Submit a lead from your website
The one endpoint designed to be called from outside the application.
Post your website form submissions here to create leads directly in Contacts. Authorize the request with the form secret from the Integrations page. The endpoint accepts cross-origin requests, so it can be called from the browser as well as from your server.
/api/contactsCreate a lead from a website form submission.
Body
| name* | string | The lead's full name. |
| email* | string | A valid email address. Used to recognise repeat submissions. Not required if an administrator has turned off the email requirement in Settings → Organization. |
| phone* | string | Digits only, at least 10. |
| company | string | Company name. |
| projectSlug | string | Routes the lead to a project and its assignees. |
| leadScore | number | 0 to 100. |
| status | string | One of your organization's contact statuses. |
| stage | string | Not Contacted, No Response, Follow Up or Connected. |
| source | string | Where the lead came from, such as Website Form. |
| comment | string | Free-text note from the form. |
| utm_source | string | Campaign source. |
| utm_medium | string | Campaign medium. |
| utm_campaign | string | Campaign name. |
| utm_term | string | Campaign term. |
| utm_content | string | Campaign content variant. |
| page_title | string | Title of the page the form was on. |
| form_title | string | Name of the form that was submitted. |
| page_url | string | URL the form was submitted from. |
| customFields | object | Values for any custom contact fields, keyed by field id. |
Returns. The created contact. If the email or phone matches an existing lead, the submission is recorded against that contact as an enquiry instead of creating a duplicate.
- Only name, email and phone are required — everything else is optional.
- If your organization has made email optional, leads without one are accepted and repeat submissions are matched by phone.
- Repeat submissions from the same lead are rate limited; exceeding the limit returns 429.
- Team members are notified when a lead arrives.
/api/contactsCross-origin preflight for the lead capture endpoint.
curl -X POST https://your-domain.com/api/contacts \
-H "Content-Type: application/json" \
-H "x-contact-secret: your_contact_secret" \
-d '{
"name": "Jane Smith",
"email": "jane@example.com",
"phone": "9876543210"
}'curl -X POST https://your-domain.com/api/contacts \
-H "Content-Type: application/json" \
-H "x-contact-secret: your_contact_secret" \
-d '{
"projectSlug": "summer-lp-2026",
"name": "John Doe",
"email": "john.doe@example.com",
"phone": "1234567890",
"company": "Acme Inc",
"leadScore": 75,
"status": "warm",
"source": "Website Form",
"stage": "Follow Up",
"comment": "Interested in a product demo",
"utm_source": "google",
"utm_medium": "cpc",
"utm_campaign": "summer_sale",
"page_title": "Contact Us - Acme Inc",
"form_title": "Contact Form",
"page_url": "https://example.com/contact"
}'Treat the secret like a password
Anyone holding it can write leads into your organization. Prefer sending it from your server or form handler, and rotate it from the Integrations page if it leaks.