Skip to content
CRM API for developers

Lead capture API for forms you already run.

Keep your own forms. POST each submission from your server to one REST endpoint with a per-product key, and it lands in that product’s LiftUp inbox. Read published posts through the headless blog API. On Growth, get HMAC-SHA256 signed webhooks when leads change.

  • Lead API on every plan
  • Keys stay server-side
  • HMAC-SHA256 webhooks
POST/api/v1/leads
POST /api/v1/leads
Authorization: Bearer {PRODUCT_API_KEY}
Content-Type: application/json

{
  "name": "Jane Smith",
  "email": "[email protected]",
  "company": "Acme Corp",
  "message": "I'd like to discuss a project.",
  "lead_source": "organic",
  "source_page": "/services/",
  "custom_fields": {
    "budget_range": "$25K-$50K"
  }
}
201 CreatedRate limit 30/min per key
Lead intake rate limit
30/min
Blog API rate limit
60/min
Webhook signature (HMAC)
SHA-256
API versions, pinned in path
2

The short answer

What is a lead capture API?

A lead capture API is an HTTP endpoint that takes a form submission and creates a lead in your CRM. With LiftUp, your server POSTs JSON to /api/v1/leads with a per-product Bearer key. The lead lands in that product’s inbox with its source page and any custom fields, and the key never reaches the browser.

What you can build

A small CRM API: REST in, webhooks out.

Two lead endpoints, a read-only blog API and signed webhooks. Anything that can send an HTTPS request can integrate: Next.js, Laravel, Django, Rails or a Cloudflare Worker.

Lead capture API

POST form submissions from any server with a product key.

Career applications

Multipart endpoint with a PDF or DOC resume, up to 5 MB.

Headless blog API

Read published posts on any frontend. No key needed.

A/B headlines (v2)

Blog API v2 serves headline variants. Growth and up.

Signed webhooks

lead.created and lead.status_changed, HMAC-SHA256.

Custom fields

Per-product intake fields, validated on ingest.

Per-product keys

One rotatable Bearer key per site, stored hashed.

Intake protection

reCAPTCHA, honeypot, dedupe window and rate limits.

On-publish revalidation

Next.js cache revalidation when a post goes live.

API reference

Lead capture API reference.

Lead endpoints take a per-product Bearer key. The blog API needs no key for published posts. All requests go over HTTPS.

Lead capture endpoint

Create a lead from any server-side form handler. Returns 201 Created with the new lead id.

Bearer {PRODUCT_API_KEY}

Rate limits: 30/min · 200/hour · 1,000/day

POST/api/v1/leads
POST /api/v1/leads
Authorization: Bearer {PRODUCT_API_KEY}
Content-Type: application/json

{
  "name": "Jane Smith",
  "email": "[email protected]",
  "company": "Acme Corp",
  "phone": "+1 555 0100",
  "message": "I'd like to discuss a project.",
  "lead_source": "organic",
  "source_page": "/services/web-development/",
  "custom_fields": {
    "budget_range": "$25K-$50K",
    "project_timeline": "Q3 2026"
  }
}
Response
201 Created

{
  "id": 1234
}

Career application

Submit a job application with a resume attachment as multipart form data.

Bearer {PRODUCT_API_KEY}

Resume: PDF or DOC, up to 5 MB

POST/api/v1/leads/career
POST /api/v1/leads/career
Authorization: Bearer {PRODUCT_API_KEY}
Content-Type: multipart/form-data

name, email, phone, message   (required)
resume                        (PDF/DOC, max 5MB, required)
lead_source, source_page      (optional)

Headless blog API

Fetch published posts for one product and render them on any frontend. No key is needed for published content.

No auth for published posts

Rate limit: 60/min

GET/api/v1/blog
GET /api/v1/blog?product={product_slug}&limit=50
GET /api/v1/blog/{slug}?product={product_slug}
Response
200 OK

{
  "title": "Setting a lead response SLA",
  "slug": "lead-response-sla",
  "excerpt": "...",
  "content": "...",
  "featured_image": "https://.../cover.jpg",
  "categories": ["growth"],
  "tags": ["crm", "sla"],
  "published_at": "2026-06-10T09:00:00Z"
}

A/B headline (v2)

Same shape as v1, plus the headline variant to show for this request. Experiments run on Growth and Enterprise.

No auth for published posts

Headline experiments: Growth and Enterprise

GET/api/v2/blog/{slug}
GET /api/v2/blog/{slug}?product={product_slug}
Response
200 OK

{
  "slug": "lead-response-sla",
  "title": "Lead response SLAs, explained"   // headline variant for this request
}

Webhooks

CRM webhooks, signed with HMAC SHA-256.

Set an endpoint per product on Growth or Enterprise. Every delivery is HMAC-signed, retried on failure and logged.

Events

  • lead.createdFired when a new lead arrives
  • lead.status_changedFired when a lead changes pipeline status

Delivery & reliability

Signing
HMAC SHA-256 per request
Retries
Automatic on failure
Auto-disable
After repeated failures
Delivery log
Every delivery, with its status

Payload

POST to your endpoint
{
  "event": "lead.created",
  "timestamp": "2026-06-13T08:00:00Z",
  "data": { ...lead object... }
}

Website forms to CRM

Send form submissions to your CRM from the server.

LiftUp doesn’t replace your frontend. Your form posts to your own route handler or edge function, which forwards the submission to the lead API with the product key. The key lives in a server environment variable and never ships to the browser.

  • Next.js, Laravel, Django, Rails or a Worker: any stack
  • One rotatable API key per product
  • Custom fields validated on ingest (Starter and up)
  • reCAPTCHA, honeypot, dedupe and rate limits on intake
POSTapp/api/contact/route.ts
// Next.js route handler: the key never leaves the server
export async function POST(req: Request) {
  const { name, email, company, message } = await req.json()

  const res = await fetch('https://app.liftup.sh/api/v1/leads', {
    method: 'POST',
    headers: {
      Authorization: `Bearer ${process.env.LIFTUP_API_KEY}`,
      'Content-Type': 'application/json',
    },
    body: JSON.stringify({ name, email, company, message, source_page: '/contact/' }),
  })

  return Response.json(await res.json(), { status: res.status })
}

API by plan

What the API includes on each plan.

The lead API and blog API are on every plan, Free included. Limits and webhooks scale with the plan.
LiftUp API features and limits by plan
API featureFreeStarterGrowthEnterprise
Access
Lead capture API (v1)IncludedIncludedIncludedIncluded
Headless blog API (v1)IncludedIncludedIncludedIncluded
Custom fields per productNot includedIncludedIncludedIncluded
A/B headline experiments (v2)Not includedNot includedIncludedIncluded
Outbound webhooks (HMAC-SHA256)Not includedNot includedIncludedIncluded
Limits
Products (one API key each)1310Unlimited
Leads per month1001,00010,000Unlimited
Blog posts10IncludedIncludedIncluded

FAQ

Lead capture API questions, answered.

Is the lead capture API free?

Yes. The lead API and the blog API are on every plan, Free included. Free covers 1 product and 100 leads a month. Starter raises that to 3 products and 1,000 leads, Growth to 10 products and 10,000 leads. Outbound webhooks and A/B headline experiments start on Growth.

How do I send form submissions to a CRM without exposing the key?

Post the form to your own server route or edge function, then forward it to /api/v1/leads with the product key read from a server environment variable. The browser only ever talks to your domain, so the key never appears in page source or network requests.

What are the lead API rate limits?

Lead intake allows 30 requests a minute, 200 an hour and 1,000 a day per key. The blog API allows 60 requests a minute. Past a limit the API returns HTTP 429, so back off and retry.

Which webhook events can I subscribe to?

Two lead events. lead.created fires when a new lead arrives, and lead.status_changed fires when a lead moves through the pipeline, for example from New to Contacted or from Qualified to Won. Outbound webhooks are available on Growth and Enterprise.

Is the API versioned?

Yes. The version is part of the path, so each request names the version it expects. v1 covers lead intake, career applications and blog reads. v2 adds A/B headline experiments to the blog API.

Can I send leads from a static site, WordPress or Webflow?

Yes, as long as something server-side makes the request: a WordPress hook, a serverless function or a Cloudflare Worker. A purely static site needs a small function in front of the API, because the product key must never ship to the browser.

Wire your forms to LiftUp.

Request a 14-day Growth trial, no card needed. Tell us your stack and which forms you want to connect. Or compare plans first: the lead API is on every plan.