API integration connects the systems a business already runs, so data moves between them without anyone copying it by hand. A typical SME has a website, a CRM, accounting or ERP software such as bexio, Xero or Abacus, a payment provider, an email tool and analytics, and often a person who retypes orders from one into another. Sensaria designs and builds these integrations for companies in Switzerland and abroad. We define which system owns which data, move it through REST APIs and webhooks, and monitor every flow, so a failure shows up as an alert and not as a missing invoice three weeks later.

Which systems does an integration connect?

Most projects link the same chain: website, CRM, ERP or accounting, payment provider, marketing automation and analytics, with AI services reading and writing under strict permissions. Each link is a separate flow with its own trigger, direction and owner of the data. Mapping these flows before building is what keeps two systems from overwriting each other.

Flow Trigger Data System of record
Website → CRM Form submitted Contact, deal, source, UTM CRM
CRM → ERP or accounting Deal won Customer, order, draft invoice ERP for customer master and invoices
Payment provider → ERP and CRM Signed webhook Payment, refund, dispute Payment provider for payment status
Shop → CRM and email Order event Customer, order, consent Shop for orders
CRM → marketing automation Segment or consent change Contact, segment, consent CRM for consent
Systems → analytics Server-side event Conversions, revenue by source Analytics holds a reporting copy
AI service ↔ systems Tool call Allow-listed reads and writes The system being called

Direct API, middleware or an integration service?

Use a direct API connection for two systems and a simple mapping. Use no-code middleware such as Zapier, Make or n8n when volumes are low and ready-made connectors exist. Build a small integration service with its own queue and database when several systems, business rules, audit requirements or volume are involved. Many companies end up with a mix: middleware for notifications, a service for money and orders.

Option Strengths Limits
Direct API connection Few moving parts Fails silently without monitoring
No-code middleware Quick to set up; many connectors Per-task pricing; limited error handling and versioning
Custom integration service Retries, audit log, tests, business rules Code to maintain, which you own

How do you make an integration reliable?

Assume every call can fail, arrive twice or arrive out of order, and design for it. That means verifying signatures on incoming webhooks, processing each event once using an idempotency key, retrying failures with back-off, respecting rate limits and logging every event with an ID you can trace. Then monitor the business result, not only the process.

  • Signed webhooks and idempotency. Stripe and Shopify, for example, sign their webhooks and retry failed deliveries, so the same event can arrive more than once, and not always in order. We verify the HMAC signature before processing and record each event ID, so a replay never creates a second invoice. Webhooks we send are signed too, retried, and disabled automatically for endpoints that keep failing.
  • Retries and a dead-letter queue. Failed jobs retry with back-off. Jobs that keep failing move to a dead-letter queue, where they can be inspected and replayed.
  • Rate limits and incremental sync. Syncs page through data with cursors and slow down when a provider throttles. The affiliate reactivation system reads its source platform at one request per second, backs off on throttling and writes with idempotent upserts.
  • Least privilege. That same integration can call only an allow-list of read operations, enforced in two layers and proven by a test. Credentials live in a secret store, never in the code.
  • Monitoring and reconciliation. Alerts on error rates and queue backlog, plus a scheduled check that compares counts, for example payments at the provider against paid invoices in accounting.

Who owns the data?

Every field has one system of record, and the integration copies from it rather than deciding. Customer master data usually belongs to the ERP, consent to the CRM, payment status to the payment provider. For personal data processed in Switzerland, the revised FADP allows disclosure to a service abroad only to a country with adequate protection or with safeguards such as standard contractual clauses, and the GDPR sets similar rules for transfers out of the EU. The integration map therefore shows which flows cross those borders. API keys should be registered in your accounts, and the code and documentation are handed over to you.

Accounting systems and your own APIs

SMEs often run bexio or Abacus in Switzerland, or Xero, QuickBooks or Microsoft Dynamics elsewhere, for accounting and ERP, next to e-banking, a shop platform and a CRM. What an integration can do depends on the API the vendor offers for your edition and license, so we check scopes, limits and test access during discovery before promising a flow.

We also build APIs. PingMyUsers publishes a REST API with an OpenAPI document, plus a read-only MCP server that AI agents can query. The affiliate recruitment engine runs its discovery sources through a job queue with retries, back-off and a dead-letter queue.

What drives cost and timeline

Driver Why it matters
Systems and flows Each flow needs mapping, tests and monitoring
API quality Missing endpoints, tight rate limits or no sandbox add work
Data mapping Different customer, product or tax models must be reconciled
Historical data Initial import and cleanup before the live sync
Error handling Money and orders need reconciliation; notifications usually don’t
Hosting and security Where the service runs, access control, audit log

After a short discovery we send a fixed-price or phased proposal.

How it connects

Integrations are the plumbing behind CRM automation, marketing automation, online shops and custom CRM and ERP systems. For company-wide process design, see internal business systems.

Why Sensaria

We have designed and published REST APIs, built incoming and outgoing webhooks with signatures and retries, connected third-party platforms over OAuth 2.0, built for Shopify and WooCommerce, and run job queues with dead-letter handling. We write integrations as tested code with logs and runbooks. Sensaria AG is based in Lugano and works in English, Italian, German and French.

What's included

API & System Integrations

  1. 01

    REST API integrations

    Connections to CRM, ERP, shop, payment and marketing platforms through their APIs, with OAuth 2.0 or scoped API keys.

  2. 02

    Webhooks

    Incoming webhooks verified by signature and processed once per event; outgoing webhooks signed, retried and disabled after repeated failures.

  3. 03

    Data synchronization

    Incremental sync with cursors, a system of record per field and explicit rules for conflicts and deletions.

  4. 04

    Middleware and integration services

    Small queue-based services for business-critical flows, or a configured no-code tool where that is enough.

  5. 05

    Payment integrations

    Payment, refund and dispute events from the payment provider reflected in accounting, the CRM and customer receipts.

  6. 06

    CRM and ERP integrations

    Customers, deals, orders and invoices kept consistent between CRM, ERP or accounting, and the online shop.

  7. 07

    Third-party and custom APIs

    Integrations with partner and industry platforms, and OpenAPI-documented APIs for your own systems, including access for AI agents via MCP.

  8. 08

    Monitoring and reconciliation

    Structured logs with an event ID, alerts on errors and backlog, a dead-letter queue for replays, and scheduled count checks.

Typical scenarios

Typical scenarios

  • Website to CRM to accounting

    A web inquiry becomes a CRM deal; the won deal creates the customer and a draft invoice in accounting, without retyping.

  • Payments reconciled automatically

    Payment-provider events mark invoices as paid, update the CRM and trigger the receipt; a daily check flags anything that doesn't match.

  • Shop and ERP in sync

    Orders flow from the shop to the ERP, and stock and prices flow back, with clear rules for which system wins.

  • Replacing fragile no-code chains

    A tangle of automations that fail silently becomes one tested service with retries, logs and alerts.

  • Opening your data to partners or AI agents

    A documented REST API or MCP server with read-only scopes, rate limits and per-client keys.

FAQ

Frequently asked questions

What is API integration?

API integration connects two or more software systems through their application programming interfaces, so data moves automatically: a web form creates a CRM deal, a won deal creates an invoice, a payment marks the invoice as paid. A good integration also handles failure: it retries, avoids duplicates, logs every event and alerts someone when a flow stops.

Should we use Zapier or Make, or build a custom integration?

No-code tools such as Zapier, Make or n8n work well for low volumes, standard connectors and notifications where an occasional failure does little harm. A custom integration service is the better choice when money, orders or customer records are involved, when several systems and business rules interact, or when per-task pricing grows with volume. Many setups combine both.

Can you integrate our accounting software with our CRM or shop?

Usually yes. bexio and Abacus, widely used in Switzerland, and tools such as Xero or QuickBooks offer APIs, but what they allow depends on your edition, license and the objects you need, such as customers, orders or invoices. We check API access, scopes and limits during discovery, then propose the flows that are actually possible, for example won deals creating invoices or payment status flowing back to the CRM.

What happens when one of the connected systems is down?

Events wait in a queue and are retried with increasing delays until the system responds again. Events that still fail go to a dead-letter queue, where they can be inspected and replayed without creating duplicates, because every event carries an idempotency key. Monitoring alerts the responsible person when errors or backlog pass a threshold.

How do you secure webhooks and API credentials?

Incoming webhooks are accepted only with a valid signature, usually an HMAC computed with a shared secret, and each event ID is processed once. Credentials are stored as secrets outside the code, limited to the permissions a flow needs, and rotated when people leave. Services that fetch URLs supplied from outside are protected against requests into internal networks (SSRF).

Who owns the integration and the data?

Your data stays in your systems; the integration moves copies according to a documented map of which system owns each field. API keys and webhook endpoints should be registered in your own accounts, not the integrator's. At handover you receive the source code, the field mappings and a runbook for failures and replays.

How long does an integration project take?

A single flow between two systems with good APIs, such as website forms into the CRM, takes days to a few weeks including tests. A project with ERP, payments and historical data runs longer, mostly because of data mapping and reconciliation. We deliver flow by flow, so each part is live and monitored before the next one starts.

Technology we use

  • REST
  • OpenAPI
  • Webhooks (HMAC)
  • OAuth 2.0
  • GraphQL
  • Python
  • Node.js
  • PostgreSQL
  • Redis
  • BullMQ
  • Stripe
  • Shopify
Technology

Tell us about your project

Website, CRM, ERP, payment provider, marketing automation, analytics and AI connected through REST APIs and signed webhooks, with idempotent processing, retries and monitoring you can check.