API integration services connect the systems your business already runs, such as Shopify and Xero or HubSpot and Sage, so orders, invoices, customers and stock move between them without anyone re-keying. A two-way integration with webhooks, retries and monitoring typically goes live in 5 to 8 weeks, and a simple one-way sync in 2 to 4 weeks. Fixology builds integrations to the standard we expect of the UK's leading software development company: protected against duplicates, watched around the clock, and running in your own cloud account under app registrations in your name.
Systems we connect, and what usually flows between them
- Accounts: Xero, Sage 50, Sage 200, Sage Intacct and QuickBooks. Sales invoices, credit notes, supplier bills, payments, contacts, tracking categories and VAT codes.
- CRM: HubSpot, Salesforce and Dynamics 365. Won deals become orders or projects, accounts and contacts stay in step with the finance system, and invoice status shows on the CRM record.
- Ecommerce: Shopify and WooCommerce. Orders, refunds, stock levels and fulfilment updates to and from an ERP, a warehouse or a 3PL.
- Payments: Stripe and GoCardless, reconciled automatically in Xero or Sage, with each payout matched to the invoices it settles.
- Everything else: Microsoft 365 and SharePoint, Twilio for SMS, carrier APIs for labels and tracking, EDI with larger trading partners, and older in-house systems with a database but no API.
Integration platform or custom code
This is the first decision, and the honest answer depends on volume, complexity and who will maintain it.
| Approach | Good for | Volume it handles well | Main risk |
|---|---|---|---|
| Native app or marketplace connector | Standard pairs such as Shopify to Xero or HubSpot to Xero | Whatever the vendor designed for | Fixed mapping that may not match your VAT, tracking or product rules |
| Zapier, Make or Power Automate | Simple steps and quick wins | Hundreds of runs a month | Silent failures and logic spread across many flows |
| Enterprise iPaaS (Boomi, Workato, MuleSoft, Azure Logic Apps) | Large estates with many systems and an in-house integration team | High | Specialist skills that are hard to hire for |
| Custom integration service | Complex mapping, business rules, legacy systems | High, scaled to your peaks | Needs a team that looks after it |
We build custom integrations, but we also recommend the first two rows regularly. If you are weighing up the low-code tools, our comparison of Zapier, Make and n8n is a good place to start.
Webhooks, retries and idempotency: the unglamorous bit that matters
Most integrations work on the day of the demo. The difference shows up three months later, on a busy Monday, when one API is slow and another sends the same event twice.
- Webhooks first, polling as a safety net. Shopify, HubSpot, Stripe and Xero can all notify us when something changes. A scheduled check catches anything a webhook missed.
- Acknowledge fast, process later. Per Shopify's webhook documentation, a delivery fails if your app does not respond within five seconds, and Shopify retries failed calls up to eight times in four hours. So we put every event on a queue and reply at once, then do the slow work in the background.
- Idempotency. Because events can arrive twice, every one is stored with its ID, and processing the same event again does nothing. Without this, a retried order webhook creates a second invoice in Xero, which is the most common integration bug businesses bring to us.
- Retries with backoff. If Xero or Sage is rate limiting or down, we wait and try again with growing gaps, rather than hammering the API or giving up.
- A dead letter queue. Events that still fail after retries are parked with the error, so someone can fix the data and replay them with one click.
- Signature checks. Incoming webhooks are verified with the sender's signing secret, so nobody can post fake orders to your endpoint.
Mapping data between systems is where the time goes
Connecting to an API takes days. Agreeing what the data means takes longer, and it needs someone from finance or operations in the room.
- Which system owns each field. If a customer's address changes in HubSpot and in Xero on the same day, which wins? We write a field by field ownership table during discovery.
- Matching records. Customers matched by email, account number or company number; products by SKU, with a plan for the SKUs that do not match.
- VAT and rounding. Ecommerce platforms often calculate VAT per line while accounts packages total it per invoice, which leaves penny differences that break reconciliation. We decide the rule up front and post rounding to a named account.
- Tracking and nominal codes. Sales by channel, region or department need to land on the right Xero tracking category or Sage department every time.
Monitoring, so you hear about failures before customers do
Every integration we build comes with a small dashboard and alerting, because an integration nobody watches will eventually fail quietly.
- A status page showing the last successful sync, events processed today, events waiting and events failed.
- Alerts by email or Microsoft Teams when failures pass a threshold, when the queue backs up, or when an OAuth connection needs reauthorising.
- A nightly reconciliation that counts records on both sides (orders in Shopify against invoices in Xero, for example) and reports any difference.
- Logs that record what happened to each record, without storing personal data you do not need.
After launch, our support and maintenance plans include watching these alerts and handling API changes, since Xero, HubSpot and Shopify all version and retire endpoints over time.
Testing an integration against the failures it will meet
An integration is only proven when it has handled bad days on purpose. Before anything touches live data, we test it against the situations that break weaker builds:
- Recorded real payloads. Sample orders, invoices and contacts from your own sandbox accounts, replayed through the mapping on every code change.
- Duplicates and out-of-order events. The same webhook sent twice, an update arriving before the create, a cancellation for an order the other system has never seen.
- Outages and throttling. One API made slow or unavailable for an hour, to confirm events queue up and drain cleanly afterwards.
- Awkward data. Zero-rated and mixed VAT lines, foreign currency, long product names, accents in customer names and deleted records.
You see the results at the demo, including what failure looks like on the dashboard, so the first real outage is a known event rather than a surprise.
When you do not need a developer for this
Check the app marketplaces first. Shopify, HubSpot and Xero each run an app marketplace full of ready-made connectors, and for a standard pair with standard rules a ready-made app is the sensible choice. Low-code tools are fine for a few hundred records a month where a failure is an inconvenience rather than a problem.
Come to us when the ready-made connector nearly fits but gets VAT, discounts or multi-currency wrong, when volumes are high, when one of the systems is old or bespoke, or when the integration is part of a bigger workflow. Integrations are often one piece of a larger job, such as a customer portal or a custom ERP, and we build them the same way in both cases.
A six week integration, step by step
- Week 1, discovery: API review for both systems, sample data exports, the field ownership table and the failure rules. You get a specification and a delivery plan.
- Weeks 2 and 3: the integration service, queue and mapping, built against sandbox accounts (a Xero demo company, a Shopify development store, a HubSpot test portal).
- Week 4: retries, duplicate protection, alerts and the monitoring dashboard, demonstrated with deliberately broken data.
- Week 5: backfill of historical records, then a week running in shadow mode where the integration logs what it would do while staff carry on by hand, so both can be compared.
- Week 6: switch on, with the manual process kept as a fallback for the first fortnight.
API development: opening your own system to partners
We also do the opposite job: building a documented API on top of your own software so customers, partners or a mobile app can connect to it. A good API is a product in its own right, and partners judge your business by how easy it is to use.
- REST with an OpenAPI specification, so partners get accurate documentation and can generate client code in their own language.
- OAuth 2.0 or scoped API keys, with each partner limited to the data and actions they need.
- Rate limits and quotas per client, so one partner's runaway script cannot slow the system for everyone else.
- Versioning and deprecation notices, so changes never break an integration someone else has built.
- A sandbox environment and webhooks of your own, so partners can build and test without touching live data.
App registrations, keys and code held in your company's name
Ownership matters more with integrations than people expect. The app registrations in the Xero, HubSpot or Shopify developer portals are created under your company's account, the API keys sit in your own secrets vault, and the code is in your repository from day one. The contract assigns all IP to you. If we disappeared, nothing would stop working and another developer could take over in days. Our article on software development contracts lists the clauses that make this so.
Integrations move personal data between processors, so they need the same care as any system. We request the narrowest OAuth scopes each API allows, store secrets in Azure Key Vault or AWS Secrets Manager rather than in code, and keep logs free of personal data beyond what is needed to trace a record. Services run in a UK or EU region, and we sign an Article 28 data processing agreement before connecting to live systems. More on our approach is on the security page.