Payments are experiencing issues due to temporary restrictions in Russia. If your payment does not go through, please submit a support request.Our support team is available 24/7 — we are always here to help with hosting and server issues.We are now accepting requests for dedicated server rental and colocation services in our data center.Reminder: we recommend enabling backups for additional data protection.A new VPS/VDS lineup with NVMe storage and improved performance is now available.Maintenance work on some servers has been completed. All services are operating normally.

MODULE FOR 1C-BITRIX

eCom Labs

Authorization via MAX (EcomLabs)

Configuration for the MAX authorization module by eCom Labs Access settings via the menu path: Settings → Product Settings → Module Settings → Authorization via MAX. Alternatively: Settings → Authorization via MAX → Settings. MAX Tab (bot and webhook) Enable authorization via MAX — main switch. When disabled, API requests to the MAX platform are not sent.

Technical details

Published
21 September 2026
Version
1.0.0
Installed
Fewer than 50 times
Compatible editions
First Site, Start, Standard, Small Business, Business
Responsive design
Yes
Composite support
Yes
Compatible with Sites24
No
Developer
eCom Labs

What this solution does

Configuration for the MAX authorization module by eCom Labs

Access settings via the menu path: Settings → Product Settings → Module Settings → Authorization via MAX. Alternatively: Settings → Authorization via MAX → Settings.

MAX Tab (bot and webhook)

Enable authorization via MAX — main switch. When disabled, API requests to the MAX platform are not sent.

MAX bot access token — token obtained from the MAX personal cabinet.

Bot username — bot login without the @ symbol. Required for automatic binding via deep link. The value can be retrieved by pressing the bot check button.

Webhook secret — if specified, the value is compared against the X-Max-Bot-Api-Secret or X-Webhook-Secret header, provided the header is present in the request.

MAX API URL — server API address. The default value is platform-api2.max.ru.

Disable SSL verification — debugging mode only. Not recommended for production environments.

Public site URL — site address without a trailing slash. Used to construct the correct webhook URL when operating behind a reverse proxy.

Webhook URL — constructed as the public site URL or current host, followed by the path bitrix/tools/ecl_maxauth_webhook.php.

Deep link template — contains placeholders #BOT# and #TOKEN#. The default is max.ru/#BOT#?start=#TOKEN#. After substitution, this forms a path-style deep link for the bot_started.payload event.

Redirect after login — destination address after successful verify_code confirmation. The default is the root directory.

Codes Tab

Code length — number of digits in the authorization code. The allowed range is 4 to 8 digits. The default value is 6.

MAX authorization module by eCom Labs. Module settings define security parameters and interaction behavior.

The code validity time is 5 minutes by default. The maximum number of code entry attempts is 5; after exceeding this limit, the code becomes invalid. The binding token validity time in deep links is 30 minutes by default. The message template with the code is configured in MAX and supports placeholders #CODE#, #TTL#, and #LOGIN#.

The 2FA tab contains an option to require a MAX code after password login. If enabled and the user has an active binding, the system redirects to the two-factor authentication page after the authorization process and logout. The 2FA page URL is specified explicitly; if empty, the AUTH_REDIRECT address is used with parameters ?max_2fa=Y and user_id.

In the administration panel, the module is accessible via Settings → Authorization via MAX. The standard settings page (settings.php?mid=ecl.maxauth) contains the parameters described above. The Tools tab (ecl_maxauth_tools.php) includes a Webhook section displaying the webhook URL and bot name in read-only mode. A bot check via GET /me returns the MAX_BOT_NAME upon success. Webhooks can be subscribed to message_created and bot_started events, and existing subscriptions can be removed. The webhook status is shown as subscribed or not subscribed for the current URL. The Binding tab contains a Bitrix widget for selecting the site user and a field for manual entry of the MAX user_id.

The MAX authentication module by eCom Labs manages the connection between system users and MAX accounts. Available operations include manual binding via database entry (unavailable if already bound), unbinding (sets status D, considered active if previously bound), automatic binding using a token and deep link opened in a new tab without displaying the URL on the page, and status update to verify the connection.

The test tab allows selecting a user via the Bitrix widget and entering text to send a test message to the MAX account linked to that user.

In the bindings management section (file ecl_maxauth_bindings.php), a list of records is available with filters by user ID, MAX user ID, and status. The table columns include ID, a link to user edit, MAX user ID, status, number of logins, and dates. Actions include unbinding (individually or in bulk) and navigating to the user card.

On the user edit tab labeled MAX Auth, the binding status, MAX user ID, number of logins via MAX, and the date of the last login are displayed. A field for entering the MAX user ID enables manual binding. Buttons for unbinding, automatic binding via deep link in a new window, and status update are also available. If a binding already exists, the manual and automatic binding buttons become inactive, leaving only unbinding and status update options.

The ecl:maxauth component is designed for login or two-factor authentication. Its purpose is to replace or supplement standard authentication with a code from the MAX system.

MAX authentication module by eCom Labs. Configures redirection after successful login (defaulting to the root path) and controls header visibility.

The login process consists of two steps. In the first step, the user enters a login, email address, or phone number, triggering a code request. The code is delivered to the user via the MAX service. In the second step, the user enters the code, the system verifies it, and completes authorization with redirection.

Two-factor authentication mode activates when the REQUIRE_MAX_AFTER_PASSWORD flag is set and the session contains ECL_MAXAUTH[2FA_UID], or when the request includes max_2fa and user_id parameters. In this mode, the code entry step executes immediately with an automatic code request using request_code_2fa and verify_code_2fa methods.

The system tracks the countdown until code expiration and the attempt counter using an N out of M scheme. Error counts are updated from the server. Upon code expiration or exhaustion of the attempt limit, login is blocked, and a resend code button becomes available.

The ecl:maxauth.bind module provides a binding block for the user profile or personal account on the storefront. It is available only to currently authorized users. It includes a header visibility setting. Functionalities allow viewing the binding status and MAX user ID, performing manual binding by entering the MAX user ID, automatic binding via token and opening a deep link in a new tab, unbinding, and refreshing the binding status.

If “Authorization via MAX (EcomLabs)” fits the task, General iT can install the module, configure it and verify the result in the project.

YOUR PROJECT INFRASTRUCTURE

A home for your website

BEFORE YOU ORDER

Let’s go through the details.

Is installation free?
The solution itself is free. Installation, configuration and customisation services are agreed separately. A compatible platform and an appropriate platform licence are required.
How do I check compatibility?
Compare the supported editions and solution version in the technical details with your project. Before installing on a live website, we recommend making a backup and checking the solution in a test environment.
Can you help with implementation?
We can help install the module, check its settings and verify how it works in your project. Compatibility with other customisations and the scope of work are assessed before we begin.

GENERAL iT

Let’s discuss your project

Получатель: ООО «Дженерал Ай Ти Рус»

1C-BITRIX

Install solution

Enter a domain with or without https://. The installer will open in your website control panel in a new tab.

Solution screenshots

Solution screenshot