REST API and webhooks
API keys, scopes, signed events and connecting to Zapier or Make.
The REST API lets you read and create leads from your tools; webhooks send events to your server. API access depends on your plan.
Use the API
- Go to Settings → API keys and create a key.
- Choose its scopes: read-only, full access or the Zapier / Make preset.
- Copy the key and keep it like a password.
- Send it with every request: Authorization: Bearer <your key>.
- The Developers page lists the endpoints and provides the OpenAPI specification.
- By default, the limit is 120 requests per minute per key; beyond that you get a 429 error with a Retry-After header.
- Lists are paginated, newest first.
Receive webhooks
- Go to Integrations and add an endpoint (HTTPS URLs only).
- Choose the events: lead.created, lead.status_changed, reply.received, reply.classified, meeting.booked, opportunity.created, opportunity.stage_changed, campaign.completed.
- Copy the signing secret: it is shown only once.
- Use "Send a test" to check that your server answers with a 2xx code.
- Each delivery is a signed JSON POST. Verify the x-outbound-signature header (t=<timestamp>,v1=<HMAC-SHA256 of "<timestamp>.<raw body>" with your secret>) and reject timestamps older than 5 minutes.
- A failed delivery is retried up to 5 times with an increasing delay. Every delivery is logged on the Integrations page.
- Zapier and Make: there is no app on their marketplaces yet; use their generic webhook modules with your API key.
Was this article helpful?
Need a personal answer?
Write to our team: we reply by email.
Contact supportHave an account? Find these guides inside the app. Open in the app
