CRM setup
Send leads to your CRM
Every lead can land in your CRM the moment it’s yours, next to the text and email you already get. Use any CRM through a webhook, or connect HighLevel directly.
Send leads to any CRM with a webhook
A webhook is a URL your CRM gives you. We post each new lead to it as JSON the moment the lead is yours. Your text, email and dashboard keep working the same way; the webhook is extra.
- In your CRM, create an inbound webhook and copy its URL. It must start with https://.
- In BuyFEXLeads, open Dashboard, then Settings, then Send leads to your CRM. Paste the URL and tap Save.
- Copy the signing secret that appears. We only show it once. You can rotate it later.
- Pick what to send: New leads (on by default) and, if you want, Outcomes (when you mark Contacted, Appt set or Sold).
- Tap Send test lead. It posts a made-up lead marked
"test": true, and the result shows under Recent deliveries.
What we send
A POST with a JSON body. Map these fields in your CRM. Use id to skip repeats: a retry has the same id.
{
"event": "lead.delivered",
"version": 1,
"id": "3f1c2a8e-0000-4000-8000-0000000000e9",
"sent_at": "2026-09-27T15:04:05.000Z",
"lead": {
"id": "8a2b0000-0000-4000-8000-000000000041",
"first_name": "Dana",
"last_name": "Ruiz",
"phone": "+16145550110",
"email": null,
"state": "OH",
"zip": "43215",
"age_band": "70-79",
"coverage": "$10,000 to $15,000",
"for_whom": "parent",
"budget": "About $50/mo",
"tobacco": "No",
"health": "1 or 2 conditions",
"phone_verified": true,
"consent": { "at": "2026-09-27T15:01:58.000Z", "trustedform_cert_url": null },
"assigned_at": "2026-09-27T15:04:03.000Z",
"dashboard_url": "https://buyfexleads.com/dashboard/leads"
},
"agent": { "id": "c0de0000-0000-4000-8000-000000000077", "email": "you@agency.com" }
}A few more fields ride along. Send a test lead to see every field your CRM will get.
phone is in +1 format. When for_whom isn’t self, the name and phone belong to the person who filled out the quiz (for example an adult child), and the age, state and health answers are about the person to be covered. An Outcomes event adds an outcome object with the stage, and on Sold the policy’s face amount and yearly premium in dollars.
Check the signature (optional)
Each request carries X-BFL-Timestamp and X-BFL-Signature. If you run your own endpoint, check them so no one else can post fake leads to it. Zapier and Make users can skip this.
import crypto from 'node:crypto'
// rawBody: the request body exactly as received (a string, not parsed JSON)
function isFromBuyFEXLeads(rawBody, headers, secret) {
const ts = headers['x-bfl-timestamp']
const sig = headers['x-bfl-signature'] || ''
if (Math.abs(Date.now() / 1000 - Number(ts)) > 300) return false
const want = 'v1=' + crypto.createHmac('sha256', secret).update(ts + '.' + rawBody).digest('hex')
return sig.length === want.length && crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(want))
}Retries and auto-off
Any 2xx response counts as delivered. We wait up to 10 seconds and don’t follow redirects, so use the final URL. If your CRM doesn’t answer, or answers with a 5xx or 429, we try again: about 1 minute, 5 minutes, 30 minutes, 2 hours and 6 hours later. A retry can run later than that when the site is quiet.
After 5 deliveries in a row fail, we turn the webhook off and email you. Leads still reach you by text, email and your dashboard. Fix the URL, send a test lead, then turn it back on.
HighLevel and CRMs built on it (beta)
Our HighLevel app puts each lead straight into your HighLevel sub-account, and it works with CRMs built on HighLevel. It is in beta: it works end to end, and we’re still watching it closely. The webhook above keeps working alongside it.
- In BuyFEXLeads, open Dashboard, then Settings, then Connect HighLevel CRM, and tap Connect HighLevel.
- Sign in to HighLevel if asked, pick your sub-account, and approve access. You come right back to Settings.
- Pick the pipeline and the stage new leads should land in, and the tags to add (BuyFEXLeads by default).
- Tap Save setup, then Send test lead. A contact named TEST shows up in HighLevel, tagged BuyFEXLeads test, with an opportunity. Delete it whenever you like.
Started the install from HighLevel instead? After you approve it, we ask you to sign in to BuyFEXLeads and confirm which account to link. The link works for an hour, in the same browser. One HighLevel sub-account can link to one BuyFEXLeads account.
What the app creates in HighLevel
- A contact for each lead: name, phone in +1 format, email when there is one, state and ZIP, with source BuyFEXLeads. If the contact already exists, your HighLevel duplicate settings decide whether it is updated.
- Tags you picked, added to the contact. Tags already on the contact stay.
- Custom fields, created once when you first save your setup (only the ones that are missing): BFL Coverage For, BFL Age Range, BFL Coverage Amount, BFL Budget, BFL Tobacco, BFL Health, BFL Phone Verified, BFL Consent Time, BFL TrustedForm Cert, BFL Lead ID and BFL Lead URL.
- An opportunity named “FE lead: <name>” in your pipeline and stage, open, with a value of $0.
If HighLevel is down or slow we try again on the same schedule as webhooks. A lead is never sent twice, and a problem on the HighLevel side never holds up your text and email. If HighLevel stops accepting our connection, we email you and the card in Settings shows what to do.
Outcomes from your pipeline
In the setup, you can map any of your pipeline stages to Contacted, Appt set or Sold, and choose whether an opportunity marked Won counts as Sold. When one of our opportunities moves into a mapped stage, we record that outcome on the lead, as if you had tapped it in the dashboard.
- Only opportunities we created count. Moving other deals does nothing here.
- A lead never moves backward. Moving to Appt set also records Contacted if it wasn’t already.
- Leads you reported as bad are left alone.
- A Sold from HighLevel has no policy details yet. Open the lead and tap Log the policy so your premium and return add up.
Can’t install apps? Use a Private Integration token
Some HighLevel accounts can’t install apps. You can connect with a Private Integration token instead. On the same card in Settings, open Can’t use the app?
- In HighLevel, open your sub-account, then Settings, then Private Integrations, and create one with these scopes: View and Edit Contacts, View and Edit Opportunities, View Locations, View and Edit Custom Fields, Edit Tags.
- Paste the token and your location id (Settings, Business Profile) and tap Connect with token.
- Pick your pipeline, stage and tags, save, and send a test lead.
Leads go to HighLevel the same way. Stage changes don’t come back on their own with a token: tap Contacted, Appt set or Sold on the lead in your dashboard. If you rotate the token in HighLevel, disconnect and connect again with the new one.
Your HighLevel access
We store HighLevel’s access tokens (or your private token) encrypted, and use them only to add your leads and to read the pipelines, stages and custom fields your setup needs. Disconnect in Settings, or uninstall the app in HighLevel, and we delete them. See our privacy policy.
Zapier or Make
Use our webhook to start a Zap or a scenario, then send the lead anywhere those tools reach.
- Zapier: create a Zap with the Webhooks by Zapier trigger and pick Catch Hook. Make: start a scenario with the Webhooks module and pick Custom webhook.
- Copy the URL it gives you and save it in Dashboard, Settings, Send leads to your CRM.
- Tap Send test lead so Zapier or Make can see the fields.
- Add your next step (your CRM, a Google Sheet, a text) and map the fields from the test lead.
- Turn the Zap or scenario on.
Troubleshooting
- The URL won’t save. It must start with https:// and use the normal port. Private and local addresses are blocked.
- The test says Not delivered. Check the HTTP code shown. A 404 usually means the URL was copied wrong. A 3xx means the URL redirects: use the final one. No response means your endpoint took over 10 seconds or is down.
- Zapier or Make shows nothing. Make sure the Zap or scenario is listening for data, then send the test lead again.
- The webhook turned itself off. 5 deliveries in a row failed. Fix the URL, send a test lead, then turn it back on.
- Signature checks fail. Check the raw body, not parsed JSON. If you rotated the secret, the old one stopped working at once.
Still stuck?
Email hello@buyfexleads.com with your CRM’s name and what the test showed. See support for other ways to reach us.
Questions? Email hello@buyfexleads.com.