Guide
Connect Entriva to your other systems
When someone finishes answering on WhatsApp, their answers can go straight into the system you already use: a membership system, a CRM such as Salesforce or HubSpot, accounting such as Sage or Xero, an HR system, or a spreadsheet. Nobody retypes anything.
Two ways to connect
- Send answers automatically. You paste one address into Entriva, and each person's answers are sent there the moment they finish. Works with Zapier, Make, Power Automate, and any system that can receive a web request. Included on every plan.
- Fetch them with the API. Your developer asks Entriva for finished answers whenever your system is ready. Part of the Network plan.
Sending answers to another system is not available for health organisations yet, such as dental practices. They can download everyone's answers as Excel, or use the API.
Set it up with Zapier, no code needed
- Start a Zap that listens for Entriva. In Zapier, create a Zap. For the trigger, choose “Webhooks by Zapier” and then “Catch Hook”. Zapier gives you an address that starts with https://hooks.zapier.com. Copy it.
- Paste the address into Entriva. In Entriva, open Settings. Under “Send answers to your own system”, paste the address and press Start sending. Only the account owner can do this.
- Send a test. Press Send a test in Entriva, then Test trigger in Zapier. Zapier shows a made-up person, Thandi Example, answering your real questions, so you can set up the next step before anyone real has finished.
- Choose where the answers go. Add an action step for the system you use: for example, create a contact in Xero or Sage Accounting, a lead or account in Salesforce, a contact in HubSpot, or a row in Google Sheets. Match its fields to Entriva’s: Person Full Name, Person Phone, and each answer under Answers By Key.
- Turn the Zap on. From now on, each person who finishes arrives in your system within moments. Every send is listed in Entriva Settings and on the Audit Trail.
Zapier's webhook step is part of its paid plans. In Make, use the Webhooks module's Custom webhook; in Power Automate, the trigger “When a HTTP request is received”. The steps are the same: copy the address it gives you, paste it into Entriva, and send a test.
What your system receives
A POST with a JSON body, one per person who finishes. This is what a test send looks like for an organisation that onboards suppliers:
{
"event": "onboarding.test",
"schema_version": 1,
"delivery_id": "5d1c3f0e-2b9a-4c67-9f11-0a8e2d7b4c55",
"sent_at": "2026-09-30T08:15:00.000Z",
"test": true,
"organisation": {
"name": "Your organisation",
"kind": "general"
},
"onboarding": {
"id": "00000000-0000-4000-8000-000000000000",
"invited_at": "2026-09-30T08:15:00.000Z",
"completed_at": "2026-09-30T08:15:00.000Z",
"link": "https://www.entriva.co.za/dashboard/intakes/00000000-0000-4000-8000-000000000000"
},
"person": {
"full_name": "Thandi Example",
"phone": "0820000000",
"phone_international": "+27820000000",
"id_or_passport_number": null,
"date_of_birth": null,
"gender": null
},
"answers": [
{
"key": "custom_company_name",
"question": "What is your company’s registered name?",
"answer": "Example answer"
},
{
"key": "custom_vat_number",
"question": "What is your company’s VAT number?",
"answer": "Example answer"
},
{
"key": "custom_bbbee_verified",
"question": "Is your company B-BBEE verified?",
"answer": "YES"
},
{
"key": "custom_bbbee_certificate",
"question": "Please send your B-BBEE certificate.",
"answer": "A photo or document was sent. Open it in Entriva."
}
],
"answers_by_key": {
"custom_company_name": "Example answer",
"custom_vat_number": "Example answer",
"custom_bbbee_verified": "YES",
"custom_bbbee_certificate": "A photo or document was sent. Open it in Entriva."
},
"summary": "This is a test send from Entriva. Nobody real answered these questions.",
"consent": {
"given_at": "2026-09-30T08:15:00.000Z",
"version": null
}
}- answers lists every answer with the question as the person saw it. answers_by_key has the same answers as one flat set of fields, which is the easiest to map in Zapier or Make.
- Each question's key stays the same when you reword the question, so rewording never breaks your connection.
- You only receive what you asked. A golf club receives the ID number, date of birth and gender it asks for; an organisation that only asks its own questions receives the name, phone number and its answers.
- Photos and documents are never sent. Your system is told one arrived, and you open it in Entriva, where each opening is recorded.
- test is true for Send a test, so your system can ignore Thandi Example.
Each send also carries these headers:
- Entriva-Event: onboarding.completed, or onboarding.test.
- Entriva-Delivery: the same as delivery_id. If a send is tried twice, it has the same id both times, so your system can ignore a repeat.
- Entriva-Signature: proof it came from Entriva (below).
Checking a send came from Entriva
When you first set an address, Entriva shows you a signing secret once. Each send is signed with it: the signature header reads t=<time>,v1=<signature>, where the signature is an HMAC-SHA256, in hex, of the time, a full stop and the raw body. Refuse a send whose signature does not match or whose time is more than five minutes old. In Node.js:
import crypto from 'node:crypto'
// secret: the signing secret from Entriva Settings (whsec_...)
// header: the Entriva-Signature header
// rawBody: the request body exactly as it arrived, before JSON.parse
export function isFromEntriva(secret, header, rawBody) {
const parts = Object.fromEntries(
String(header || '').split(',').map((p) => p.trim().split('=')),
)
const t = Number(parts.t)
if (!Number.isInteger(t) || Math.abs(Date.now() / 1000 - t) > 300) return false
const expected = crypto
.createHmac('sha256', secret)
.update(t + '.' + rawBody)
.digest('hex')
const given = String(parts.v1 || '')
return given.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(given), Buffer.from(expected))
}Lost the secret? Press New secret in Settings. The old one stops working at once.
If your system is down
- Answer with any 2xx status within 10 seconds and the send counts as delivered. Redirects are not followed, so give Entriva the final address.
- Anything else, and Entriva tries again: whenever someone else finishes at your organisation, and at least once a night, for 3 days.
- After that it shows Not delivered in Settings and on your Audit Trail, and you can press Send again. The answers are always kept in Entriva either way.
Privacy
You decide where your answers go, so only the account owner can set the address, and it must be an https address on the internet. The answers travel encrypted, and Entriva never keeps a copy on the way. Every send that arrives, and every one that could not be delivered, is written to your Audit Trail with where it went. Once the answers are in your system, looking after them there is up to you, as it is with a download.
Fetching answers with the API
On the Network plan, the account owner makes an API key in Settings. Send it as a bearer token on every request. Start with this, which returns no personal information:
curl -H "Authorization: Bearer $ENTRIVA_KEY" \ https://www.entriva.co.za/api/v1/me
GET /api/v1/me
Check a key works. Returns the practice and plan it belongs to, and no patient data — safe to run anywhere.
GET /api/v1/intakes
The index: ids, status and appointment slot, oldest first. No patient data, so it is cheap to poll.
GET /api/v1/intakes/{id}
One full record — demographics, medical aid, clinical answers, AI summary, ICD-10 and risk flags. Each read is written to the practice audit trail.
POST /api/v1/intakes
Start an intake from your own system — send the WhatsApp or email invite the moment an appointment is booked. Spends one against your plan, exactly as the dashboard does.
Settings shows the full reference, with a worked example, next to your keys.