Developer & API

A CRM developer API built for both integrations and AI assistants

CRMLeaf's developer platform gives you a token-authenticated REST API, webhooks with a delivery log, a certificate-secured public API for partner systems, and an MCP server so Claude, Cursor or Copilot can work with your CRM data inside your own permissions.

  • ✓Free trial
  • ✓No credit card
  • ✓Free onboarding
One token · one permission model

REST API

$ curl https://api.example.com/api/v1/leads \

-H "Authorization: Bearer crmleaf_pat_••••7f3a"

200 OKread-only token · 30-day expiry

{
  "data": [
    { "id": 2291, "name": "Priya Shah", "stage": "qualified" },
    { "id": 2290, "name": "Arjun Mehta", "stage": "new" }
  ],
  "meta": { "page": 1, "total": 148 }
}

AI assistant · MCP

Which leads came in this week?

toollist_leads{ created: "this_week" }Scoped to you

12 new leads this week - 4 already qualified. Priya Shah is the highest-value.

No delete tools · audit-logged

What's inside

Six developer capabilities

REST API

Standard REST endpoints over api/v1, authenticated with tokens.

API Tokens & Scopes

Self-issued tokens, read-only or read-write, with a 30-day default expiry.

Webhooks

Outbound and inbound events with a delivery log, for direct integrations.

Public API (mTLS)

Certificate-secured endpoints built for partner and system integrations.

MCP Server

Around 50 tools for AI clients, scoped to your own permissions and logged.

API Documentation

Reference, examples and a changelog for every endpoint.

Capability 01

REST API

CRMLeaf's REST API exposes the platform's core objects over versioned endpoints (api/v1), authenticated with personal access tokens rather than session cookies - the same API a mobile app or an AI assistant integration would call.

  • Versioned endpoints (api/v1)
  • Token authentication (Sanctum)

Built in

  • REST endpoints over api/v1, authenticated with tokens
  • The same underlying API used by CRMLeaf's own mobile app
Read the API documentation

Capability 02

API Tokens & Scopes

Personal access tokens are issued from Profile → Access Tokens, with a 30-day default validity and a choice of read-only or read-write scope, so an integration or assistant gets exactly the access it needs and nothing more.

  • Self-issued
  • Read-only or read-write
  • 30-day default expiry

Built in

  • Self-issued personal access tokens with a 30-day default expiry
  • Read-only or read-write scoping per token
  • Tokens power both API integrations and MCP (AI assistant) access
Explore API tokens

Capability 03

Webhooks

The webhook engine gives you configurable outbound and inbound webhooks with a delivery log, for when you or a developer want a direct connection to CRMLeaf rather than a middleware service like Zapier. Every delivery is recorded, so you can tell whether an automation actually received the data.

  • Outbound & inbound events
  • Delivery log
  • Direct integration, no middleware required

Built in

  • Configurable outbound webhooks that send data to a URL you own when something happens in CRMLeaf
  • Inbound webhooks that let an external system send data in
  • A delivery log recording every attempt, so a missed automation is easy to diagnose
Explore webhooks

Capability 04

Public API (mTLS)

For partner and system integrations that need machine-to-machine access with stronger authentication than a bearer token, CRMLeaf offers a certificate-secured (mTLS) public API endpoint.

  • Certificate authentication
  • Built for partner systems

Built in

  • mTLS certificate-authenticated endpoints for machine-to-machine access
  • Aimed at partner and system integrations rather than ad-hoc scripting
Explore the public API

Capability 05

MCP Server

CRMLeaf's MCP server exposes around 50 tools so an AI assistant - Claude Desktop, Claude CLI, Cursor or VS Code Copilot, or any Model Context Protocol client - can read and act on your CRM data. It calls the API as you, forwarding your own token, so it's bound by the same multi-tenant scoping and per-user permissions you already have; the MCP server exposes no delete tools by design, and the audit trail records who acted, the action and the fields touched, never the values.

  • ~50 tools, permission-scoped
  • Any MCP client
  • No delete tools by design
  • Field-level audit trail

Built in

  • Around 50 tools for AI clients, bound by the same permissions as the person connecting
  • Works with any Model Context Protocol client, including Claude Desktop, Claude CLI, Cursor and VS Code Copilot
  • No delete tools, by design
  • Audit trail records who acted, the token, the action, the record and the field names touched - never the field values
Explore the MCP server

Capability 06

API Documentation

Reference documentation, worked examples and a changelog live alongside the API itself, so a developer integrating against CRMLeaf isn't working from a wiki page that's fallen out of date.

  • Reference & examples
  • Changelog

Built in

  • Endpoint reference with examples
  • A changelog tracking API changes over time
Explore the API docs
Built on the same platform

One API, the same permissions as your team

Every developer surface - REST, webhooks, the public API and the MCP server - reads and writes through the same ownership-scoped permissions your team already has. Nothing here is a separate, less-audited path into your data.

See Roles & Permissions →

Administration

Same roles, same ownership-scoped visibility

Integrations

40+ integrations, several webhook-driven

AI & Automation

Workflow Automation triggers alongside the API

Security

Audit log covers API and MCP activity too

FAQ

Common questions about CRMLeaf's developer platform

Start building on CRMLeaf

Generate a token, call the API, or point your AI assistant at the MCP server - all inside your free trial.