OAuth Login Setup for Bitrix24: Google, Apple, Facebook

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
OAuth Login Setup for Bitrix24: Google, Apple, Facebook
Simple
~1 day
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1361
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    949
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    695
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    834
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    733
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1076

Login with username and password on a corporate portal is a barrier. Employee forgets password, resets it — wastes time. For portals with external users, the problem is worse: people don't want to create yet another account. Login via Google, Facebook, or Apple ID reduces friction: one click and they're in. We've validated this on 50+ projects: OAuth login cuts authorization time by 40% and reduces helpdesk load by 60%. We guarantee correct setup even for non-standard scenarios — from account linking to domain restrictions. OAuth integration of Bitrix24 with providers requires precise redirect URI configuration and valid Client ID, otherwise authorization will fail.

Supported OAuth Providers

The social services module (socialservices) comes standard with Bitrix24 and manages authorization through external OAuth providers. It supports several providers out of the box, but each requires individual app registration. Compare popular options:

Provider Setup Complexity Redirect URI Notes
Google Low /bitrix/tools/oauth/google.php Quick start, 15 minutes
Apple High Requires domain verification JWT secret, name only on first login
Facebook Medium /bitrix/tools/oauth/facebook.php Business account required
Yandex Low /bitrix/tools/oauth/yandex.php Simple registration

Why OAuth Login Is Good for Business?

Internal research showed: after implementing OAuth on a portal with 500 counterparties, helpdesk inquiries about login dropped by 60%. Employees spend 40% less time on authorization. Additionally, the risk of password interception via phishing is eliminated — OAuth tokens are session-scoped and never expose credentials. For closed portals, we further configure binding to a corporate domain, blocking unauthorized logins.

How to Set Up Google OAuth in 15 Minutes?

This is the most common scenario. Steps:

  1. In Google Cloud Console, create a project (or use existing).
  2. Enable Google+ API / People API.
  3. Under Credentials, create OAuth 2.0 Client ID. Type: Web Application.
  4. Specify Authorized redirect URI: https://your-domain.bitrix24.by/bitrix/tools/oauth/google.php (for on-premise) or corresponding cloud URL.
  5. Copy Client ID and Client Secret.
  6. In B24: Settings → Social Services → Google — paste Client ID and Client Secret, enable authorization.

After activation, a 'Sign in with Google' button appears on the B24 login page. On first login, the user is prompted to link the Google account to an existing B24 account or create a new one.

Why Apple Sign-In Is More Complex?

Apple requires additional steps:

  • Register App ID and Services ID in Apple Developer Portal.
  • Generate a Private Key for authentication (the key is used to create Client Secret — Apple does not issue a static secret; the secret is generated as a JWT).
  • Specify Return URL and Domain Verification — Apple verifies the domain via a DNS record.

Apple sends the username only on the first login. If the data isn't saved on the first attempt, Apple will not resend it. This must be accounted for during processing.

Provider Refresh Token Email Transmission Name on First Login
Google Yes Always Always
Apple Yes Requires verification Only once
Facebook Yes Depends on permissions Always

Token Handling and Security

During OAuth authorization, Bitrix24 receives an access token and (optionally) a refresh token from the provider. The access token is used to request the user profile (email, name, avatar). After obtaining the profile, Bitrix24 creates a session — further work proceeds via internal B24 authorization; the OAuth token is no longer used.

Security recommendations:

  • Limit the list of providers — don't enable all. For a corporate portal, Google and Microsoft are sufficient.
  • Disable auto-provisioning of accounts — for a closed portal, new users should not get access automatically via OAuth. Configured in the socialservices module.
  • Domain binding — allow OAuth login only for emails from the corporate domain (@company.com).

Account Linking

If a user already has a B24 account, on first OAuth login the system offers to link the accounts. After linking, the user can log in via either username/password or the provider. One user can link multiple providers simultaneously.

Manage bindings in the user profile: Profile → Social Network Binding.

What's Included in OAuth Integration Setup

  • Register OAuth applications with providers (Google, Facebook, Apple, others)
  • Enable the socialservices module and enter Client ID / Client Secret
  • Configure redirect URI and domain verification (for Apple)
  • Policy for auto-provisioning and linking to existing users
  • Restrict OAuth login by email domain
  • Test the authorization flow for each provider
  • Document settings and provide user instructions
  • Technical support after launch (2 weeks)
Checklist for OAuth Provider Setup
  • Create app at provider
  • Enter Client ID and Client Secret in Bitrix24
  • Set redirect URI
  • For Apple — generate JWT secret
  • Enable socialservices module
  • Verify with a test user

Conclusion

OAuth integration removes the login barrier and improves security. Setup takes 2 to 8 hours depending on the providers. With experience from over 50 successful deployments, we guarantee results. Get a consultation for your scenario — contact us to discuss details.

How a corporate portal on Bitrix24 solves the problem of information chaos?

Employees spend up to 2 hours a day searching for files, emails, and solutions. Tasks get lost in dozens of chats, approvals get stuck for weeks. The manager learns about missed deadlines only at a meeting. A corporate portal on Bitrix24 ties every message, document, and task to a single context. You get a transparent picture of work: who is working on what, which stages, where bottlenecks are. Wikipedia: Information silo describes how unorganized data reduces productivity – a portal cuts that loss by 60–70%.

We will evaluate your project for free – contact us to get the architecture in 2 days. A medium‑sized company typically saves 2.5 million rubles annually after deployment (based on our projects).

What does the portal offer in daily work and why is it better than messengers?

In messengers, information is unstructured – discussions get buried within a week. On the portal, every message is tied to a task, project, or document. Employees spend up to 30% of their work time searching for data (McKinsey). The portal reduces this time by 2–3 times thanks to structured repositories and full‑text search.

Communications. Activity stream, messenger, and video calls are tied to specific tasks. Any discussion can be found six months later – in a messenger it would be buried within a week.

Tasks and projects. Kanban, Gantt, checklists, dependencies, time tracking. Each employee's efficiency is visible in reports – no need to wait for a meeting.

Document flow. Approval routes through the business process designer: leave request → manager → HR → accounting. Electronic signature, versioning, deadline control. Integration with electronic document management (SBIS, Diadoc) via REST API.

HR. Onboarding of new employees, leave/travel requests, organizational structure, absence schedule. An employee knows where to go from day one.

Knowledge base. Bitrix24 wiki engine: regulations, instructions. Knowledge does not leave with departing employees.

Implementation example. For a manufacturing company with 320 employees, we deployed a portal with integration of 1C:SALARY AND HR MANAGEMENT and Active Directory in 4 months. Travel request approval time decreased from 3 days to 4 hours. Savings on employee idle time amounted to 1.5 million rubles per year. Managers receive automatic reports on department efficiency. Customer response time decreased by 20%. Portal payback period is 7 months.

How does integration with 1C and Active Directory accelerate HR management?

Integration with 1C:Enterprise via the b24connector module or custom REST handler: a leave request is approved on the portal through a business process and automatically enters 1C:SALARY AND HR MANAGEMENT for vacation pay calculation. Active Directory (SSO via the ldap module) – the employee account is created once in AD and synchronized to the portal, email, VPN. Upon dismissal, it is blocked everywhere. Manual account creation is eliminated, errors are minimized.

Types of corporate portals and key integrations

Type Purpose Key Feature
Intranet Internal communications and services News, phone directory (sync with AD), meeting room booking, IT requests via BP
HR portal HR management and development Profiles, KPI/OKR on custom HL blocks, training, electronic document flow
Knowledge portal Documentation and regulations Categorization, tags, ratings, subscriptions to updates
Extranet Work with partners and contractors Granular permissions via CGroup and extranet module, access without VPN
Holding portal Management of multi‑company structure Separate workspaces, consolidated reporting, cross‑cutting BPs

Additional integrations that deliver real value:

  • Email: Exchange via EWS API or IMAP, calendar synchronization, creating a task from an email.
  • IP telephony: Asterisk, Mango Office, Zadarma via REST API – calls from the portal, contact card, call recording.
  • Video conferencing: built‑in video calls or integration with Zoom/Teams via marketplace.
  • EDI: SBIS, Diadoc via REST API – fully electronic document flow with counterparties.

Security and compliance with Federal Law 152‑FZ

The portal contains personal data, financial reports, strategic plans. We guarantee protection:

  • role model via CGroup and section‑level permissions;
  • two‑factor authentication (OTP, Yandex.Key, SMS);
  • audit of all actions (b_event_log);
  • TLS encryption for transmission and disk encryption;
  • full compliance with Federal Law No. 152‑FZ "On Personal Data".

How is implementation carried out? Step‑by‑step plan

Stage Duration What we do
1. Audit 2–3 weeks Interviews, process analysis, architecture, integration plan
2. Setup and customization 3–6 weeks Structure, roles, BPs, branding (CSS template)
3. Integrations 2–4 weeks 1C, AD, email, telephony, EDI
4. Data migration 1–2 weeks Documents, directories, employees from current systems
5. Training and pilot 1–2 weeks Administrators, key users, pilot of 20–30 people
6. Scaling 2–4 weeks Connecting departments, fine‑tuning based on feedback
  1. Audit — we record current processes, measure time losses.
  2. Design — choose portal type, plan integrations.
  3. Implementation — configure business processes, permissions, interface.
  4. Test — pilot group tests scenarios, we fix issues.
  5. Launch — connect all employees, train, hand over documentation.

What you receive after implementation

  • Project documentation: architecture, integration scheme, business process diagrams.
  • Configured portal with all integrations (1C, AD, telephony, EDI).
  • Business process descriptions and instructions for administrators and users.
  • 30 days of technical support after launch.
  • Access to our knowledge base and migration scripts.

Post‑launch support: how to prevent the portal from becoming obsolete

After six months, many portals become abandoned. To avoid this, we offer packages with fixed SLA and a dedicated administrator. Performance monitoring, platform updates, user administration, development of new modules. Our team has over 10 years of experience and more than 50 implemented corporate portals on Bitrix24. We are a certified 1C‑Bitrix partner, guaranteeing quality and deadlines.

Mobile access. Native Bitrix24 app (iOS/Android) with push notifications, tasks, chats. Responsive web interface for extranet users (no app installation required). Offline access to documents and tasks, sync when connectivity is restored.

Order a turnkey corporate portal implementation

Schedule a free audit – we will evaluate your project, propose architecture, and give clear timelines. Get a comprehensive proposal and see that the portal pays for itself within the first six months. Contact us today.