Integrations and APIs

Connecting your system to the ones outside it is where the time goes: tokens that expire, rate limits, retries and notifications that arrive twice. We keep every major social network integrated at once, and a public API that third parties consume.

Who it is for
Teams with a working system that now needs to talk to another one: a supplier, a marketplace, an ERP, or their own customers.
Deliverable
Integration in production · tested against the real API, not against mocks

What it includes

  • The whole integration, not the API call: OAuth sign-up, token renewal, the permissions the provider reviews, and telling the user when it is time to reconnect.
  • Queues, retries and rate control with a ceiling nothing can go above even when everything fails, because some providers block by IP and take down all of your customers at once.
  • Incoming webhooks verified by signature, idempotent (the same notification twice duplicates nothing) and answered before they are processed.
  • Your own public API: OpenAPI, per-customer credentials, outgoing webhooks and versioning, so whoever integrates it never has to ask you anything.
  • Tests that talk to the real API on top of the mocked ones, and a panel showing which integration is down and since when.

Where it gets hard

A mocked contract proves nothing

Tests against made-up responses stay green forever: they pass on the day the provider retires an endpoint and on the day it starts demanding a new field. That is why every integration also has a suite that talks to the real API, and that is the one that finds what matters.

The token expires at 3 a.m.

Almost no permission lasts forever, and the one that expires warns nobody. It has to be renewed ahead of time, a temporary failure told apart from a final one, and the user warned in their panel, because re-authorising is something only they can do.

The rate limit belongs to everyone

Providers count requests per application or per IP, not per customer. One noisy customer, or one bug retrying without a brake, locks out the rest. The only guarantee worth anything is arithmetic: a global ceiling the code cannot go above.

The proof

PlanVortex keeps every major social network integrated at once, each with its own OAuth, its limits and its notifications. Its public API is documented with OpenAPI and has libraries on npm and PyPI. And we are not its only client: TalkToCart has consumed it since 2024.

Check it at
planvortex.com · talktocart.com

What we have written about this

How we work

Half an hour of conversation, a closed proposal with scope, price and date, a deployed increment every two weeks in an environment you can log into, and handover. The four steps are on the home page.

Frequently asked questions

What if the provider changes its API?
It happens constantly and not always with notice. That is why the integrations we maintain have tests that talk to the real API and run on their own: the change shows up there, not in an angry customer's phone call.
Does the provider have to approve the integration?
Often yes, and it is the deadline that compresses least: Meta, Google or TikTok review the application and its permissions before letting it into production. It goes into the calendar from the proposal onwards, together with what has to be prepared (video, privacy policy, verified domain) so the first round is not lost.
Can you integrate an internal API of ours, not just the well-known ones?
Yes, and sometimes it is simpler. The work is the same: document it, give it authentication and rate control, and leave it with a reference other teams can read without calling you.