Overview
Everything the application does is available over a JSON HTTP API.
All endpoints live under /api on your own SalesFlow domain. Requests and responses are JSON unless noted, and every endpoint operates inside the organization you are signed in to — you never pass an organization identifier yourself.
Authentication
- Session
- The default. The signed-in user's session is used, and the endpoint applies that user's role and permissions. This is how the application itself calls the API.
- Form secret
- Used only by the public lead capture endpoint. Your website sends an x-contact-secret header instead of a session.
Permissions apply to the API, not just the interface
Where an endpoint lists a required permission, calling it as a user who lacks that permission returns 403 — the same rules that hide a button also block the request.
Conventions
| Convention | Detail |
|---|---|
| Content type | application/json, except file upload endpoints which accept multipart/form-data |
| Identifiers | Record ids are opaque strings; always pass back exactly what you received |
| Dates | ISO 8601 strings in responses |
| Paging | page and limit query parameters; responses include totalPages and currentPage |
| Filtering | A filters query parameter containing a JSON array of filter rows |
Filter rows
List endpoints that support filtering accept the same structure the filter bar produces. Each row names a field, an operator and a value, and all rows must match.
[
{ "field": "status", "operator": "is", "value": "hot" },
{ "field": "source", "operator": "is not", "value": "Import" }
]