A CRM API your developers can trust with every retry
The DigiPix Flow CRM API gives each system its own key with only the access it needs, so your systems send leads in with one well-behaved REST call and can retry safely when a network drops. Keys are shown once, stored as a hash, rotated in a click and recorded in your audit log.
- One key per system, revoked in a click
- Retries never create a second lead
- Every key change in the audit log
- REST call to create a lead
- 1
- requests a minute for each workspace
- 120
- that a key's secret is ever shown
- 1 time
What every API call carries
- API clientA named key for each system that calls you
- ScopeExactly what that key is allowed to do
- Idempotency keyOne per lead, so a retry is recognised
- LeadEmail, name, company and the source
- ConsentWhat the person agreed to, and where
- Audit entryWho created, rotated or revoked a key
One password shared by every script
A single login gets pasted into a website plugin, a partner's script and a spreadsheet macro. When someone leaves or a laptop goes missing, nobody knows which of those systems will break if the password changes, so it never does.
A timeout that turns into two leads
A request reaches the server, the connection drops before the answer comes back, and the calling system tries again. Without a way to recognise the retry, the same enquiry lands twice and two reps call the same buyer.
No record of who can get in
Keys are created in a hurry during a launch and forgotten. Months later nobody can say which ones exist, which are still in use, or who made them, and cleaning up feels riskier than leaving them alone.
CRM API keys: a separate one for every system that calls you
Create an API client for each website, partner or internal tool that sends you leads, and give it a name your team will recognise later. Each client appears in Settings with its scope, when it was created and when it was last used, so an unused key is easy to spot and switch off.
- One named client for each calling system
- Last used time shown against every client
- Rename a client as systems change hands
- Revoke one key without touching the others
Secrets shown once, then kept only as a hash
When you create or rotate a client, DigiPix Flow shows its secret one time, ready to copy into the system that will use it. After that only a one-way hash is kept, so nobody can look the secret up again, including us. Rotating issues a fresh secret and the old one stops working at once.
- The full secret is shown a single time
- Stored only as a one-way SHA-256 hash
- Rotate to issue a fresh secret in a click
- The previous secret stops working straight away
Each key can do only what you allowed
Every client carries scopes that decide what its key may do, and a request outside them is refused with a clear error rather than quietly allowed. Today the public API has one scope, creating leads, so a key handed to a website form can add enquiries and nothing else in your workspace.
- Scopes chosen when the client is created
- Requests outside a scope refused with 403
- Today's scope: create leads, and nothing more
- Managing clients needs its own permission
One request, and the lead joins your intake
Send a POST with the person's email and, if you have them, their first and last name, company and a source label. DigiPix Flow accepts the request with a 202 and a correlation id you can log, then the lead goes through the same intake as every other source: duplicate checks, assignment and the source you named.
- A single POST to one versioned endpoint
- Email required; names, company and source optional
- A 202 response with a correlation id to log
- The same intake as leads from any other source
Retry as often as you like, get one lead
Every request carries an Idempotency-Key header that you choose, such as the enquiry's id in your own system. If the same key arrives again, DigiPix Flow creates nothing new and answers with the first request's correlation id and a duplicate flag, so a caller can retry after any timeout with confidence.
- An Idempotency-Key header on every request
- A repeated key creates nothing new
- The first request's correlation id returned
- A duplicate flag your code can check
Send what the person agreed to, with the evidence
If your form asked for permission, include it. Each consent claim names the purpose, marketing or sales outreach, and the channel, email, SMS or WhatsApp, along with when it was captured and the version of the notice the person saw. A grant without a notice version is refused, so every recorded yes can be traced.
- Up to 12 consent claims with each lead
- Marketing or sales outreach, per channel
- The notice version required for a grant
- Leaving consent out records nothing at all
Clear answers when something is wrong
Each workspace can send up to 120 requests a minute, and a request beyond that gets a 429 so your code knows to slow down and try again. A missing or revoked key returns 401, a key without the right scope returns 403, and a request without an Idempotency-Key returns 422, each with a readable message.
- 120 requests a minute for each workspace
- 429 when a caller needs to slow down
- 401 for a revoked key, 403 for a missing scope
- 422 when the Idempotency-Key is missing
A record of every key, and who touched it
Creating, renaming, rotating and revoking an API client are each written to your workspace audit log with the person who did it and when. Only people with permission to manage API access can make those changes, so an admin can review who holds a key before a security questionnaire, not after an incident.
- Create, rename, rotate and revoke all logged
- The person and time on every entry
- API access managed by permitted people only
- Kept alongside the rest of your audit log
From a new key to your first lead, in five steps
- STEP 01
Create an API client
Name it after the system that will call you and choose its scope.
- STEP 02
Copy the secret once
Store it in that system's secrets; DigiPix Flow keeps only a hash.
- STEP 03
Send a lead
POST the lead with a Bearer token and an Idempotency-Key.
- STEP 04
Retry without worry
A repeated key returns the first result instead of a second lead.
- STEP 05
Review and rotate
Check last used times and the audit log, and rotate on your schedule.
API clients vs shared logins and scripts
| What it covers | Shared logins and scripts | |
|---|---|---|
| Credentials | One login pasted into every tool | A named API client for each system |
| Storing the secret | In plain text wherever it was pasted | Shown once, then kept only as a hash |
| Access | Everything the login can see | Only the scopes given to that key |
| A retried request | A second copy of the same lead | Recognised by its Idempotency-Key |
| Someone leaves | Change the password and hope nothing breaks | Rotate or revoke just the affected key |
| Too many requests | Silent failures or a locked account | A 429 your code can back off from |
| Who changed what | Nobody remembers | Every key change in the audit log |
Public API questions, answered
What can the public API do today?
It creates leads. A single endpoint accepts a lead with an email address and, optionally, a first and last name, company name, source label and consent claims. Every key is limited to the scopes you give it, and creating leads is the scope available today.
How do I authenticate?
Create an API client in Settings, copy its secret when it is shown, and send it as a Bearer token in the Authorization header. The secret is shown only once; if it is lost, rotate the client to issue a new one.
What happens if we send the same lead twice?
Every request needs an Idempotency-Key header. If a key has been seen before, no second lead is created and the response carries the first request's correlation id with duplicate set to true. Use an id from your own system, such as the enquiry id, as the key.
Is there a rate limit?
Yes. Each workspace can make up to 120 requests a minute. Requests beyond that receive a 429 response, and your code should wait briefly and try again with the same Idempotency-Key.
What does a successful response look like?
A 202 Accepted with accepted set to true, a correlation id and a duplicate flag. The lead is then created by the same intake that handles every other source, which runs duplicate checks and assignment.
How do we rotate or revoke a key?
Open the client in Settings and choose Rotate secret to issue a new one, or Revoke to switch it off. Rotating stops the old secret working at once, so update the calling system as soon as you copy the new secret.
Who can create and manage API clients?
Only people whose role includes permission to manage API access. Every create, rename, rotate and revoke is recorded in the workspace audit log with the person and the time.
Can we include consent with the lead?
Yes. Send up to 12 consent claims, each naming the purpose, marketing or sales outreach, and the channel, email, SMS or WhatsApp. A grant must include the notice version the person saw. If you send no consent, nothing is recorded and nothing is treated as a withdrawal.
Should we use the API or webhooks?
Use the API to send leads into DigiPix Flow from your own systems. Use outbound webhooks when your systems need to hear about changes made in DigiPix Flow, such as a deal being won. Many teams use both.
Something we haven't covered? Talk to an expert
Keep exploring
Visit the blog- INTEGRATIONSCRM webhooks for lead and deal eventsSigned event notifications for leads, contacts, companies and deals.See the integration
- INTEGRATIONSLead capture APIThe lead endpoint in detail: fields, consent, duplicates and where leads land.See the integration
- INTEGRATIONSWebsite form to CRMHosted and embedded forms for teams who would rather not write code.See the integration
- PRODUCTLead inboxWhere every lead lands, is checked for duplicates and assigned.See how it works
- FEATURESConsent and opt-outsHow consent, unsubscribes and do-not-contact work across every channel.Explore the feature
- INTEGRATIONSOutbound webhooksThe other half of the developer story: events pushed to your endpoint as they happen.See the integration
GUIDECRM Migration Checklist: Move From Spreadsheets or Another CRM Without Losing DataA step-by-step crm migration checklist for moving from spreadsheets or another CRM: audit your data, map every field, clean duplicates, run a test import, then plan the cut-over.Read the guide
GUIDEDuplicate Customer Records: Why the Same Buyer Appears Three Times, and How to Fix It for GoodDuplicate customer records creep in from ad forms, phone calls and old spreadsheets until one buyer has three records and two reps calling. This guide shows where they come from, how to merge them safely and how to stop new ones at the door.Read the guide
Connect your own systems without sharing a single password
Talk to an expert — bring the systems that collect your enquiries today, and see a lead arrive through the API.
- A real person, not a bot
- Bring your developer
- See a lead arrive through the API

