A form on your own website — a whitepaper download, a demo request, a contact page — can create leads in AB Sales directly, and so can a backend or an automation tool. Both use one intake key from CRM Settings. Nothing on your site needs to sign in, and a plain HTML form needs no JavaScript at all.
Where the key is
Open your workspace → Settings → the Website form and API card. The first time an Owner or Admin opens it, a key is created; members see the same key read-only. The card shows the key with a copy button, a ready-to-paste HTML form snippet, an API example, and a Regenerate key button.
Two ways in
A plain HTML form
Your existing form posts straight to AB Sales and sends the visitor on to your thank-you page. Best for a download or contact form on a site without a developer on hand.
The JSON API
Your backend, Zapier, Power Automate or any tool that can make a web request sends the same fields as JSON (a plain text format for structured data) with the key as a bearer token.
1. Point an HTML form at AB Sales
- Copy the snippet. On the Website form and API card, click Copy next to HTML form. It already carries your key.
- Change the thank-you URL. The hidden
redirectfield is where your visitor lands after submitting — your download or thank-you page, as a fullhttps://address. - Keep the hidden fields, add your own.
keyandredirectdo the work;ab_hpis a honeypot (a field people never see, so a bot that fills every field it finds gives itself away and its submission is dropped). Addcompany,phone,websiteormessageas extra inputs with exactly those names. - Submit once yourself. The lead appears in Leads within a moment, with the source Website.
<form method="post" action="https://blz.actionbridge.io/api/crm/leads/form">
<input type="hidden" name="key" value="lk_…your key…">
<input type="hidden" name="redirect" value="https://www.example.com/thank-you">
<input type="text" name="ab_hp" value="" tabindex="-1" autocomplete="off" style="display:none">
<input name="name" placeholder="Your name">
<input name="company" placeholder="Company">
<input name="email" type="email" required placeholder="Work email">
<button type="submit">Download</button>
</form>
message field such as Downloaded: Pricing guide lands in the lead’s Notes, so whoever picks it up knows why this person is here — and the AI research reads Notes too.Fields
Only email is required — it is how a repeat submission is recognised and how the lead is reached. Everything else is optional.
| Form field | API field | Becomes |
|---|---|---|
email required | email | |
name | name | Contact name — or the lead’s Name when no company is given |
company | company | Name. When present, name becomes the contact person, the way the Teams bot does it |
phone, website, industry | same | Phone, Website, Industry |
source | source | Source. Defaults to Website; the Leads list filters on it, so keep to a few values |
message | message | Notes, up to 4,000 characters |
country, language, timezone | countryCode, preferredLanguage, timeZone | Country (JP), preferred language (ja-JP), time zone (Asia/Tokyo). A value that is not a valid code is refused, so the lead never holds one nothing downstream can read |
Text fields are capped at 200 characters. If a submission is refused, the answer names the field.
2. The JSON API
The same fields, camel-cased, with the key as a bearer token (sent in the Authorization header). For a tool that cannot set that header, an X-AB-Key header carries the key instead.
curl -X POST https://blz.actionbridge.io/api/crm/leads \
-H "Authorization: Bearer lk_…your key…" \
-H "Content-Type: application/json" \
-d '{"name":"Aoi Sato","company":"Contoso","email":"aoi@contoso.com","message":"Downloaded the pricing guide"}'
| Status | Meaning |
|---|---|
| 201 | A new lead. The body carries its leadId. |
200 existing: true | A repeat: a note was added to that lead instead (below). |
| 400 | A field was wrong. The error says which. |
| 401 | Unknown key — mistyped, or regenerated since. |
| 429 | The workspace is over its lead allowance, or one address is sending more than 60 requests a minute. |
Repeat submissions do not make duplicates
A second submission from an email that already belongs to a live lead in the workspace does not create another lead. A note is added to the existing one — “Submitted again through the website form.” from a form, or “Submitted again through the API.” from the API, with a custom source in parentheses when one was sent — followed by whatever they wrote. So the team sees the renewed interest where they are already working, and the allowance is not spent twice on one person. Matching ignores letter case; an archived lead does not count, so somebody who comes back after being archived starts fresh.
What your visitor sees
With a redirect, always your thank-you page — including when the submission was a repeat, a bot, or the workspace is over its lead allowance. Your plan limit is your business, not your visitor’s. Without a redirect (a form submitted with JavaScript), the endpoint answers with the JSON in the table above.
If the key gets abused
Abuse costs you spam leads and allowance, nothing else. Click Regenerate key on the card, confirm, and the old key stops working at once — then paste the new key into every form and integration that used it. Requests are also rate-limited per calling address, so a scraper hits a wall a real page never will.
Your website form is just another way a lead arrives: the same lead, the same funnel, the same allowance — only the typing is gone.