Help
Webhooks, incoming leads and API keys
Three ways LASSO talks to your other software: webhooks send events out, incoming lead keys bring leads in, and API keys let scripts work as you.
Everything here lives in Settings, in the Connections and webhooks card. Managers see all three sections. Reps see only Your API key.
Add a webhook (managers)
A webhook sends a short message to a web address you choose whenever something happens in LASSO, such as a new lead or a won deal. The other system can then act on it.
- In Connections and webhooks, under Webhooks, tap Add a webhook.
- Give it a Name you will recognize, such as the system it feeds.
- Paste the Address it should send to. It must start with https and be reachable on the public internet.
- Under Which events, tick Every event or pick the ones you want.
- Tap Add webhook.
- LASSO shows the webhook's secret once. Tap Copy secret and give it to whoever runs the receiving end.
- Tap Send a test now to check that the address answers.
The events you can send
| Event | When it is sent |
|---|---|
| New lead | A lead is made from a card scan, a kept Find leads place, a QR form, an incoming lead key, the app or the API. |
| Lead closed | A rep closes a lead, with the reason. |
| Lead reopened | A closed lead is opened again. |
| Lead taken over | A rep takes over a teammate's untouched lead. |
| New account | An account is made in the app, from a card, from a lead, or by an import. |
| New deal | A deal is added. |
| Deal won | A deal moves to a won stage. Sent once per deal. |
| Stop done | A stop is marked done, with the door outcome if there was one. |
| Meeting booked | A meeting is booked from a QR form or a voice note. |
Leads made from canvassing pins do not send New lead yet. You may also see one or two other event names in the list that do not apply to your company. Leaving them unticked is fine.
Signatures and retries, in plain words
- Each message is JSON. It names the event, your company, the rep involved, the time, a link back into LASSO, and the record's details in plain words.
- Each message is signed. LASSO combines the timestamp and the message with your webhook's secret (HMAC SHA-256) and sends the result in the x-lasso-signature header, with the time in x-lasso-timestamp. The receiving end does the same math with the same secret; if the two match, the message really came from LASSO. It should also refuse a message whose timestamp is more than five minutes old.
- LASSO waits up to 8 seconds for an answer. If the address does not answer with success, LASSO tries again on a schedule of about 1 minute, 5 minutes, 30 minutes, 2 hours and 12 hours (it checks for retries every 15 minutes), then gives up on that message.
- After five failures in a row, the webhook shows Failing and managers get an alert. One success clears it.
Each webhook has Send a test, Deliveries (the last 50 messages, with their status and the answer they got), Edit, and Turn off. Webhooks are turned off, never deleted. In Edit, tick New secret if the old one leaked; the old secret stops working.
Take leads in from web forms and call tracking (managers)
An incoming lead key is a private web address. When your website's contact form, a call-tracking service or Zapier sends a lead there, it shows up in LASSO for a rep, with an alert.
- Under Incoming leads, tap Add an incoming key.
- Give it a Name that says where leads come from, such as "Website contact form."
- Under Leads go to, pick a rep, or leave Round robin, which gives each lead to the rep with the fewest open leads.
- Tap Make the key.
- LASSO shows the address once. Tap Copy address. Anyone with it can create leads for your company, so treat it like a password.
- Use the sample under A plain HTML form for a website form, or the From a script sample for other systems.
What to send: company is required, plus a phone, an email or a note. LASSO also reads name (or first and last name), title, street, city, state, ZIP, source, the type of work, and a redirect address for a thank-you page. A source like "Web: Contact form" or "Call: Google Ads" shows on the lead. If your call-tracking service is CallRail, LASSO reads its caller name, phone, city and source fields as they come.
Make a personal API key (anyone)
An API key lets a script or another tool work in LASSO as you. It sees what you see and can do what you can do.
- Under Your API key, tap Make a key.
- In What is it for?, name it (for example, Zapier).
- Under What can it do?, pick Read and write or Read only.
- Tap Make the key, then Copy key. It is shown once; LASSO keeps only a fingerprint of it.
Send the key in an Authorization: Bearer header to your company's LASSO address followed by /api/. Each key allows up to 600 calls a minute. Each key shows when it was made and last used; tap Revoke to stop it right away. There is no published API reference yet, so ask your LASSO admin at WebPro360 for the calls you need.
Use Zapier
Zapier works with LASSO today through Zapier's own Webhooks by Zapier steps. A LASSO app inside Zapier is Coming.
- LASSO events into a Zap: start a Zap with a Webhooks by Zapier catch hook, copy the address Zapier gives you, and add it in LASSO as a webhook (above). Pick the events you want, then send a test so Zapier sees a sample.
- Leads from a Zap into LASSO: add a Webhooks by Zapier step that posts to an incoming lead key's address (above), with at least the company name and a phone, email or note.
LASSO's messages are its own JSON, so a chat app or another tool that expects a different format needs a step in between, such as a Zap.