Connect Frontiva to software we have never heard of.
An API key lets your own systems read and write this practice's records. A webhook tells them the moment something happens here, so nothing has to sit and poll us.
What works today
- Create API keys in Settings, and tick exactly what each one may do. A key can never do more than the person who made it, and no key can manage billing, your team, or these settings, so one that leaks cannot issue itself a replacement.
- The key is shown once and stored only as a fingerprint, so nobody at Frontiva can read it back to you or to anyone claiming to be you.
- Revoke a key and it stops on the very next request. Revoked keys stay listed, because after an incident the question is what existed and when it was stopped.
- Point a webhook at your own address and choose which events it wants: new contacts, new leads, messages received, missed calls, tags, pipeline moves, and the appointment lifecycle (booked, cancelled, no-show).
- Every request is signed, so your end can prove it came from us and reject a replay of one it has already seen.
- We send identifiers rather than customer details, and you fetch the record with your key. It means a mistyped address cannot leak a patient's name or number.
- Send a test request from the screen and see exactly what your server answered. Failed deliveries retry for about seven hours, and an address that stays broken is switched off with a reason rather than retried forever.
- Every key issued or revoked, and every webhook added or changed, is written to your audit log. So is anything a key then does.
What's next
Incoming webhooks, so another system can push events to us the way we push them to you. The event list grows with the product: it is the same list the automation builder offers, deliberately, so anything you can build a sequence from is also something you can be told about.
Frequently asked questions
Do I need to be a developer to use this?
For this, yes. It is the escape hatch for a practice with its own software or somebody building for them. If you want Frontiva to talk to a system you already use, tell us which one: most of what people ask for is better as a proper integration than as something you maintain.
What does the webhook actually send?
A small JSON body with the event name, when it happened, and the identifiers involved, signed so you can verify it. It deliberately carries no names, phone numbers or message text: that address is one you typed, and a single wrong character should cost you a failed delivery rather than a patient's details. Fetch the record with your API key once you know it changed.
What happens if my server is down?
We retry, with increasing gaps, for about seven hours. If ten deliveries in a row fail, the endpoint switches itself off and the screen tells you why, so one broken address does not leave everything else queued behind it. Turn it back on once you have fixed your end.
Who can create keys?
Owners and Admins only. Handing out a credential that reads your records from anywhere on the internet is a different decision from connecting a channel, so it is not something a manager or a member of staff can do.
Connect API and webhooks when you're ready.
Start free - channel connections are configured per organization from Settings once you're signed up.