- CategoryCRM
- AuthAPI key + webhook
Overview
ScoreApp connects on /integrations in the dashboard. Click the ScoreApp card and the 'Connect ScoreApp' modal takes a single API Key (field label "API Key", type password, placeholder "Paste your ScoreApp API Key") that you generate in ScoreApp under Settings/Integrate, API. The same modal mints a per-connection webhook URL and signing secret (both lazily generated when the modal opens), shows them for you to paste back into ScoreApp's outgoing webhooks, and gates the Integrate button behind an explicit "accept all permissions" checkbox listing the five data categories MessageMind will read. Once connected, ScoreApp posts each lead signup, quiz start, quiz finish, and lead-details update to the per-tenant routing URL '/integration-webhook/scoreapp/<token>'; MessageMind resolves the contact, enrols it into any automation listening on the matching trigger, and the entity ledger deduplicates ScoreApp's own retries so a byte-identical redelivery is a no-op.
What MessageMind can do with it
- Receive and process four ScoreApp webhook events: lead signed up, quiz started, quiz finished, and lead details updated.
- Enrol the lead's contact (resolved by email and phone) into any active MessageMind automation whose trigger matches the ScoreApp event.
- Mint a per-connection webhook URL ('/integration-webhook/scoreapp/<routing token>') and a signing secret (24 random bytes, hex) so inbound ScoreApp deliveries can be authenticated and routed to the right tenant.
- Deduplicate ScoreApp's own retries via the entity ledger so a byte-identical redelivery is treated as a no-op; a genuinely distinct delivery (a retaken quiz, another details update) still fires.
Requirements
- A ScoreApp account that can configure outgoing webhooks on a quiz.
- A ScoreApp API key, generated under Settings/Integrate, API.
- At least one MessageMind automation using a ScoreApp trigger (lead signed up, quiz started, quiz finished, or lead details updated) for the inbound events to do anything.
How to connect
- In ScoreApp, open Settings/Integrate, API and generate an API key. Copy the value: treat it like a password and never share it.
- In the MessageMind dashboard, open /integrations and click the ScoreApp card. The 'Connect ScoreApp' modal opens with the instruction 'Add your API key, connect the webhook, and accept the permissions to finish.'
- Paste the key into the 'API Key' field (type: password, placeholder 'Paste your ScoreApp API Key').
- In the webhook panel of the same modal, copy the Webhook URL ('/integration-webhook/scoreapp/<routing token>', minted lazily on first open) and the Secret key (24 random bytes, hex) using the copy buttons. A 'rotate' control regenerates the secret if you need a fresh one.
- In ScoreApp, open your quiz's outgoing webhooks and paste the Webhook URL and Secret key MessageMind just showed you (Step 3 in the modal is labelled 'Save in ScoreApp').
- Back in MessageMind, tick the 'accept all permissions' box (the ScoreApp-only panel listing: read your scorecards and quizzes, read quiz responses and scores, read captured leads and contact details, read tags, categories and result pages, receive lead and quiz activity). The Integrate button only enables after this is ticked.
- Click Integrate. MessageMind stores the API key, the webhook routing token and the signing secret, and the card flips to Connected.
Authentication and permissions
- Mechanism
- Inbound webhook authenticated by a per-connection signing secret, routed to the owning tenant by an unguessable routing token embedded in the webhook URL. A ScoreApp API key is also stored for the account the webhook belongs to. API-key validation depends on the configured server API endpoint; when format-only validation is enabled, accepting the key format does not prove a successful live account API request.
- Credentials
- The pasted ScoreApp API Key, a Webhook Secret and a routing Webhook Token are saved when you click Integrate. The browser generates the secret and token with 24 random bytes when the modal first opens. Regenerate changes the secret in the modal; save it with Integrate and update the ScoreApp webhook to match.
Available data and actions
Reads
- ScoreApp's webhook body for each delivery: the event name (LEAD_SIGNED_UP, QUIZ_STARTED, QUIZ_FINISHED, LEAD_DETAILS_UPDATED), the lead's identity (email, phone, first and last name) used to resolve or create the MessageMind contact, and the quiz context ScoreApp carries (lead id, status, started_at, total score tier, actual and percent).
AI agent use cases
- Start a MessageMind automation the moment a lead signs up for a ScoreApp quiz.
- React to quiz progress: send a nudge when a quiz is started but not finished, or a tailored follow-up when it is finished (optionally templated with the score tier and percent).
- Pick a conversation back up when a ScoreApp lead updates their details, without a human re-syncing contacts.
Configuration
- ScoreApp retries a webhook delivery up to five times on a slow or failed answer; the entity ledger turns a byte-identical redelivery into a no-op so the lead is not enrolled twice.
- Delivery identity falls back to a hash of email, phone and quiz start time when ScoreApp's event body carries no lead id, so dedup still works on events that lack one.
- Deliveries are retained for 30 days of dedup history. A redelivery older than that is treated as new.
- The webhook signing secret can be rotated from the connect card (the 'rotate' control regenerates it). Rotating in MessageMind requires repasting the new secret in ScoreApp before the next delivery.
Example workflows
Enrol a new ScoreApp lead into an automation
- A lead signs up for your ScoreApp quiz; ScoreApp posts the LEAD_SIGNED_UP event to '/integration-webhook/scoreapp/<routing token>'.
- MessageMind authenticates the delivery against the stored signing secret and resolves (or creates) the contact from the lead's email and phone.
- Every active automation listening on the ScoreApp lead-signed-up trigger is started for that contact.
- If ScoreApp retries the same delivery because the first answer was slow, the entity ledger recognises the byte-identical body and does nothing.
Follow up on a finished quiz
- A lead completes your ScoreApp quiz; ScoreApp posts QUIZ_FINISHED with the total score (percent, tier, actual) and lead identity.
- MessageMind resolves the contact and starts every active automation listening on the quiz-finished trigger, exposing the score fields (e.g. {scoreapp_first_name}, {scoreapp_total_score_tier}, {scoreapp_total_score_percent}) to the message template.
Limitations
- ScoreApp triggers are inbound-only in the current implementation: there is no outbound write from MessageMind back into ScoreApp.
- Only four ScoreApp events are mapped to automation triggers: lead signed up, quiz started, quiz finished, and lead details updated.
- Dedup is based on the delivery body plus the lead identity (ScoreApp's id when present, otherwise an email/phone/started-at hash). A delivery that mutates even one field will fire again, by design.
- The Integrate button stays disabled until the 'accept all permissions' checkbox is ticked; the ScoreApp card specifically enforces that panel while other integrations ignore it.
- The connection is available on Starter, Professional and Enterprise plans.
Troubleshooting
The same ScoreApp lead was enrolled twice.
Check whether both deliveries were byte-identical. ScoreApp's own retries are deduplicated by the entity ledger, but a redelivery with any changed field (including a new lead id) is treated as a new, distinct event by design.
A ScoreApp signup never reached a MessageMind automation.
Confirm an active MessageMind automation is listening on the matching ScoreApp trigger, and that the Webhook URL and Secret key pasted into ScoreApp match the ones currently on the MessageMind connect card. Deliveries without any listening automation report nothing started.
ScoreApp reports the webhook URL returns 404.
An unknown routing token returns a 404 by design (so an attacker cannot probe which tokens exist). Repaste the current Webhook URL from the MessageMind connect card into ScoreApp; the token in the path must match the stored one for your tenant.
The Integrate button in the modal stays disabled.
The ScoreApp card gates Integrate behind the 'accept all permissions' checkbox listing the five data categories (scorecards and quizzes, responses and scores, captured leads, tags and categories, lead and quiz activity). Tick that box, then Integrate enables.
I rotated the signing secret in MessageMind and deliveries started failing.
Regenerate changes the value in the modal. Save it with Integrate, then paste the same new secret into the ScoreApp outgoing webhook so subsequent delivery signatures match.
Disconnect and reconnect
- Remove the Webhook URL from your ScoreApp quiz's outgoing webhooks so ScoreApp stops sending events (an inbound delivery to a disconnected tenant returns 404 anyway).
- On /integrations in the dashboard, open the ScoreApp card and disconnect to clear the stored API key, routing token and signing secret. Any ScoreApp-triggered automations in MessageMind will stop receiving work.