IntakeFlow for developers
IntakeFlow has a complete integration layer: a REST API for import/export with other portals, signed webhooks that push events to your automations, and an MCP server so AI agents can run your whole intake pipeline.
Three ways to integrate
REST API
Import clients, send portals, export responses and files, approve or reject items.
Read →Webhooks
Signed JSON events pushed to your URL the moment something happens.
Read →MCP server
Let Claude, Cursor, or any MCP client list, send, and review portals.
Read →Authentication
Every request carries an API key as a bearer token (or in the x-api-key header). Keys have read and/or write scopes; each endpoint below lists what it needs.
curl https://your-domain.com/api/public/v1/portals \ -H "Authorization: Bearer ifl_live_YOUR_KEY"
The data model in one minute
clients— the people you send portals to (name + email).templates— reusable checklists; each has ordereditemsof typetext | file | select | credential.portals— one client × one template, with a status (not_started → in_progress → awaiting_review → complete) and a signed client link.responses— the client's answer per item. Text and files are readable via the API; credentials never are (only ahas_credentialflag).
Base URL
All endpoints are relative to your deployment root. On IntakeFlow cloud that's your workspace domain; self-hosting follows the same paths.
https://your-domain.com/api/public/v1
Errors
Errors are JSON: { "error": "message" } with a meaningful status —401 missing/invalid key, 403 scope missing,404 wrong id, 400 bad payload, and429-style plan limits reported as 400 with an upgrade hint.
Quickstart
# 1. create (or update) the client
curl -X POST https://your-domain.com/api/public/v1/clients \
-H "Authorization: Bearer ifl_live_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"name":"Acme Co","email":"hello@acme.com"}'
# 2. send the kickoff portal (emails the client their link)
curl -X POST https://your-domain.com/api/public/v1/portals \
-H "Authorization: Bearer ifl_live_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"template_id":"<from GET /templates>","client_name":"Acme Co","client_email":"hello@acme.com"}'Rate limits & etiquette
The API is designed for onboarding-scale traffic (tens of calls per day), not bulk syncing. Poll GET /portals at most every few minutes — or better, subscribe to webhooks instead of polling.