- Home
- Import and export
-
OIA Shield24
OIA Shield24
A zero-trust API gateway for Bitrix24 REST API
Install
Free
In-app purchases
-
RatingNo ratings
-
Installations3
-
Developer
Description
OIA Shield24 is an enterprise API gateway that sits between your CRM and every third-party
developer, AI tool, or integration partner that needs to call it — so you never have to hand out
your master API key again.
What it solves:
developer, AI tool, or integration partner that needs to call it — so you never have to hand out
your master API key again.
What it solves:
- - Replaces shared master API keys with scoped, revocable Vendor Endpoints — each one limited to
- specific CRM/Users/Calendar/Tasks methods, specific HTTP methods, and (on paid plans) an IP
- allow/block list.
- - Every request passes a security pipeline before it reaches your CRM: API-key hashing and
- zero-trust lookup, OAuth token decryption/refresh, HTTP-method and CORS/origin checks, IP
- allow/block enforcement, plan-tier quota checks, and a 50MB payload cap with malformed-input
- sanitization.
- - Routes and rate-limits every vendor's traffic through a per-endpoint queue, so one integration
- hammering your CRM can never starve another.
- - Forwards real-time CRM events (deal/lead/contact changes, etc.) to your own external webhook
- receivers, with automatic retries and delivery-rate tracking.
- - Gives administrators a live dashboard of allowed/blocked/rate-limited traffic, with automatic
- threat-signal detection for suspicious activity (Enterprise plan).
- - Tariff plans gate functionality. On the free Starter plan: up to 2 vendor endpoints, 10,000
- requests/month, 30 requests/minute, 256 KB max payload, and up to 5 outbound event rules — IP
- allow/block lists, custom domains, and advanced threat-intelligence analytics are NOT available
- on Starter. The Developer plan raises these to 10 endpoints, 100,000 requests/month, 120
- requests/minute, 2 MB payload, 25 outbound event rules, and unlocks IP filtering and custom
- domains. The Enterprise plan removes the endpoint/request/payload/event-rule limits entirely and
- adds advanced threat-intelligence analytics.
- - Upgrading to a paid plan requires a card payment processed via Stripe, handled through the
- app's own in-app billing screen — no separate account or software installation is required.
- - Only a Bitrix24 administrator can install the app, create/edit/revoke Vendor Endpoints, or
- change billing — matches the OAuth scopes granted at install and is enforced server-side, not
- just hidden in the UI.
- - Outbound event delivery requires the administrator to supply their own externally reachable
- webhook URL; OIA Shield24 does not host or provide that receiving endpoint.
Technical Support
Mohamed Ali
InfinityBHT, LLC,
developers@infinitybht.com
Contact us at our website:
https://bitcommissions24.infinitybht.app/
LinkedIn:
https://www.linkedin.com/in/zetagalactic/
Working Hours:
09:00 AM - 05:00 PM UTC +01:00
Monday through Friday
Estimated response time is 48 hours
Installation instructions
How to Access & Setup the App:
- Navigate to your Bitrix24 main menu.
- Click on "OIA Shield24" to open the app.
- Create Rules — Open "Access Control" in the left-hand menu, click "New Vendor" and create a scoped endpoint — choose which CRM/Users/ Calendar/Tasks methods it may call, then hand that to the vendor instead of any master credential.
- Forward Events—Open "Outbound Events," click "Create Webhook" pick which Bitrix24 events to route, and enter the externally reachable URL that should receive them. That receiving endpoint is yours to build and host.
- Monitor — Open "Observability" — it populates automatically from real traffic once at least one Vendor Endpoint is in use.
Data security
OIA Shield24
The application requests access to the following data:
CRM
full access: view, create, edit and delete leads, contacts, companies, deals, invoices, quotes, activities, user fields etc.
Tasks
full access: view, create, edit and delete tasks, check lists, comments, files, dependencies, costs; view, create, edit and delete stages
Tasks
Forum
not used in applications
Sites
full access: view, create, edit and delete sites, blocks, site and block templates; publish and unpublish sites and site pages
Lists
full access: view, create, edit and delete lists, sections, items and item fields
Drive
full access: view, create, edit and delete storages, folders and files
appform
CoPilot
full access: add and delete AI providers; get a list of existing providers
Intranet
not used in applications
Calendar
full access: view, create, edit and delete calendars, calendar events, meetings, booking resources
Shipments
full access: view, create, edit and delete shipments, extra services and shipment handlers for online store orders
Telephony
restricted access: view, create, edit and delete outgoing call lines; search CRM clients by phone number; view, create, edit and delete SIP lines; manage call info pane and view call statistics
Agreements
restricted access: view agreements and add user consents
Workgroups
full access: view, create, edit and delete workgroups; manage users
Feed (log)
full access: add, edit and delete Feed posts, comments and recipients
Mail (mail)
Vote (vote)
Online Store
full access: view, create, edit and delete orders, order properties; order, shipment and payment statuses; view, create, edit and delete shopping cart items etc.
Data storage
full access: view, create, edit and delete storages, items and item fields
Open Channels
full access: view, create, edit and delete connectors; view and edit Open Channel settings; manage Open Channel agents etc.
Message import
full access: add chats, messages and users
Social Network
not used in applications
Cash registers
full access: view, create, edit and delete cash registers and cash register handlers for online store orders
Contact center
widgets: add, delete and edit widgets
Payment systems
full access: view, create, edit and delete CRM invoice payment systems and payment system handlers; online store orders
E-mail services
full access: view, create, edit and delete email service descriptions
Users (minimum)
read user list and names without contact information
Face recognition
full access: view, create and delete photos; identify employees and clients
Messaging service
full access: view, create, edit and delete message providers; read messages submitted for sending
Company structure
full access: view, create, edit and delete departments
e-Signature for HR
Chat enabled sales
reserved for future use
Commercial catalog
full access: add, edit and delete commercial catalog, prices, products, estimates, warehouses etc.
Document Generator
full access: view, create, edit and delete document templates, documents, auto numbering templates, access permissions for templates and documents
Mobile application
restricted access: add user interfaces to Bitrix24 mobile app
Business Processes
full access: view, create, edit and delete workflow actions, automation rules and triggers; view task list; run workflows
User custom fields
full access: read, add, edit and delete custom fields inside user profiles
Chat and Notifications
full access: view, create, edit and delete chats and messages; connect users to chats; edit chats; read all chat messages
BI analytics connector
add BI dashboards
Custom fields settings
full access: view, create, edit and delete custom field settings for some of the modules
Working Time Management
restricted access: clock-in and clock-out times; enable and disable reporting; view reports
Knowledge base 2.0 (note)
Telephony (outbound calls)
restricted access: make outgoing calls via built-in telephony
Tasks (extended permissions)
not used in applications
Creating and managing Chat bots
full access: view, create, edit and delete chatbots and their commands and messages; connect chatbots to chats; edit chats; read all chat messages
Resource and appointment booking
Robotic Process Automation (RPA)
full access: view, add, edit and delete workflows, stages and timeline items; run activities
HCM Link (humanresources.hcmlink)
Company Structure REST 3.0 (humanresources)
Instant system messages (without access to service user channel)
not used in applications
Rating
0 /5
5 stars
0
4 stars
0
3 stars
0
2 stars
0
1 star
0
Reviews
No reviews!