Developers
A REST API, webhooks and developer tools.
A REST API to create and read leads, embeddable inquiry forms and chat for program pages, and a secured webhook trigger for workflows, so your IT team can connect the website, the application portal and the SIS.
Samples use placeholders. Your API base URL is shown in Settings > API Access.
# Send an inquiry from your application portalcurl -X POST https://YOUR-API-BASE-URL/v1/leads \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "first_name": "Emily", "last_name": "Carter", "email": "emily.carter@example.com", "phone": "+1 555 0142", "source": "Application portal" }'What your developers can use.
The API, the website widgets and the webhook trigger work the same way for every account, so your IT team can plan an integration against this list.
REST API for leads
Create leads from your website, application portal or event check-in app, and read them back for status checks.
Scoped API keys
One key per integration with only the access it needs. Revoke, rotate or reactivate a key without touching the others.
Per-key quotas
Request quotas on each key stop one integration from crowding out the rest.
IP allow-list
Accept API calls only from the campus or vendor networks you list as CIDR ranges.
Embeddable forms
Program-page inquiry forms with CAPTCHA, spam protection and UTM capture, added with a snippet.
Chat widget
Website chat that runs your chatbot and creates an inquiry once a visitor shares an email or phone number.
Signed inbound webhooks
Integration webhooks must carry a valid HMAC-SHA256 signature; workflow webhook URLs require a secret header.
Inbound webhook trigger
Your portal or SIS calls a workflow's URL. The workflow can look up the lead by email or lead ID and use the request body in its steps.
REST API
Create leads from your portal. Read them back from any campus system.
Post an inquiry from your website, application portal, event check-in app or a partner system, and it arrives as a lead with its source attached, ready for routing, scoring and workflows. Read leads back to show an applicant's stage in another system.
- One scoped key per integration
- Per-key quotas plus platform rate limiting
- IP allow-list for campus and vendor networks
- Source saved on each lead you create
curl https://YOUR-API-BASE-URL/v1/leads/LEAD_ID \ -H "Authorization: Bearer YOUR_API_KEY"{ "id": "LEAD_ID", "name": "Emily Carter", "stage": "Qualified", "owner": "Daniel Brooks", "source": "Application portal", "created_at": "2026-09-18T09:12:00Z"}Add inquiry forms and chat to program pages with a snippet.
Forms and the chat widget sit on your own pages, including program pages in your content management system, and send each inquiry to higheredcrm.ai with its source and campaign details. Copy the exact snippet from Settings > Embeddable Widgets.
<!-- Where the form should render on the program page --><div id="inquiry-form"></div><script src="https://YOUR-WIDGET-HOST/embed.js" data-form-key="YOUR_FORM_KEY" data-target="#inquiry-form" async></script>- CAPTCHA and spam protection
- UTM and campaign values saved
- A repeat inquiry updates the existing lead
<!-- Add once, before </body>, on pages that show chat --><script src="https://YOUR-WIDGET-HOST/widget.js" data-widget-key="YOUR_WIDGET_KEY" async></script>- Creates an inquiry once the visitor shares an email or phone number
- Runs your flow-based chatbot
- Transcript saved to the lead's communication log
Signature and secret checks
Requests without a valid signature or secret are rejected.
Webhooks from connected integrations are checked against an HMAC-SHA256 signature, and each workflow webhook URL needs its secret header, which you can regenerate. Integration logs show what arrived when your IT team needs to troubleshoot.
- An HMAC-SHA256 signature on every integration webhook
- A regenerable secret header on each workflow webhook URL
- Integration logs for troubleshooting
- No outbound webhooks: your systems read leads through the API
// Reject any request whose signature doesn't matchconst expected = hmacSha256(rawBody, INTEGRATION_SECRET);if (!safeEqual(expected, signatureHeader)) { return reject(401);}POST /workflows/YOUR_WORKFLOW_IDX-Webhook-Secret: wrong-valueHTTP/1.1 401 UnauthorizedInbound webhook trigger
Let your portal or SIS start a workflow.
Add a webhook trigger to any workflow. When your application portal, SIS or event app calls it, the workflow runs its steps: send a message, assign a counselor, change a stage or create a follow-up.
- 1
Add the trigger
Pick Webhook as the workflow's trigger in the builder.
- 2
Copy the URL and secret
Each workflow gets its own URL and a secret header, and you can regenerate the secret.
- 3
Call it
Your portal posts to the URL when its event happens, such as an applicant creating an account.
- 4
Watch it run
Open the workflow's run history to see each run, what started it and the result of each step.
curl -X POST https://YOUR-WORKFLOW-WEBHOOK-URL \ -H "X-Webhook-Secret: YOUR_SECRET" \ -H "Content-Type: application/json" \ -d '{ "email": "emily.carter@example.com", "event": "portal_account_created" }'About these samples. They use placeholder hosts (such as YOUR-API-BASE-URL), placeholder keys and generic field and event names. Your API base URL is shown in Settings > API Access, each workflow's webhook URL is shown on its trigger, and widget snippets are in Settings > Embeddable Widgets. Your account comes with the exact endpoints, authentication details and payloads, and we can take your developers through them.
Where API-created leads go next.
Integrations
Messaging, email, SMS, calling and single sign-on connections.
ExploreWorkflow automation
Triggers, conditions, waits and actions, with a run history for each workflow.
ExploreLead capture
Forms, website chat, WhatsApp, Messenger and imports, checked for duplicates.
ExploreRoles, security & campuses
SSO, MFA, audit logs, API key IP allow-lists and field encryption.
ExploreTrust center
How applicant data is protected, for your security review.
ExploreFor IT & operations
The checks an IT team runs before go-live.
ExploreGlossary: Inquiry, Attribution, Workflow automation, CRM vs SIS
FAQ
Questions from developers
What can our IT team build with the API?
The public REST API creates and reads leads. A common setup sends inquiries from the application portal, the website or an event check-in app, and looks leads up from another campus system. Keys are scoped, subject to quotas and can be limited by IP allow-list.
Is there a public API reference?
Not on this site. The samples here use placeholders for the base URL, keys and field names. Your API base URL is shown in Settings > API Access, the exact endpoints, authentication details and field names come with your account, and our team can go through them with your developers.
Can the API change a stage or send a message to an applicant?
Not directly: the public API creates and reads leads. To change a stage, send a message or create a follow-up when something happens in your SIS or portal, call a workflow's inbound webhook trigger and let the workflow take those steps.
How does higheredcrm.ai verify requests from our systems?
Webhooks from connected integrations must carry a valid HMAC-SHA256 signature, and each workflow webhook URL requires its secret header, which you can regenerate. Requests that fail either check are rejected.
Does the web team need a developer to add forms to program pages?
Not usually. Forms and the chat widget go in by pasting a snippet into your pages or your content management system. Forms include CAPTCHA and spam protection and save UTM parameters with each inquiry.
What controls will our security review find on the API?
A scope on each key, quotas on request volume, IP allow-lists in CIDR ranges and platform rate limiting. Keys can be revoked, rotated or reactivated, and stored credentials are encrypted with AES-256.
How do we move leads from ad platforms or a previous CRM?
You can post leads to the REST API from another tool, or call a workflow's webhook trigger when something changes on the other side. For a one-off migration, import a CSV or Excel file of up to 50,000 rows, with duplicates skipped and reported.
Connect your campus systems to higheredcrm.ai.
Bring a developer to the call. We'll cover authentication, the lead fields your portal would send and where a workflow webhook fits alongside your SIS.