Contact leads
HMAC ingest, operator Review, Plane issue, then read approved leads.
Contact leads is the proving journey: website form → signed webhook → contact-lead workflow → Plane → Experience API.
Journey
- Partner POSTs
eventType: contact.leadwith a uniqueexternalId. See Sign requests. - Connect persists the lead JSON on the event row, then starts
contact-leadunder the accept correlation id. - Fork: Matrix notify runs in parallel with operator Review (23h timeout).
- Approve →
createPlaneLead. Reject or timeout → skip Plane; run Completed. - Integrators read approved issues with
GET /api/v1/leads.
Read API
| Method | Path | Auth |
|---|---|---|
GET | /api/v1/leads | API key (contact-leads grant) or JWT |
GET | /api/v1/leads/{leadId} | same |
Query: limit, cursor, since, state, label. This API reads the Plane side only — not the webhook event payload.
PII boundary
| Store | Contents |
|---|---|
| Webhook event row | Full lead JSON |
| Workflow input | Ids only (correlationId, catalog id, webhookEventId, externalId) |
| Hop result | Ids / ok flags — no Authorization header |
Try it
APIs → Experience → Contact leads.
If this fails
| Symptom | Cause |
|---|---|
| Duplicate 200 | Same (partnerId, externalId) — expected |
| Approve, no Plane issue | Plane hop failed — inspect the run graph |
403 on GET leads | Consumer missing contact-leads grant |
| Waiting forever | Operator has not reviewed and timeout has not fired |
Next: Review a task · Authentication