REST API
Standard REST endpoints over api/v1, authenticated with tokens.
CRMLeaf's developer platform gives you a token-authenticated REST API, webhooks with a delivery log, a certificate-secured public API for partner systems, and an MCP server so Claude, Cursor or Copilot can work with your CRM data inside your own permissions.
REST API
$ curl https://api.example.com/api/v1/leads \
-H "Authorization: Bearer crmleaf_pat_••••7f3a"
200 OKread-only token · 30-day expiry
{
"data": [
{ "id": 2291, "name": "Priya Shah", "stage": "qualified" },
{ "id": 2290, "name": "Arjun Mehta", "stage": "new" }
],
"meta": { "page": 1, "total": 148 }
}AI assistant · MCP
Which leads came in this week?
12 new leads this week - 4 already qualified. Priya Shah is the highest-value.
No delete tools · audit-logged
What's inside
Standard REST endpoints over api/v1, authenticated with tokens.
Self-issued tokens, read-only or read-write, with a 30-day default expiry.
Outbound and inbound events with a delivery log, for direct integrations.
Certificate-secured endpoints built for partner and system integrations.
Around 50 tools for AI clients, scoped to your own permissions and logged.
Reference, examples and a changelog for every endpoint.
Capability 01
CRMLeaf's REST API exposes the platform's core objects over versioned endpoints (api/v1), authenticated with personal access tokens rather than session cookies - the same API a mobile app or an AI assistant integration would call.
Capability 02
Personal access tokens are issued from Profile → Access Tokens, with a 30-day default validity and a choice of read-only or read-write scope, so an integration or assistant gets exactly the access it needs and nothing more.
Capability 03
The webhook engine gives you configurable outbound and inbound webhooks with a delivery log, for when you or a developer want a direct connection to CRMLeaf rather than a middleware service like Zapier. Every delivery is recorded, so you can tell whether an automation actually received the data.
Capability 04
For partner and system integrations that need machine-to-machine access with stronger authentication than a bearer token, CRMLeaf offers a certificate-secured (mTLS) public API endpoint.
Capability 05
CRMLeaf's MCP server exposes around 50 tools so an AI assistant - Claude Desktop, Claude CLI, Cursor or VS Code Copilot, or any Model Context Protocol client - can read and act on your CRM data. It calls the API as you, forwarding your own token, so it's bound by the same multi-tenant scoping and per-user permissions you already have; the MCP server exposes no delete tools by design, and the audit trail records who acted, the action and the fields touched, never the values.
Capability 06
Reference documentation, worked examples and a changelog live alongside the API itself, so a developer integrating against CRMLeaf isn't working from a wiki page that's fallen out of date.
Every developer surface - REST, webhooks, the public API and the MCP server - reads and writes through the same ownership-scoped permissions your team already has. Nothing here is a separate, less-audited path into your data.
See Roles & Permissions →Administration
Same roles, same ownership-scoped visibility
Integrations
40+ integrations, several webhook-driven
AI & Automation
Workflow Automation triggers alongside the API
Security
Audit log covers API and MCP activity too
Generate a token, call the API, or point your AI assistant at the MCP server - all inside your free trial.