JSON API for 1C-Bitrix Turnkey — Strict Contract and Caching

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
JSON API for 1C-Bitrix Turnkey — Strict Contract and Caching
Medium
~1-2 weeks
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1361
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    948
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    694
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    833
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    732
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1075

Development of JSON API for 1C-Bitrix Turnkey — Strict Contract and Caching

We develop JSON API for 1C-Bitrix — not just "endpoints returning JSON", but a strict contract according to the jsonapi.org specification. With it, a client familiar with the standard can integrate without extra documentation. In our practice, this reduces negotiation time by 30% and eliminates ambiguities in data transfer. A typical project includes 10–15 endpoints; development cost varies depending on complexity. At the same time, savings on maintenance amount to up to 40% due to a single contract.

Advantages of Ordering a JSON API

A ready-made solution accelerates frontend development, mobile apps, and CRM integrations. You cease to depend on internal changes to Bitrix components — the API lives its own life. And with tagged cache (tagged cache on OnBeforeIBlockElementUpdate events), server load drops by 3–5 times compared to standard REST methods. JSON API is faster and more predictable than the built-in REST, especially when working with catalogs of 10,000+ products.

JSON API Architecture on Bitrix

Pure PHP implementation on top of the Bitrix kernel. Entry point is a controller outside the component system:

/local/
  api/
    v1/
      router.php        — request routing
      middleware/
        AuthMiddleware.php
        RateLimitMiddleware.php
      resources/
        ProductResource.php   — data transformer
        OrderResource.php
      controllers/
        ProductController.php
        OrderController.php

In router.php, routes are defined. For example, for products and orders:

$router->get('/v1/products', [ProductController::class, 'index']);
$router->get('/v1/products/{id}', [ProductController::class, 'show']);
$router->post('/v1/orders', [OrderController::class, 'create']);
$router->patch('/v1/orders/{id}', [OrderController::class, 'update']);

Transforming Data into JSON API

The resource class transforms raw data from information blocks into JSON structure, isolating clients from field changes. Example for products:

class ProductResource
{
    public static function make(array $product, array $include = []): array
    {
        $data = [
            'id' => (int)$product['ID'],
            'type' => 'products',
            'attributes' => [
                'name' => $product['NAME'],
                'code' => $product['CODE'],
                'description' => $product['DETAIL_TEXT'],
                'active' => $product['ACTIVE'] === 'Y',
                'created_at' => $product['DATE_CREATE'],
            ],
            'relationships' => [],
        ];

        if (in_array('prices', $include)) {
            $data['relationships']['prices'] = PriceResource::collection(
                PriceRepository::getForProduct((int)$product['ID'])
            );
        }

        if (in_array('sku', $include)) {
            $data['relationships']['sku'] = SkuResource::collection(
                SkuRepository::getForProduct((int)$product['ID'])
            );
        }

        return $data;
    }
}

The ?include=prices,sku parameter in the request controls inclusion of related data — the client gets exactly what they need.

Filtering, Sorting, and Pagination

All three mechanisms are implemented via query parameters. They work in a single code block and return metadata on record count.

// Filtering
$filter = ['IBLOCK_ID' => CATALOG_IBLOCK_ID, 'ACTIVE' => 'Y'];
if (isset($_GET['filter']['section_id'])) {
    $filter['SECTION_ID'] = (int)$_GET['filter']['section_id'];
}

// Sorting
$sort = [];
foreach (explode(',', $_GET['sort'] ?? 'id') as $field) {
    $direction = str_starts_with($field, '-') ? 'DESC' : 'ASC';
    $sort[ltrim($field, '-')] = $direction;
}

// Pagination (offset-based)
$limit = (int)($_GET['page']['size'] ?? 20);
$offset = ((int)($_GET['page']['number'] ?? 1) - 1) * $limit;

The response includes metadata:

{
  "data": [...],
  "meta": {
    "total": 1543,
    "page": 2,
    "per_page": 20,
    "last_page": 78
  },
  "links": {
    "self": "/v1/products?page[number]=2",
    "next": "/v1/products?page[number]=3",
    "prev": "/v1/products?page[number]=1"
  }
}

Creating an Order

POST /v1/orders with request body:

{
  "data": {
    "type": "orders",
    "attributes": {
      "delivery_address": "Moscow, Pushkina St., 1",
      "payment_method": "card"
    },
    "relationships": {
      "items": {
        "data": [
          { "type": "order-items", "product_id": 123, "quantity": 2 },
          { "type": "order-items", "product_id": 456, "quantity": 1 }
        ]
      }
    }
  }
}

The controller validates data and calls \Bitrix\Sale\Order::create() through the D7 API of the sale module. On error — a 422 Unprocessable Entity response with a structured error list.

Authentication

  • Bitrix session. For requests from browser applications where the user is logged in on the site. We check \CUser::IsAuthorized().
  • Bearer token (JWT). For mobile clients and server-to-server. Middleware decodes JWT, gets user_id, initializes Bitrix session:
$userId = $jwt->getClaim('sub');
\CUser::SetCurrent($userId);

After that, all standard permission checks work correctly.

  • API Key. For B2B partners. Key in the X-API-Key header, tied to a user or group in Bitrix.

Input Validation

Before passing to modules — strict validation. Each endpoint has a Request class with rules:

class CreateOrderRequest
{
    public function validate(array $data): array
    {
        $errors = [];
        if (empty($data['delivery_address'])) {
            $errors[] = ['pointer' => '/data/attributes/delivery_address', 'detail' => 'Required field'];
        }
        if (!in_array($data['payment_method'] ?? '', ['card', 'cash', 'invoice'])) {
            $errors[] = ['pointer' => '/data/attributes/payment_method', 'detail' => 'Invalid value'];
        }
        return $errors;
    }
}

Errors are returned in JSON API Errors format:

{
  "errors": [
    {
      "status": "422",
      "source": { "pointer": "/data/attributes/delivery_address" },
      "title": "Validation error",
      "detail": "Required field"
    }
  ]
}

Response Caching

For GET requests, we set up HTTP cache via headers:

header('Cache-Control: public, max-age=600, s-maxage=3600');
header('ETag: "' . md5($cacheKey . $dataHash) . '"');

On the Bitrix side — tagged cache for aggregated data. When a product is updated from 1C exchange, the tag is invalidated, and the next request fetches fresh data from the database.

What’s Included in the Work

  • Resource and endpoint design
  • Router, middleware, authentication development
  • Catalog resources implementation (Products, SKU, prices, leftovers)
  • Commerce operations (cart, orders, payment)
  • User endpoints (auth, profile, order history)
  • Caching (HTTP headers, Redis, tagged cache)
  • OpenAPI documentation + Postman collection
  • Integration tests and load testing
  • Code in Git, deployment instructions

Development Stages

Stage Content Duration
Design Resources, endpoints, data format 1 week
Infrastructure Router, middleware, authentication 1 week
Catalog resources Products, SKU, prices, leftovers, sections 1–2 weeks
Commerce operations Cart, orders, payment 1–2 weeks
User endpoints Auth, profile, order history 1 week
Caching HTTP headers, Redis, tagged cache 1 week
Documentation OpenAPI, Postman collection 3–5 days
Testing Integration tests, load testing 1 week
Cache Architecture DetailsWe use Bitrix tagged cache: when an information block element is saved, the `OnAfterIBlockElementAdd` event is triggered, which invalidates the cache by the `iblock_id_XXX` tag. This guarantees data freshness without manual reset.

JSON API on Bitrix is a strict, predictable contract that lives independently of component versions and templates. With proper implementation, the frontend team works with the API as an independent service. All requests are logged, errors are returned in a standard format, and versioning protects clients from unexpected schema changes.

Evaluate your project for free. Contact us — we will analyze the requirements and propose an architecture with timelines. Get a consultation from an engineer with over 10 years of Bitrix experience.

1C-Bitrix Module Development and Setup

The main trap of Bitrix is init.php. You add an OnBeforeIBlockElementUpdate handler there, then another one — a year later the file is 2000 lines, and on every hit all that code executes. We move business logic into full-fledged modules with D7 ORM, custom tables, and administrative interface. The module can be disabled, transferred to another project, covered with tests — none of that is possible with init.php. Our team has 10+ years of Bitrix experience, certified specialists, and a 6-month code guarantee. Request a consultation — we'll explain how to migrate legacy code to a modular architecture.

Why is init.php the worst place for business logic?

Init.php does not support class autoloading, lacks an isolated namespace, cannot be unit tested, and cannot be disabled without editing the file itself. Every handler written there runs on every request, even if not needed. In a module, you register handlers through EventManager, and they only execute when the event occurs. Performance difference: up to 3x with 10+ handlers.

Standard Modules: Typical Problems and Solutions

Information blocks. IBlock architecture is the first thing we review on any project. A classic mistake: one catalog infoblock with 80 properties, 30 of which are multiple. The b_iblock_element_property table swells to millions of rows, and CIBlockElement::GetList with filtering on three properties does a full scan. We move reference data to Highload-blocks, eliminate multiple properties where possible, and design the structure for 5x growth.

e-Store (sale). Cart business rules are a separate story. We set discount priorities to prevent two campaigns from giving 60% instead of 30%, connect payment handlers, and write custom validation via OnSaleOrderBeforeSaved.

Search. The built-in search module with morphology works up to 10–15 thousand elements. Beyond that — Elasticsearch. We configure it via the Bitrix search module API, indexing through CSearchFullText or custom indexers.

Highload-blocks for dictionaries, logs, user data — instead of bloated IBlocks. Direct queries via Bitrix\Highloadblock\HighloadBlockTable, custom tables instead of the EAV structure of standard infoblocks. A million records — no degradation.

Mail events. Configuration is not just templates in b_event_message. The key is SPF, DKIM, DMARC on the DNS, otherwise transactional emails go to spam. We check deliverability and set up bounce handling.

How to Design Infoblocks for Performance?

We use Highload-blocks for reference data (colors, sizes, manufacturers) that are not involved in complex queries. For SKUs — a separate infoblock with linking via IBLOCK_ELEMENT_PROPERTY. Enable INDEX_PROPERTY for frequently filtered properties. Tagged caching: when an element changes, only the related cache is cleared. Highload-blocks process up to 10x faster than infoblocks with multiple properties on volumes of 100,000 records.

Custom Module Development

Each module follows the structure /local/modules/vendor.modulename/:

  • install/index.php — setup class, create tables via $DB->RunSQLBatch()
  • lib/ — D7 ORM classes, extending Bitrix\Main\ORM\Data\DataManager
  • admin/ — administrative pages using CAdminList, CAdminForm
  • include.php — autoloading, event handler registration via EventManager::getInstance()->registerEventHandler()
  • REST API endpoints via \Bitrix\Rest\RestManager

The module registers in the system, appears in the "Installed Solutions" list, and has its own settings at /bitrix/admin/settings.php?mid=vendor.modulename. It can be enabled, disabled, and updated through UpdateSystem or custom migration mechanics.

Examples of implemented tasks:

  • Campaign management — visual condition builder via CAdminCalendar, timers via agents (CAgent::AddAgent), analytics linked to the sale module
  • Cost calculator — React widget on the frontend, REST API in the module, formulas stored in a Highload-block
  • Booking system — real-time calendar, locking via $DB->StartTransaction() / $DB->Commit() on concurrent requests, integration with channel manager via webhook

Components and Composite Cache

Component customization via result_modifier.php and component_epilog.php, not by editing template.php of the standard template. This way core updates are painless.

Composite cache ("Composite Site" technology) — the server sends ready HTML, bypassing PHP routing. Dynamic areas (cart, authorization) are loaded via CBitrixComponent::setFrameMode(true) and AJAX. TTFB drops to 30–50 ms. But there are caveats: not all components are compatible, $APPLICATION->ShowPanel() breaks composite, and careful markup of <div id="bx-composite-..."> is required.

What to Check Before Installing a Marketplace Module?

Before installing a module from the marketplace, an audit is mandatory. We check: SQL queries without prepared statements (hello SQL injection), direct use of $_REQUEST without filtering, use of outdated kernel API instead of D7, conflicts with the composite cache module. A module with no updates for over a year and a few dozen installations is likely a problem on the next PHP update. A typical case: a module calls CIBlockElement::GetList with no cache reset — the site crashes with 5000 elements.

Migration to D7

When upgrading PHP or switching to a new edition — refactor outdated calls:

  • CIBlockElement::GetList()Bitrix\Iblock\Elements\ElementTable::getList()
  • CSaleOrder::GetList()Bitrix\Sale\Order::getList()
  • CModule::IncludeModule()Bitrix\Main\Loader::includeModule() Testing on staging, rollback via git on issues.

According to official 1C-Bitrix documentation, D7 ORM is the recommended tool for working with data, providing type safety and automatic query generation.

Comparison: Init.php vs Module

Criterion Init.php Module with D7 ORM
Performance Executes on every hit Executes only on event
Testability No autoloading, tests impossible Full PHPUnit support
Maintainability Codebase grows uncontrollably Isolated structure, versioning
Migrations None Custom tables, managed via install
Caching Does not support auto-invalidation Tagged caching, event-based clearing

Module Development Scope and Cost

What is included in module development?

  • Technical specification and architectural plan
  • Code following PSR-4 and Bitrix code style
  • Unit tests (PHPUnit) for business logic
  • Integration tests for events and REST API
  • Installation, configuration, and API documentation
  • Repository and documentation access
  • Administrator training for module usage
  • 6-month warranty support

Estimated timelines and complexity:

Complexity Examples Timeline
Simple Callback widget, banner system, simple calculator 3–5 days
Medium Booking system, product configurator, review module with moderation 1–2 weeks
Complex Multi-regionality, custom loyalty program, ERP integration 2–4 weeks
Enterprise Marketplace platform, complex business processes with multiple roles 1–3 months

Cost is calculated individually — contact us for a project estimate.

Module Testing

Unit tests via PHPUnit cover business logic: discount calculation, validation, document generation. Mocks for Bitrix\Main\Application::getConnection() allow tests to be DB-independent. Integration tests verify event handlers on a real database — OnAfterIBlockElementAdd, OnSaleOrderSaved, etc. REST API endpoints are tested via curl or PHPUnit HTTP client. Critical for modules working with b_sale_order, b_catalog_price — where errors cost money.

Compatibility is checked on PHP 7.4, 8.0, 8.1, 8.2 and editions: Standard, Small Business, Business. We check conflicts with popular marketplace modules — they often intercept the same events. Load testing: measurements on 10K, 100K, 1M records, profiling via Xdebug for memory leaks and N+1 queries.

Practical Examples

Campaign module for an electronics chain. The built-in sale module discounts did not cover scenarios like "2+1", a gift with purchase over a certain amount, or combined conditions. We built a visual builder: marketers create rules via drag-and-drop without development tickets. Campaign calendar, auto-deactivation via agents, analytics linked to b_sale_order — conversion, average check, usage count. Time to launch a new campaign dropped from two days to half an hour.

Calculator for builders. Parameters (area, materials, number of floors) → formula → preliminary estimate → lead to CRM via CRest::call('crm.lead.add'). Regional coefficients and seasonal markups from a Highload-block, material prices from 1C exchange. The number of target leads increased by a third: clients see a breakdown before calling a manager.

Booking for a hotel chain. Real-time availability via AJAX requests to a custom table vendor_booking_slots, seasonal tariff calculation, synchronization with Booking.com via channel manager API. Room locking on concurrent booking via SELECT ... FOR UPDATE in transactions. Timezones handled via \DateTimeZone — a guest from Vladivostok and a manager from Moscow see the same picture.

We will evaluate your project within one day. Write to us — we'll tell you what is included in turnkey development. Contact us for a consultation on your project. Order a custom module development — get a ready solution with documentation and support.