Developer & API

A CRM API your developers can trust with every retry

The DigiPix Flow CRM API gives each system its own key with only the access it needs, so your systems send leads in with one well-behaved REST call and can retry safely when a network drops. Keys are shown once, stored as a hash, rotated in a click and recorded in your audit log.

  • One key per system, revoked in a click
  • Retries never create a second lead
  • Every key change in the audit log
An example of DigiPix Flow's Developer access settings with a list of API clients beside an example request. A new client for a showroom tablet app is created and its secret shown once, a lead request returns 202 Accepted, the same request retried with its Idempotency-Key is recognised as a duplicate so no second lead is created, and the partner portal client's secret is rotated.
REST call to create a lead
1
requests a minute for each workspace
120
that a key's secret is ever shown
1 time

What every API call carries

  • API clientA named key for each system that calls you
  • ScopeExactly what that key is allowed to do
  • Idempotency keyOne per lead, so a retry is recognised
  • LeadEmail, name, company and the source
  • ConsentWhat the person agreed to, and where
  • Audit entryWho created, rotated or revoked a key
THE PROBLEM

Where home-made lead connections go wrong

See how it's fixed
  1. One password shared by every script

    A single login gets pasted into a website plugin, a partner's script and a spreadsheet macro. When someone leaves or a laptop goes missing, nobody knows which of those systems will break if the password changes, so it never does.

  2. A timeout that turns into two leads

    A request reaches the server, the connection drops before the answer comes back, and the calling system tries again. Without a way to recognise the retry, the same enquiry lands twice and two reps call the same buyer.

  3. No record of who can get in

    Keys are created in a hurry during a launch and forgotten. Months later nobody can say which ones exist, which are still in use, or who made them, and cleaning up feels riskier than leaving them alone.

API CLIENTS

CRM API keys: a separate one for every system that calls you

Create an API client for each website, partner or internal tool that sends you leads, and give it a name your team will recognise later. Each client appears in Settings with its scope, when it was created and when it was last used, so an unused key is easy to spot and switch off.

  • One named client for each calling system
  • Last used time shown against every client
  • Rename a client as systems change hands
  • Revoke one key without touching the others
An example of DigiPix Flow's API clients list: four named clients, each with its key id, the create leads scope and when it was last used, including one old landing page client that has never been used and is shown as revoked, with a New client button.
SECRETS

Secrets shown once, then kept only as a hash

When you create or rotate a client, DigiPix Flow shows its secret one time, ready to copy into the system that will use it. After that only a one-way hash is kept, so nobody can look the secret up again, including us. Rotating issues a fresh secret and the old one stops working at once.

  • The full secret is shown a single time
  • Stored only as a one-way SHA-256 hash
  • Rotate to issue a fresh secret in a click
  • The previous secret stops working straight away
An example of the secret shown when an API client is created in DigiPix Flow: the Website enquiries client's full secret is displayed with a Copy button and a warning that it will not be shown again, and below it a Rotate secret action explains that the previous secret stops working straight away.
SCOPES

Each key can do only what you allowed

Every client carries scopes that decide what its key may do, and a request outside them is refused with a clear error rather than quietly allowed. Today the public API has one scope, creating leads, so a key handed to a website form can add enquiries and nothing else in your workspace.

  • Scopes chosen when the client is created
  • Requests outside a scope refused with 403
  • Today's scope: create leads, and nothing more
  • Managing clients needs its own permission
An example of creating an API client in DigiPix Flow: the client is named Showroom tablet app and given the create leads scope, the only scope available today, and a request from this key to anything outside its scope would be refused with a 403 API scope denied error.
CREATE A LEAD

One request, and the lead joins your intake

Send a POST with the person's email and, if you have them, their first and last name, company and a source label. DigiPix Flow accepts the request with a 202 and a correlation id you can log, then the lead goes through the same intake as every other source: duplicate checks, assignment and the source you named.

  • A single POST to one versioned endpoint
  • Email required; names, company and source optional
  • A 202 response with a correlation id to log
  • The same intake as leads from any other source
Explore the lead API
An example request to the DigiPix Flow public API: a POST to the leads endpoint with a Bearer token and an Idempotency-Key header, carrying Neha Patil's email, first and last name, company and the source website-enquiry, and a 202 Accepted response with accepted true, a correlation id and duplicate false.
SAFE RETRIES

Retry as often as you like, get one lead

Every request carries an Idempotency-Key header that you choose, such as the enquiry's id in your own system. If the same key arrives again, DigiPix Flow creates nothing new and answers with the first request's correlation id and a duplicate flag, so a caller can retry after any timeout with confidence.

  • An Idempotency-Key header on every request
  • A repeated key creates nothing new
  • The first request's correlation id returned
  • A duplicate flag your code can check
An example of safe retries with the DigiPix Flow public API: a request with Idempotency-Key enq-20931 loses its connection, is retried twice with the same key, and both retries return 202 with duplicate true and the first request's correlation id, so only one lead, for Neha Patil, exists.
LIMITS & ERRORS

Clear answers when something is wrong

Each workspace can send up to 120 requests a minute, and a request beyond that gets a 429 so your code knows to slow down and try again. A missing or revoked key returns 401, a key without the right scope returns 403, and a request without an Idempotency-Key returns 422, each with a readable message.

  • 120 requests a minute for each workspace
  • 429 when a caller needs to slow down
  • 401 for a revoked key, 403 for a missing scope
  • 422 when the Idempotency-Key is missing
An example of the DigiPix Flow public API's limits and responses: a meter shows 96 of 120 requests used this minute for the workspace, and a table lists 202 Accepted, 401 for an invalid or revoked key, 403 for a missing scope, 422 when the Idempotency-Key header is missing and 429 when there are too many requests.
AUDIT

A record of every key, and who touched it

Creating, renaming, rotating and revoking an API client are each written to your workspace audit log with the person who did it and when. Only people with permission to manage API access can make those changes, so an admin can review who holds a key before a security questionnaire, not after an incident.

  • Create, rename, rotate and revoke all logged
  • The person and time on every entry
  • API access managed by permitted people only
  • Kept alongside the rest of your audit log
Explore webhooks
An example of DigiPix Flow's audit log filtered to API key changes: Kavya Iyer rotated the Partner referrals portal secret today, Rahul Kumar revoked the Old landing page client yesterday, and earlier entries show a client renamed and the Website enquiries client created, each with the person and time.
HOW IT WORKS

From a new key to your first lead, in five steps

  1. STEP 01

    Create an API client

    Name it after the system that will call you and choose its scope.

  2. STEP 02

    Copy the secret once

    Store it in that system's secrets; DigiPix Flow keeps only a hash.

  3. STEP 03

    Send a lead

    POST the lead with a Bearer token and an Idempotency-Key.

  4. STEP 04

    Retry without worry

    A repeated key returns the first result instead of a second lead.

  5. STEP 05

    Review and rotate

    Check last used times and the audit log, and rotate on your schedule.

THE DIFFERENCE

API clients vs shared logins and scripts

What it coversShared logins and scriptsDigiPix Flow
CredentialsOne login pasted into every toolA named API client for each system
Storing the secretIn plain text wherever it was pastedShown once, then kept only as a hash
AccessEverything the login can seeOnly the scopes given to that key
A retried requestA second copy of the same leadRecognised by its Idempotency-Key
Someone leavesChange the password and hope nothing breaksRotate or revoke just the affected key
Too many requestsSilent failures or a locked accountA 429 your code can back off from
Who changed whatNobody remembersEvery key change in the audit log

Public API questions, answered

What can the public API do today?

It creates leads. A single endpoint accepts a lead with an email address and, optionally, a first and last name, company name, source label and consent claims. Every key is limited to the scopes you give it, and creating leads is the scope available today.

How do I authenticate?

Create an API client in Settings, copy its secret when it is shown, and send it as a Bearer token in the Authorization header. The secret is shown only once; if it is lost, rotate the client to issue a new one.

What happens if we send the same lead twice?

Every request needs an Idempotency-Key header. If a key has been seen before, no second lead is created and the response carries the first request's correlation id with duplicate set to true. Use an id from your own system, such as the enquiry id, as the key.

Is there a rate limit?

Yes. Each workspace can make up to 120 requests a minute. Requests beyond that receive a 429 response, and your code should wait briefly and try again with the same Idempotency-Key.

What does a successful response look like?

A 202 Accepted with accepted set to true, a correlation id and a duplicate flag. The lead is then created by the same intake that handles every other source, which runs duplicate checks and assignment.

How do we rotate or revoke a key?

Open the client in Settings and choose Rotate secret to issue a new one, or Revoke to switch it off. Rotating stops the old secret working at once, so update the calling system as soon as you copy the new secret.

Who can create and manage API clients?

Only people whose role includes permission to manage API access. Every create, rename, rotate and revoke is recorded in the workspace audit log with the person and the time.

Can we include consent with the lead?

Yes. Send up to 12 consent claims, each naming the purpose, marketing or sales outreach, and the channel, email, SMS or WhatsApp. A grant must include the notice version the person saw. If you send no consent, nothing is recorded and nothing is treated as a withdrawal.

Should we use the API or webhooks?

Use the API to send leads into DigiPix Flow from your own systems. Use outbound webhooks when your systems need to hear about changes made in DigiPix Flow, such as a deal being won. Many teams use both.

Something we haven't covered? Talk to an expert

Connect your own systems without sharing a single password

Talk to an expert — bring the systems that collect your enquiries today, and see a lead arrive through the API.

  • A real person, not a bot
  • Bring your developer
  • See a lead arrive through the API
Talk to an expert