Integrations Platform
One catalogue, one credential store and one mapping layer behind every Solidlio connector — plus signed outbound webhooks for the tools we don't integrate with yet.
The problem
Every tool you buy claims to integrate with everything. In practice each connector is its own island: credentials pasted into a settings box somewhere, no record of what synced or when, no way to tell which of your client’s records a given external id belongs to, and no way to push an event into the one system that matters to you but isn’t on the vendor’s list. When something stops working, you find out from a customer.
What Solidlio does about it
Every connector in Solidlio runs on the same substrate. Credentials go into one encrypted store and are never readable back out. External records are paired to Solidlio records through an explicit mapping layer, so one connection can serve many client organizations and every imported record lands in the right tenant. Each sync run is logged with counts, duration and a per-record error list. And for the systems Solidlio does not integrate with, outbound webhooks push signed events to any address you control.
Capabilities
| Capability | What it does |
|---|---|
| Provider catalogue | Presents the providers your portal and plan can actually use, and hides the rest |
| Scope enforcement | Restricts each provider to MSP, organization, platform or user context — on reads and writes alike |
| Guided setup | Collects credentials with per-provider field guidance and tests the connection before saving |
| Entity mapping | Pairs external ids with Solidlio records, with name-matched suggestions and bulk accept |
| Multi-tenant routing | Routes one connection’s records into many client organizations, restricted to accounts you manage |
| Sync history | Records every run with counts, duration, status and per-record errors |
| Outbound webhooks | Pushes Solidlio events to your address, signed and replay-resistant |
| Delivery history + retry | Shows every attempt with its response, and retries on demand |
| API key management | Mints scoped, expiring keys, hashed at rest and shown once |
| Guide library | Attaches how-to recordings to tickets and services |
| Audit trail | Records connect, disconnect, sync, test, settings, mapping and key lifecycle events |
Built for MSPs and their clients
One connection frequently serves several client organizations — one Automate server, one Azure tenancy, one GLPI instance. Mapping is what makes that multi-tenant rather than one undifferentiated pile.
| Organization | MSP | |
|---|---|---|
| Catalogue | Sees org-scoped providers | Sees MSP-scoped providers |
| Connecting | Connects its own systems | Connects on the client’s behalf |
| Entity mapping | Maps into its own organization | Maps each external record to the right client organization |
| Mapping boundary | — | Restricted to organizations the MSP owns or services |
| Webhooks | Its own destinations and secrets | Its own destinations and secrets |
How it works
- Browse — the catalogue shows what your portal can use. Roadmap providers are visibly disabled and cannot be set up.
- Set up — the wizard collects the provider’s fields, tests the connection live, then encrypts and stores the credentials.
- Map — pair external records with Solidlio organizations, assets or products. Accept suggestions individually or in bulk.
- Sync — trigger a run, then watch counts, duration and errors in history.
- Push outward — subscribe a webhook to the events you care about and verify the signature at your end.
Security
- Credentials are encrypted with AES-256 using a per-operation random salt, behind a mandatory 32-character minimum key.
- Webhook destinations are validated when saved and re-validated on the delivery connection itself, so a hostname cannot be repointed at an internal address between the check and the request. Private, reserved, loopback, link-local and cloud-metadata addresses are refused.
- API keys are stored only as a one-way hash; the plaintext is shown once and never again. Scopes are immutable after creation.
- Entity mappings are restricted to organizations your account owns or services.
- Connect, disconnect, sync, test, settings and mapping changes are all written to the audit trail through a redacting writer.
Honest limits
- A path not mapped to a scope resource is refused rather than allowed.
- Guides can be created, linked and deleted, but not edited in the UI.
- Sync cadence is set per provider, not globally per integration.
Editions
Most of the platform is available on every tier. Plan gating applies to specific providers rather than to the substrate.
| Capability | Free | Starter | Growth | Scale | Enterprise |
|---|---|---|---|---|---|
| Integration catalogue + setup | ● | ● | ● | ● | ● |
| Entity mapping + sync history | ● | ● | ● | ● | ● |
| Outbound webhooks | ● | ● | ● | ● | ● |
| QuickBooks Online | — | — | ● | ● | ● |
| Microsoft Teams | — | — | — | ● | ● |
| Microsoft 365 | — | — | — | — | ● |
| API key management | — | — | ● | ● | ● |
RMM, monitoring and GLPI connectors are not plan-gated. Customer-plan equivalents: Essentials, Professional, Business, Enterprise.