Leads from Your Website Form or API

A form on your own website — a whitepaper download, a demo request, a contact page — can create leads in AB Sales directly, and so can a backend or an automation tool. Both use one intake key from CRM Settings. Nothing on your site needs to sign in, and a plain HTML form needs no JavaScript at all.

Where the key is

Open your workspace → Settings → the Website form and API card. The first time an Owner or Admin opens it, a key is created; members see the same key read-only. The card shows the key with a copy button, a ready-to-paste HTML form snippet, an API example, and a Regenerate key button.

Two ways in

A plain HTML form

Your existing form posts straight to AB Sales and sends the visitor on to your thank-you page. Best for a download or contact form on a site without a developer on hand.

The JSON API

Your backend, Zapier, Power Automate or any tool that can make a web request sends the same fields as JSON (a plain text format for structured data) with the key as a bearer token.

1. Point an HTML form at AB Sales

  1. Copy the snippet. On the Website form and API card, click Copy next to HTML form. It already carries your key.
  2. Change the thank-you URL. The hidden redirect field is where your visitor lands after submitting — your download or thank-you page, as a full https:// address.
  3. Keep the hidden fields, add your own. key and redirect do the work; ab_hp is a honeypot (a field people never see, so a bot that fills every field it finds gives itself away and its submission is dropped). Add company, phone, website or message as extra inputs with exactly those names.
  4. Submit once yourself. The lead appears in Leads within a moment, with the source Website.
<form method="post" action="https://blz.actionbridge.io/api/crm/leads/form">
  <input type="hidden" name="key" value="lk_…your key…">
  <input type="hidden" name="redirect" value="https://www.example.com/thank-you">
  <input type="text" name="ab_hp" value="" tabindex="-1" autocomplete="off" style="display:none">

  <input name="name" placeholder="Your name">
  <input name="company" placeholder="Company">
  <input name="email" type="email" required placeholder="Work email">
  <button type="submit">Download</button>
</form>

Fields

Only email is required — it is how a repeat submission is recognised and how the lead is reached. Everything else is optional.

Form fieldAPI fieldBecomes
email requiredemailEmail
namenameContact name — or the lead’s Name when no company is given
companycompanyName. When present, name becomes the contact person, the way the Teams bot does it
phone, website, industrysamePhone, Website, Industry
sourcesourceSource. Defaults to Website; the Leads list filters on it, so keep to a few values
messagemessageNotes, up to 4,000 characters
country, language, timezonecountryCode, preferredLanguage, timeZoneCountry (JP), preferred language (ja-JP), time zone (Asia/Tokyo). A value that is not a valid code is refused, so the lead never holds one nothing downstream can read

Text fields are capped at 200 characters. If a submission is refused, the answer names the field.

2. The JSON API

The same fields, camel-cased, with the key as a bearer token (sent in the Authorization header). For a tool that cannot set that header, an X-AB-Key header carries the key instead.

curl -X POST https://blz.actionbridge.io/api/crm/leads \
  -H "Authorization: Bearer lk_…your key…" \
  -H "Content-Type: application/json" \
  -d '{"name":"Aoi Sato","company":"Contoso","email":"aoi@contoso.com","message":"Downloaded the pricing guide"}'
StatusMeaning
201A new lead. The body carries its leadId.
200 existing: trueA repeat: a note was added to that lead instead (below).
400A field was wrong. The error says which.
401Unknown key — mistyped, or regenerated since.
429The workspace is over its lead allowance, or one address is sending more than 60 requests a minute.

Repeat submissions do not make duplicates

A second submission from an email that already belongs to a live lead in the workspace does not create another lead. A note is added to the existing one — “Submitted again through the website form.” from a form, or “Submitted again through the API.” from the API, with a custom source in parentheses when one was sent — followed by whatever they wrote. So the team sees the renewed interest where they are already working, and the allowance is not spent twice on one person. Matching ignores letter case; an archived lead does not count, so somebody who comes back after being archived starts fresh.

What your visitor sees

With a redirect, always your thank-you page — including when the submission was a repeat, a bot, or the workspace is over its lead allowance. Your plan limit is your business, not your visitor’s. Without a redirect (a form submitted with JavaScript), the endpoint answers with the JSON in the table above.

If the key gets abused

Abuse costs you spam leads and allowance, nothing else. Click Regenerate key on the card, confirm, and the old key stops working at once — then paste the new key into every form and integration that used it. Requests are also rate-limited per calling address, so a scraper hits a wall a real page never will.

Your website form is just another way a lead arrives: the same lead, the same funnel, the same allowance — only the typing is gone.

Published on 2026-10-06
Version 2