Case study

Automated Middleware Integration

Two systems. One reliable source of truth.

PHP 8 OAuth 2.0 Five-minute sync Structured audit logging

Authoritative data

Third-party source system

New and changed records originate here.

Secure middleware

Local synced copy

Client-facing platform

Fast, current records for end users.

OAuth 2.0 Every 5 minutes

Connect / Validate / Synchronise

01

Authenticate

Secure server-side connection using OAuth 2.0.

02

Request changes

Pull only records changed since the last run.

03

Match by ID

Find the correct local record using its unique reference.

04

Update safely

Create, update or flag without duplicating data.

05

Log the run

Record the outcome and any recoverable errors.

One secure bridge. No manual re-entry.

The challenge

Critical records were trapped in the wrong system.

The client-facing platform and the third-party system holding the authoritative records had no native way to exchange data.

Without a secure bridge, staff would have needed to monitor the source system and copy information manually. That meant slow updates, avoidable errors and data that could become outdated almost immediately.

01

Disconnected systems

One platform had no visibility into records that were created or changed in the other.

02

Manual cross-checking

Keeping both sides current would have depended on repeated checking and retyping by staff.

03

No reliable match

Without a shared reference, duplicate or conflicting records were a genuine operational risk.

Automated middleware

Sync overview

Scheduled

Source authentication

Server-side OAuth 2.0 client credentials

Secure

Change detection

New and updated records since the previous run

Incremental

Record matching

Unique source reference mapped to local data

Duplicate-safe

Error recovery

Failures logged and retried on the next cycle

Resilient

Administrator controls

Visible status, rolling log and Sync Now override

Auditable

What we built

A secure integration that keeps itself up to date.

01

Server-side integration layer

Credentials and access tokens remain on the server and are never exposed to end users.

02

Scheduled sync engine

A background job runs every five minutes and requests only records that are new or changed.

03

Reference-ID upsert logic

Existing records are updated, new records are created and closed records are flagged without duplication.

04

Audit and fail-safe handling

Each run records what changed. Timeouts, rate limits and outages are logged without corrupting existing data.

05

Admin visibility and control

Administrators can view sync status and logs or trigger an immediate update using Sync Now.

The result

Manual cross-checking replaced by an automated five-minute cycle.

The completed integration handles authentication, change detection, record matching and error recovery against the live third-party API.

The client-facing platform reads from its own fast, synchronised copy, while every run remains visible and auditable. Final field verification and client sign-off are the remaining steps before go-live.

Its modular, hook-based architecture also supports a phased rollout and future changes to the schedule, sync logic or destination fields without rebuilding the integration.

AutomatedAuditableBuilt to extend
05

Minute sync cycle

Near-real-time updates without anyone having to start a batch.

ID

Reliable matching

Every incoming record is checked against its unique source reference.

LOG

Full audit trail

Added, updated and closed records are recorded for every run.

↻

Automatic recovery

Temporary failures are logged and safely retried on the next cycle.

Technology used

PHP 8OAuth 2.0Client credentialsScheduled cronReference-ID upsertsStructured logging

Connect your systems

Have systems that should be talking to each other?

We build secure integrations that remove manual work and keep business data moving.

Start a project

Wait a moment

Carta