returns a fixed set of fields. A mobile app needs name and price—it receives 40 fields. Another client needs stock by warehouse—it makes a second request. GraphQL allows each client to describe its needs:
# Mobile app
query {
product(id: 123) {
name
price { value currency }
images { url }
}
}
# Warehouse module
query {
product(id: 123) {
name
sku { id stock { warehouse quantity } }
}
}
One endpoint, one request—different data for different clients. GraphQL is better than REST in scenarios with multiple consumers: frontend, mobile app, external services—each gets only its own data.
The main problem with GraphQL is N+1 queries. The client requests a list of 20 products, each needs prices—20 separate queries to b_catalog_price. Solution: DataLoader (batching pattern). DataLoader accumulates queries within one GraphQL execution and makes one batch query:
class PriceDataLoader
{
private array $buffer = [];
public function load(int $productId): Promise
{
$this->buffer[] = $productId;
return new Promise(fn($resolve) => $resolve($productId));
}
public function dispatch(): void
{
// Single query for all accumulated IDs
$prices = \Bitrix\Catalog\PriceTable::getList([
'filter' => ['PRODUCT_ID' => $this->buffer],
])->fetchAll();
// Distribute results
}
}
Instead of 20 queries—1. For nested data (products → SKUs → stock) the saving is multiplicative. On large catalogs (50,000+ items) this reduces response time to 200 ms.
How to Implement GraphQL in Bitrix: From Schema to Endpoint
Bitrix does not support GraphQL out of the box. The implementation is built on top of standard Bitrix PHP using the GraphQL-PHP library—the de facto standard for PHP.
The entry point is a single controller at /api/graphql that accepts POST requests with JSON body ({ "query": "...", "variables": {...} }).
// /local/php_interface/api/graphql.php
use GraphQL\GraphQL;
use GraphQL\Type\Schema;
$rawInput = file_get_contents('php://input');
$input = json_decode($rawInput, true);
$schema = new Schema([
'query' => QueryType::build(),
'mutation' => MutationType::build(),
]);
$result = GraphQL::executeQuery($schema, $input['query'], null, null, $input['variables'] ?? null);
header('Content-Type: application/json');
echo json_encode($result->toArray());
Each GraphQL type corresponds to a Bitrix entity. Example for catalog:
// ProductType
ObjectType(['name' => 'Product', 'fields' => fn() => [
'id' => ['type' => Type::int()],
'name' => ['type' => Type::string()],
'code' => ['type' => Type::string()],
'price' => [
'type' => PriceType::get(),
'resolve' => fn($product) => PriceResolver::resolve($product['ID']),
],
'sku' => [
'type' => Type::listOf(SkuType::get()),
'resolve' => fn($product) => SkuResolver::resolve($product['ID']),
],
'sections' => [
'type' => Type::listOf(SectionType::get()),
'resolve' => fn($product) => SectionResolver::resolve($product['IBLOCK_SECTION_ID']),
],
]]);
Resolvers are functions that fetch data for each field. The resolver for price accesses b_catalog_price, for sku—the child SKU info block, for sections—b_iblock_section. Experience shows that a well-designed type schema pays off at the stage of feature expansion.
How to Implement Mutations and Authorization
Mutations in GraphQL are the analog of POST/PUT/DELETE in REST:
mutation {
createOrder(input: {
productId: 123,
quantity: 2,
deliveryAddress: "Moscow, Lenin St., 1"
}) {
orderId
status
totalAmount
}
}
The mutation resolver calls \Bitrix\Sale\Order::create() with the required parameters—standard D7 API of the sale module. We recommend validating input data via resolvers and returning clear errors.
Authorization is implemented on two levels. Request level: middleware checks JWT or Bitrix session before executing the GraphQL query. Field level: a specific field is accessible only to authorized users. For example, the costPrice field (cost price) is visible only to users with the 'Administrator' role. Implemented in the resolver without additional code blocks—a simple permission check.
How to Cache GraphQL and Organize Subscriptions
GraphQL is harder to cache than REST: queries are unique by field set and variables. Approaches:
-
Resolver-level cache—most common: the resolver caches the result of a specific DataLoader batch in Redis/Memcache. TTL depends on data update frequency.
-
Persisted Queries: the client sends a hash of a pre-registered query instead of its full text. This allows caching at the HTTP level (CDN caches GET requests with the hash).
-
Bitrix tagged cache: register tags when reading data (
iblock_id_1), invalidate on change.
For high-load projects we use a combination of all three methods—this gives 90% cache hit rate.
GraphQL supports subscriptions—real-time updates via WebSocket. When an order changes, all subscribers receive a notification. For Bitrix it is implemented via a separate WebSocket server (Ratchet/Swoole) + Redis pub/sub. When a Bitrix entity changes (via an event handler), we publish to a Redis channel, and the WebSocket server delivers to all subscribers.
What is Included in Our Development and Work Stages
We provide a full package: schema design, type and resolver implementation, DataLoader and caching setup, documentation in GraphQL SDL + Markdown format, team training on GraphiQL, and 30-day warranty support after deployment. We evaluate your project in 1 day. The cost of the project ranges from 200,000 to 500,000 rubles depending on complexity.
| Stage |
Content |
Duration |
| Schema Design |
Types, queries, mutations, relations |
1 week |
| Basic Infrastructure |
GraphQL endpoint, authorization |
3–5 days |
| Type & Resolver Implementation |
Catalog, orders, users |
2–4 weeks |
| DataLoader (N+1) |
Batching for nested data |
1 week |
| Caching |
Redis DataLoader cache + tags |
1 week |
| Field Authorization |
Access control |
3–5 days |
| Testing |
Unit tests for resolvers, integration tests |
1 week |
Comparison of Approaches
| Criterion |
REST |
GraphQL |
| Overfetching/underfetching |
Often |
None |
| Number of requests for nested data |
N+1 |
1 |
| Flexibility for different clients |
Low |
High |
| Caching complexity |
Medium |
High |
GraphQL on Bitrix is a mature solution for projects with multiple clients and complex nested data. For a simple site with one frontend, REST is sufficient. Get a consultation—our engineers will evaluate your project in 1 day and help you choose the best option. Contact us to discuss your project.
1C-Bitrix Module Development and Setup
The main trap of Bitrix is init.php. You add an OnBeforeIBlockElementUpdate handler there, then another one — a year later the file is 2000 lines, and on every hit all that code executes. We move business logic into full-fledged modules with D7 ORM, custom tables, and administrative interface. The module can be disabled, transferred to another project, covered with tests — none of that is possible with init.php. Our team has 10+ years of Bitrix experience, certified specialists, and a 6-month code guarantee. Request a consultation — we'll explain how to migrate legacy code to a modular architecture.
Why is init.php the worst place for business logic?
Init.php does not support class autoloading, lacks an isolated namespace, cannot be unit tested, and cannot be disabled without editing the file itself. Every handler written there runs on every request, even if not needed. In a module, you register handlers through EventManager, and they only execute when the event occurs. Performance difference: up to 3x with 10+ handlers.
Standard Modules: Typical Problems and Solutions
Information blocks. IBlock architecture is the first thing we review on any project. A classic mistake: one catalog infoblock with 80 properties, 30 of which are multiple. The b_iblock_element_property table swells to millions of rows, and CIBlockElement::GetList with filtering on three properties does a full scan. We move reference data to Highload-blocks, eliminate multiple properties where possible, and design the structure for 5x growth.
e-Store (sale). Cart business rules are a separate story. We set discount priorities to prevent two campaigns from giving 60% instead of 30%, connect payment handlers, and write custom validation via OnSaleOrderBeforeSaved.
Search. The built-in search module with morphology works up to 10–15 thousand elements. Beyond that — Elasticsearch. We configure it via the Bitrix search module API, indexing through CSearchFullText or custom indexers.
Highload-blocks for dictionaries, logs, user data — instead of bloated IBlocks. Direct queries via Bitrix\Highloadblock\HighloadBlockTable, custom tables instead of the EAV structure of standard infoblocks. A million records — no degradation.
Mail events. Configuration is not just templates in b_event_message. The key is SPF, DKIM, DMARC on the DNS, otherwise transactional emails go to spam. We check deliverability and set up bounce handling.
How to Design Infoblocks for Performance?
We use Highload-blocks for reference data (colors, sizes, manufacturers) that are not involved in complex queries. For SKUs — a separate infoblock with linking via IBLOCK_ELEMENT_PROPERTY. Enable INDEX_PROPERTY for frequently filtered properties. Tagged caching: when an element changes, only the related cache is cleared. Highload-blocks process up to 10x faster than infoblocks with multiple properties on volumes of 100,000 records.
Custom Module Development
Each module follows the structure /local/modules/vendor.modulename/:
-
install/index.php — setup class, create tables via $DB->RunSQLBatch()
-
lib/ — D7 ORM classes, extending Bitrix\Main\ORM\Data\DataManager
-
admin/ — administrative pages using CAdminList, CAdminForm
-
include.php — autoloading, event handler registration via EventManager::getInstance()->registerEventHandler()
- REST API endpoints via
\Bitrix\Rest\RestManager
The module registers in the system, appears in the "Installed Solutions" list, and has its own settings at /bitrix/admin/settings.php?mid=vendor.modulename. It can be enabled, disabled, and updated through UpdateSystem or custom migration mechanics.
Examples of implemented tasks:
- Campaign management — visual condition builder via
CAdminCalendar, timers via agents (CAgent::AddAgent), analytics linked to the sale module
- Cost calculator — React widget on the frontend, REST API in the module, formulas stored in a Highload-block
- Booking system — real-time calendar, locking via
$DB->StartTransaction() / $DB->Commit() on concurrent requests, integration with channel manager via webhook
Components and Composite Cache
Component customization via result_modifier.php and component_epilog.php, not by editing template.php of the standard template. This way core updates are painless.
Composite cache ("Composite Site" technology) — the server sends ready HTML, bypassing PHP routing. Dynamic areas (cart, authorization) are loaded via CBitrixComponent::setFrameMode(true) and AJAX. TTFB drops to 30–50 ms. But there are caveats: not all components are compatible, $APPLICATION->ShowPanel() breaks composite, and careful markup of <div id="bx-composite-..."> is required.
What to Check Before Installing a Marketplace Module?
Before installing a module from the marketplace, an audit is mandatory. We check: SQL queries without prepared statements (hello SQL injection), direct use of $_REQUEST without filtering, use of outdated kernel API instead of D7, conflicts with the composite cache module. A module with no updates for over a year and a few dozen installations is likely a problem on the next PHP update. A typical case: a module calls CIBlockElement::GetList with no cache reset — the site crashes with 5000 elements.
Migration to D7
When upgrading PHP or switching to a new edition — refactor outdated calls:
-
CIBlockElement::GetList() → Bitrix\Iblock\Elements\ElementTable::getList()
-
CSaleOrder::GetList() → Bitrix\Sale\Order::getList()
-
CModule::IncludeModule() → Bitrix\Main\Loader::includeModule()
Testing on staging, rollback via git on issues.
According to official 1C-Bitrix documentation, D7 ORM is the recommended tool for working with data, providing type safety and automatic query generation.
Comparison: Init.php vs Module
| Criterion |
Init.php |
Module with D7 ORM |
| Performance |
Executes on every hit |
Executes only on event |
| Testability |
No autoloading, tests impossible |
Full PHPUnit support |
| Maintainability |
Codebase grows uncontrollably |
Isolated structure, versioning |
| Migrations |
None |
Custom tables, managed via install |
| Caching |
Does not support auto-invalidation |
Tagged caching, event-based clearing |
Module Development Scope and Cost
What is included in module development?
- Technical specification and architectural plan
- Code following PSR-4 and Bitrix code style
- Unit tests (PHPUnit) for business logic
- Integration tests for events and REST API
- Installation, configuration, and API documentation
- Repository and documentation access
- Administrator training for module usage
- 6-month warranty support
Estimated timelines and complexity:
| Complexity |
Examples |
Timeline |
| Simple |
Callback widget, banner system, simple calculator |
3–5 days |
| Medium |
Booking system, product configurator, review module with moderation |
1–2 weeks |
| Complex |
Multi-regionality, custom loyalty program, ERP integration |
2–4 weeks |
| Enterprise |
Marketplace platform, complex business processes with multiple roles |
1–3 months |
Cost is calculated individually — contact us for a project estimate.
Module Testing
Unit tests via PHPUnit cover business logic: discount calculation, validation, document generation. Mocks for Bitrix\Main\Application::getConnection() allow tests to be DB-independent. Integration tests verify event handlers on a real database — OnAfterIBlockElementAdd, OnSaleOrderSaved, etc. REST API endpoints are tested via curl or PHPUnit HTTP client. Critical for modules working with b_sale_order, b_catalog_price — where errors cost money.
Compatibility is checked on PHP 7.4, 8.0, 8.1, 8.2 and editions: Standard, Small Business, Business. We check conflicts with popular marketplace modules — they often intercept the same events. Load testing: measurements on 10K, 100K, 1M records, profiling via Xdebug for memory leaks and N+1 queries.
Practical Examples
Campaign module for an electronics chain. The built-in sale module discounts did not cover scenarios like "2+1", a gift with purchase over a certain amount, or combined conditions. We built a visual builder: marketers create rules via drag-and-drop without development tickets. Campaign calendar, auto-deactivation via agents, analytics linked to b_sale_order — conversion, average check, usage count. Time to launch a new campaign dropped from two days to half an hour.
Calculator for builders. Parameters (area, materials, number of floors) → formula → preliminary estimate → lead to CRM via CRest::call('crm.lead.add'). Regional coefficients and seasonal markups from a Highload-block, material prices from 1C exchange. The number of target leads increased by a third: clients see a breakdown before calling a manager.
Booking for a hotel chain. Real-time availability via AJAX requests to a custom table vendor_booking_slots, seasonal tariff calculation, synchronization with Booking.com via channel manager API. Room locking on concurrent booking via SELECT ... FOR UPDATE in transactions. Timezones handled via \DateTimeZone — a guest from Vladivostok and a manager from Moscow see the same picture.
We will evaluate your project within one day. Write to us — we'll tell you what is included in turnkey development. Contact us for a consultation on your project. Order a custom module development — get a ready solution with documentation and support.