Dropdown Menu Item above the Task List TASK_USER_LIST_TOOLBAR, TASK_GROUP_LIST_TOOLBAR

If you are developing integrations for Bitrix24 using AI tools (Codex, Claude Code, Cursor), connect to the MCP server so that the assistant can utilize the official REST documentation.

Scope: placement, task

The widget adds its own item to the dropdown menu above the task list. The placement works with the list as a whole rather than with an individual task: the handler receives the identifier of the list owner — a user or a workgroup.

The task list of a user and the task list of a group are two different placements with different codes. Register both if the application has to work in both lists.

The placement code is specified in the PLACEMENT parameter of the placement.bind method.

The widget is not displayed in the interface until the application installation is complete. Check the application installation

Where the Widget is Embedded

Placement Code

Location

TASK_USER_LIST_TOOLBAR

Dropdown menu item above the task list of a user

TASK_GROUP_LIST_TOOLBAR

Dropdown menu item above the task list of a workgroup or project

Where to Find It in the Interface

Open the task list and click the arrow next to the button in the right part of the panel above the list. The application item appears in this menu next to the knowledge base and Bitrix24 Market items. The button itself shows the ••• icon or the name of the item opened last.

Dropdown menu item above the task list of a user

Dropdown menu item above the task list of a group

What the Handler Receives

Data is sent in a POST request: some parameters come in the handler URL query string, the rest in the request body


        Array
        (
            [DOMAIN] => xxx.bitrix24.com
            [PROTOCOL] => 1
            [LANG] => en
            [APP_SID] => 4617fa96af5d1f523fc2e2b72bd54f11
            [AUTH_ID] => 5253ba6600705a0700005a4b00000001f0f1076fef51e6d3d3c1616a9fd92a71
            [AUTH_EXPIRES] => 3600
            [REFRESH_ID] => 42d2e16600705a0700005a4b00000001f0f107cf69d8060249da353587f8ec86
            [SERVER_ENDPOINT] => https://oauth.bitrix.info/rest/
            [APPLICATION_TOKEN] => 3f0a7c19e5b84d2196c8ad470e5f2b31
            [APPLICATION_SCOPE] => task,placement
            [member_id] => da45a03b265edd8787f8a258d793cc5d
            [status] => L
            [PLACEMENT] => TASK_USER_LIST_TOOLBAR
            [PLACEMENT_OPTIONS] => {"USER_ID":"1","URI":"\/company\/personal\/user\/1\/tasks\/"}
        )
        
        

        Array
        (
            [DOMAIN] => xxx.bitrix24.com
            [PROTOCOL] => 1
            [LANG] => en
            [APP_SID] => 9f3b397a4bc09ad1ee9b7a5db991a603
            [AUTH_ID] => cc53ba6600705a0700005a4b00000001f0f107e316cd1ed3be4be6856b7077e1
            [AUTH_EXPIRES] => 3600
            [REFRESH_ID] => bcd2e16600705a0700005a4b00000001f0f1075b826a128425efbda11902d7f5
            [SERVER_ENDPOINT] => https://oauth.bitrix.info/rest/
            [APPLICATION_TOKEN] => 3f0a7c19e5b84d2196c8ad470e5f2b31
            [APPLICATION_SCOPE] => task,placement
            [member_id] => da45a03b265edd8787f8a258d793cc5d
            [status] => L
            [PLACEMENT] => TASK_GROUP_LIST_TOOLBAR
            [PLACEMENT_OPTIONS] => {"GROUP_ID":"11","URI":"\/workgroups\/group\/11\/tasks\/"}
        )
        
        

Required parameters are marked with *

Parameters in the Handler URL Query String

Parameter
type

Description

DOMAIN*
string

The Bitrix24 address where the widget handler was invoked

PROTOCOL*
string

Secure or non-secure HTTP protocol:

  • 0 - HTTP
  • 1 - HTTPS

LANG*
string

The user interface language of Bitrix24 that invoked the widget. You can localize the interface language in your widget based on this value

APP_SID*
string

Application session identifier. Bitrix24 generates a new one each time the widget is rendered and uses it to link the js library with the application environment

Parameters in the POST Request Body

Parameter
type

Description

AUTH_ID
string

Authorization token OAuth 2 issued for the user who invoked the widget. Can be used for REST API calls on behalf of this user

AUTH_EXPIRES
integer

Time in seconds after which the authorization token will become invalid

REFRESH_ID
string

Refresh token OAuth 2 issued for the user who invoked the widget. Can be used to refresh the authorization token on behalf of this user

SERVER_ENDPOINT*
string

Address of the Bitrix24 authorization server needed to refresh OAuth 2 tokens

APPLICATION_TOKEN*
string

Application token. The same value is passed in the application_token parameter when event handlers are invoked. The widget handler can use it to verify that the request came from Bitrix24

APPLICATION_SCOPE*
string

List of scopes granted to the application, separated by commas. Shows which REST API methods are available with the authorization token received

member_id*
string

Unique string identifier of Bitrix24 where the widget handler was invoked.

status
string

Type of application that registered the handler for this widget. Accepts values:

  • L - local application
  • F - free mass-market application
  • D - demo version of a mass-market application
  • T - trial version of a mass-market application, time-limited
  • P - paid mass-market application

PLACEMENT*
string

The placement code. You can use the same handler URL for all your widgets. The value that Bitrix24 will report in the PLACEMENT parameter will help determine from which specific placement your handler was invoked in each case

PLACEMENT_OPTIONS
string

Additional data in the form of a JSON string that defines the context of the widget execution. For example, this could be an array containing the numeric identifier of the CRM object in the detail form where the widget handler was invoked, etc. The PLACEMENT_OPTIONS parameter, along with the PLACEMENT parameter, allows you to accurately determine for which specific placement and object the widget handler was invoked

Bitrix24 adds a URI key to PLACEMENT_OPTIONS — the path with the query string of the page from which the widget was opened. It arrives for any placement, along with the keys of that placement itself. The key is absent if the browser did not send the Referer header or if the widget was opened from a page on a different domain.

How to Parse the Call Context

PLACEMENT_OPTIONS arrives as a JSON string, not as an array: parse it on the handler side before use. The set of keys is specific to each placement and is described in the PLACEMENT_OPTIONS section of this page.

$placement = $_POST['PLACEMENT'] ?? '';
        $options = json_decode($_POST['PLACEMENT_OPTIONS'] ?? '{}', true);
        
options = json.loads(request.form.get("PLACEMENT_OPTIONS", "{}") or "{}")
        

In B24JsSDK, there is no need to parse the string: the $b24.placement.options property returns a ready object, and $b24.placement.placement returns the placement code.

What the Handler Must Return

The handler responds with a regular HTML page — Bitrix24 displays it in a frame in place of the widget. The page must allow embedding: if the application server sends the X-Frame-Options or Content-Security-Policy headers that prohibit framing, an empty area remains in place of the widget. How to fix it is described in the article Site Does Not Allow Connection.

PLACEMENT_OPTIONS

The PLACEMENT_OPTIONS value is passed as a JSON string with the call context. In addition to the universal URI key, the context carries the key of the placement itself: each placement has its own.

Required parameters are marked with *

Parameter

Description

USER_ID*
string

Identifier of the user whose task list the widget is opened above. Arrives only for the TASK_USER_LIST_TOOLBAR placement.

User data is returned by the user.get method

GROUP_ID*
string

Identifier of the workgroup or project whose task list the widget is opened above. Arrives only for the TASK_GROUP_LIST_TOOLBAR placement.

Group data is returned by the sonet_group.get method

Code Examples

How to Use Examples in Documentation

curl -X POST \
          -H "Content-Type: application/json" \
          -H "Accept: application/json" \
          -d '{
            "PLACEMENT": "TASK_USER_LIST_TOOLBAR",
            "HANDLER": "https://your-domain.com/widgets/task-list-toolbar-handler.php",
            "TITLE": "My task list item",
            "LANG_ALL": {
              "en": {
                "TITLE": "My task list item"
              },
              "de": {
                "TITLE": "Mein Aufgabenlisten-Element"
              }
            },
            "auth": "**put_access_token_here**"
          }' \
          https://**put_your_bitrix24_address**/rest/placement.bind
        
// This snippet is an ES module: top-level await requires type="module" or a bundler.
        // $b24 is an already-initialized SDK instance (see the SDK "Get started" guide).
        import { Text } from '@bitrix24/b24jssdk'
        import type { B24Frame } from '@bitrix24/b24jssdk'
        
        declare const $b24: B24Frame
        
        try {
          const response = await $b24.actions.v2.call.make<boolean>({
            method: 'placement.bind',
            params: {
              PLACEMENT: 'TASK_USER_LIST_TOOLBAR',
              HANDLER: 'https://your-domain.com/widgets/task-list-toolbar-handler.php',
              TITLE: 'My task list item',
              LANG_ALL: {
                en: {
                  TITLE: 'My task list item',
                },
                de: {
                  TITLE: 'Mein Aufgabenlisten-Element',
                },
              },
            },
            requestId: Text.getUuidRfc4122()
          })
        
          // The payload is available only on a successful response
          if (!response.isSuccess) {
            console.error(response.getErrorMessages().join('; '))
          } else {
            const result = response.getData()!.result
            console.info('Placement bound successfully:', result)
          }
        } catch (error) {
          // Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
          console.error(error)
        }
        
<!-- Load the SDK (UMD build); it is exposed as the global B24Js -->
        <script src="https://unpkg.com/@bitrix24/b24jssdk@1/dist/umd/index.min.js"></script>
        <script>
          async function bindTaskUserListToolbar() {
            try {
              // Initialize the SDK inside a Bitrix24 frame
              const $b24 = await B24Js.initializeB24Frame()
        
              const response = await $b24.actions.v2.call.make({
                method: 'placement.bind',
                params: {
                  PLACEMENT: 'TASK_USER_LIST_TOOLBAR',
                  HANDLER: 'https://your-domain.com/widgets/task-list-toolbar-handler.php',
                  TITLE: 'My task list item',
                  LANG_ALL: {
                    en: {
                      TITLE: 'My task list item',
                    },
                    de: {
                      TITLE: 'Mein Aufgabenlisten-Element',
                    },
                  },
                },
                requestId: B24Js.Text.getUuidRfc4122()
              })
        
              // The payload is available only on a successful response
              if (!response.isSuccess) {
                console.error(response.getErrorMessages().join('; '))
                return
              }
        
              const result = response.getData().result
              console.info('Placement bound successfully:', result)
            } catch (error) {
              // Thrown on transport or SDK failures (AjaxError, SdkError, etc.)
              console.error(error)
            }
          }
        
          document.addEventListener('DOMContentLoaded', bindTaskUserListToolbar)
        </script>
        
try {
            $response = $b24Service
                ->core
                ->call(
                    'placement.bind',
                    [
                        'PLACEMENT' => 'TASK_USER_LIST_TOOLBAR',
                        'HANDLER' => 'https://your-domain.com/widgets/task-list-toolbar-handler.php',
                        'TITLE' => 'My task list item',
                        'LANG_ALL' => [
                            'en' => [
                                'TITLE' => 'My task list item',
                            ],
                            'de' => [
                                'TITLE' => 'Mein Aufgabenlisten-Element',
                            ],
                        ],
                    ]
                );
        
            $result = $response->getResponseData()->getResult();
            if ($result->error()) {
                error_log($result->error());
            } else {
                echo 'Success: ' . print_r($result->data(), true);
            }
        } catch (Throwable $e) {
            error_log($e->getMessage());
            echo 'Error binding placement: ' . $e->getMessage();
        }
        
BX24.callMethod(
            'placement.bind',
            {
                PLACEMENT: 'TASK_USER_LIST_TOOLBAR',
                HANDLER: 'https://your-domain.com/widgets/task-list-toolbar-handler.php',
                TITLE: 'My task list item',
                LANG_ALL: {
                    en: { TITLE: 'My task list item' },
                    de: { TITLE: 'Mein Aufgabenlisten-Element' }
                }
            },
            function(result) {
                if (result.error()) {
                    console.error(result.error());
                } else {
                    console.log(result.data());
                }
            }
        );
        
require_once('crest.php');
        
        $result = CRest::call(
            'placement.bind',
            [
                'PLACEMENT' => 'TASK_USER_LIST_TOOLBAR',
                'HANDLER' => 'https://your-domain.com/widgets/task-list-toolbar-handler.php',
                'TITLE' => 'My task list item',
                'LANG_ALL' => [
                    'en' => [
                        'TITLE' => 'My task list item',
                    ],
                    'de' => [
                        'TITLE' => 'Mein Aufgabenlisten-Element',
                    ],
                ],
            ]
        );
        
        echo '<PRE>';
        print_r($result);
        echo '</PRE>';
        
// client and ctx are already created — see the Go SDK section
        res, err := client.Core().Call(ctx, "placement.bind", b24.Params{
        	"PLACEMENT": "TASK_USER_LIST_TOOLBAR",
        	"HANDLER":   "https://your-domain.com/widgets/task-list-toolbar-handler.php",
        	"TITLE":     "My task list item",
        	"LANG_ALL": b24.Params{
        		"ru": b24.Params{
        			"TITLE": "My task list item",
        		},
        		"en": b24.Params{
        			"TITLE": "My task list item",
        		},
        	},
        })
        if err != nil {
        	return fmt.Errorf("placement.bind: %w", err)
        }
        
        // The response arrives as json.RawMessage — unmarshal it into the response
        // shape of the placement.bind method, see "Response Handling" on its page.
        fmt.Printf("%s\n", res.Result)
        

Continue Learning