Lead capture API

Post website form submissions straight into Contacts, with authentication, every accepted field and runnable curl examples.

Submit a lead from your website

The one endpoint designed to be called from outside the application.

Post your website form submissions here to create leads directly in Contacts. Authorize the request with the form secret from the Integrations page. The endpoint accepts cross-origin requests, so it can be called from the browser as well as from your server.

POST/api/contacts

Create a lead from a website form submission.

Auth: Form secret in the x-contact-secret header

Body

name*stringThe lead's full name.
email*stringA valid email address. Used to recognise repeat submissions. Not required if an administrator has turned off the email requirement in Settings → Organization.
phone*stringDigits only, at least 10.
companystringCompany name.
projectSlugstringRoutes the lead to a project and its assignees.
leadScorenumber0 to 100.
statusstringOne of your organization's contact statuses.
stagestringNot Contacted, No Response, Follow Up or Connected.
sourcestringWhere the lead came from, such as Website Form.
commentstringFree-text note from the form.
utm_sourcestringCampaign source.
utm_mediumstringCampaign medium.
utm_campaignstringCampaign name.
utm_termstringCampaign term.
utm_contentstringCampaign content variant.
page_titlestringTitle of the page the form was on.
form_titlestringName of the form that was submitted.
page_urlstringURL the form was submitted from.
customFieldsobjectValues for any custom contact fields, keyed by field id.

Returns. The created contact. If the email or phone matches an existing lead, the submission is recorded against that contact as an enquiry instead of creating a duplicate.

  • Only name, email and phone are required — everything else is optional.
  • If your organization has made email optional, leads without one are accepted and repeat submissions are matched by phone.
  • Repeat submissions from the same lead are rate limited; exceeding the limit returns 429.
  • Team members are notified when a lead arrives.
OPTIONS/api/contacts

Cross-origin preflight for the lead capture endpoint.

Auth: None
Minimal submission
curl -X POST https://your-domain.com/api/contacts \
  -H "Content-Type: application/json" \
  -H "x-contact-secret: your_contact_secret" \
  -d '{
    "name": "Jane Smith",
    "email": "jane@example.com",
    "phone": "9876543210"
  }'
Full submission with campaign details and routing
curl -X POST https://your-domain.com/api/contacts \
  -H "Content-Type: application/json" \
  -H "x-contact-secret: your_contact_secret" \
  -d '{
    "projectSlug": "summer-lp-2026",
    "name": "John Doe",
    "email": "john.doe@example.com",
    "phone": "1234567890",
    "company": "Acme Inc",
    "leadScore": 75,
    "status": "warm",
    "source": "Website Form",
    "stage": "Follow Up",
    "comment": "Interested in a product demo",
    "utm_source": "google",
    "utm_medium": "cpc",
    "utm_campaign": "summer_sale",
    "page_title": "Contact Us - Acme Inc",
    "form_title": "Contact Form",
    "page_url": "https://example.com/contact"
  }'

Treat the secret like a password

Anyone holding it can write leads into your organization. Prefer sending it from your server or form handler, and rotate it from the Integrations page if it leaks.