Integrations
What the agent captures is worth nothing stuck in here. Every booking, message, lead, screening and handover can be sent to an address you choose, the moment it happens.
One address, not thirty ready-made connectors — because the connection to your CRM, your calendar, your invoicing software or the software your company wrote is built by us, from scratch, around your system. We do not use third-party automation services. Talk to us to scope the connection you need.
Available from the Pro plan upwards.
Setting it up
In the agent's settings, Send it to your own tools:
- Paste the destination address. It has to start with
https://. - Choose what to send — just the bookings, for instance.
- Press Send a test. It arrives in seconds, shaped exactly like a real delivery.
The address is checked the moment you save it. If it is refused, we say why.
What you receive
A POST with Content-Type: application/json:
{
"event": "booking.created",
"at": "2026-08-07T10:32:11.204Z",
"data": {
"id": "bk_7Kd2…",
"kind": "booking",
"channel": "voice",
"contactName": "Ana Silva",
"contactPhone": "+351910000000",
"contactEmail": null,
"scheduledFor": "2026-08-12T15:00:00.000Z",
"notes": "First consultation."
}
}
The events are booking.created, message.taken, lead.captured, screening.recorded,
document.requested and handover.
Checking it really came from us
Your address is public. Without a check, anyone who finds it can create fake bookings in your CRM.
Every delivery carries three headers:
| Header | What it is |
| --- | --- |
| x-nexiagent-event | The event, so you can route without reading the body. |
| x-nexiagent-timestamp | Seconds since 1970, included in the signature. |
| x-nexiagent-signature | HMAC-SHA256 of {timestamp}.{body}, in hex. |
The signing key is on the same screen. In Node:
import { createHmac, timingSafeEqual } from "node:crypto";
function isValid(rawBody, headers, key) {
const ts = headers["x-nexiagent-timestamp"];
const got = Buffer.from(headers["x-nexiagent-signature"] ?? "");
const want = Buffer.from(
createHmac("sha256", key).update(`${ts}.${rawBody}`).digest("hex"),
);
// Refuse anything stale: without this, a captured delivery can be replayed.
if (Math.abs(Date.now() / 1000 - Number(ts)) > 300) return false;
return got.length === want.length && timingSafeEqual(got, want);
}
In Python:
import hmac, hashlib, time
def is_valid(raw_body: bytes, headers, key: str) -> bool:
ts = headers.get("x-nexiagent-timestamp", "")
if abs(time.time() - float(ts or 0)) > 300:
return False
want = hmac.new(
key.encode(), f"{ts}.".encode() + raw_body, hashlib.sha256
).hexdigest()
return hmac.compare_digest(want, headers.get("x-nexiagent-signature", ""))
Two things that usually go wrong:
- Sign the raw body, exactly as it arrived. Decode and re-encode it and one extra space changes the signature.
- Compare in constant time (
timingSafeEqual,compare_digest). A plain===leaks, through how long it takes, how many characters you got right.
When your endpoint is down
We do not drop it. We try again after 1 minute, 5, 25, about 2 hours and about 10 — six attempts across half a day, which covers a deploy, an expired certificate, or your provider having a bad afternoon.
If it still fails after that, the delivery is marked failed and the address shows Not getting through along with the exact error. Recent attempts are listed on the same screen.
Answer 2xx for us to count it delivered. Answer quickly — if you take longer than 10
seconds we abandon that attempt. If you have slow work to do, store what arrived and do it
afterwards.
What we will not accept
The address is used by our servers, so:
httpsonly. Your customers' details do not travel unencrypted.- Public addresses only. We refuse
localhost,127.0.0.1,10.x,192.168.x,169.254.xand their IPv6 equivalents — checked after resolving the name, not just from the text of the address.
This is not red tape: without those two rules, an address pointed inwards would make our servers read our own infrastructure on your behalf.
Security
- The signing key is a secret. Keep it the way you keep a password.
- If you think it has been exposed, remove the address and create it again — the new key is different.
- We never ask you for the password to any of your tools.