# SharpSpring (Constant Contact Lead Gen & CRM) > Marketing automation and CRM for small businesses and digital marketing agencies. SharpSpring was > acquired by Constant Contact in 2021 and is now sold as Constant Contact Lead Gen & CRM, but the > developer surface is still branded and hosted as SharpSpring. That surface is the SharpSpring Open > API: one HTTPS POST endpoint that takes a JSON envelope of `method`, `params` and `id` — the > provider calls it "very similar to JSON-RPC" — exposing roughly 120 published methods across leads, > accounts, opportunities, campaigns, deal stages, emails, email jobs, lists, list members, fields, > folders, notes, products and tasks. Generated by API Evangelist on 2026-08-12. SharpSpring serves no /llms.txt of its own (https://sharpspring.com/llms.txt → 404, https://api.sharpspring.com/llms.txt → 307). This file is an independent third-party profile, not a provider document. ## What an agent needs to know first - **Base URL**: `https://api.sharpspring.com/pubapi/v1.2/` — all timestamps UTC. The older `https://api.sharpspring.com/pubapi/v1/` resolves timestamps against the account's Company Profile time zone. Both are live; prefer v1.2. - **Every call is `POST`** to that one URL with `Content-Type: application/json` and a body of `{"method": "...", "params": {...}, "id": "..."}`. There are no resource paths. - **Auth is a static credential pair**, an account ID and secret key generated by an account admin under Settings > SharpSpring API > API Settings. Pass them as `?accountID=…&secretKey=…` on the query string (which takes precedence), or as the `X-Account-Id` header plus an `Authorization: bearer` header. No OAuth, no scopes, no expiry, no per-user credentials — one credential reads and writes everything in the account. - **Errors do not use HTTP status.** A response is `{"result": …, "error": …, "id": …}`. API-level failures populate `error` with a numeric code; per-object failures in a bulk write leave `error` null and hide the failures inside the `result` array. Check both. - **Rate limits are published but not signalled.** 50,000 requests/day, 10 queries/second, 500 queries/request, 100 leads per lead-processing call. There are no `RateLimit-*` or `Retry-After` headers and no HTTP 429 — exhaustion arrives as error code 106, 107, 209 or 222. - **There is no idempotency key.** A retried write after a timeout has no defined outcome. The only protection is that `emailAddress` is the natural key on a lead. - **There is no webhook subscription API.** Events are pushed by Postback URLs a human configures on a form or an automation step, as `multipart/form-data`, unsigned, with no documented retries. Most integrations poll the `*DateRange` methods instead. - **There is no OpenAPI, JSON Schema, GraphQL SDL, AsyncAPI, MCP server or agent card.** The object schemas are HTML tables in a knowledge base. ## Docs - [Open API: Overview](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50374-Understanding-Lead-Gen--CRM-Open-API-Overview?lang=en_US): endpoint, auth, envelope, rate limits - [Open API: Methods](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50564-Understanding-Lead-Gen--CRM-Open-API-Methods?lang=en_US): the full method index, grouped by object - [Open API: Example Code](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50404-Understanding-Lead-Gen-CRM-Open-API-Example-Code?lang=en_US): PHP cURL request/response samples - [Open API: Error Codes](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50570-Understanding-Lead-Gen-CRM-Open-API-Error-Codes?lang=en_US): every numeric code and message - [Open API Schema: Leads](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50881-Understanding-Lead-Gen-CRM-Open-API-Schema-Leads?lang=en_US) - [Open API Schema: Opportunities](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50887-Understanding-Lead-Gen-CRM-Open-API-Schema-Opportunities?lang=en_US) - [Open API Schema: Emails](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50888-Understanding-Lead-Gen--CRM-Open-API-Schema-Emails?lang=en_US) - [Open API Schema: Lists](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50880-Understanding-Lead-Gen-CRM-Open-API-Schema-Lists?lang=en_US) - [Using Postback URLs](https://knowledgebase.constantcontact.com/lead-gen-crm/articles/KnowledgeBase/50234-Using-Postback-URLs?lang=en_US): the event surface - [Knowledge base home](https://knowledgebase.constantcontact.com/lead-gen-crm?lang=en_US) ## Operations - [Status page](https://status.sharpspring.com/) — Atlassian Statuspage, 20 components including a dedicated "APIs and Integrations" component - [Status API](https://status.sharpspring.com/api/v2/summary.json) — machine-readable - [security.txt](https://api.sharpspring.com/.well-known/security.txt) — RFC 9116, served on the API and app hosts - [Responsible disclosure](https://www.constantcontact.com/disclosure) - [App marketplace](https://sharpspring.com/app-marketplace/) - [Support](https://sharpspring.com/customer-support/) ## API Evangelist artifacts in this repository - `authentication/sharpspring-authentication.yml` — the credential model and its failure modes - `conventions/sharpspring-conventions.yml` — envelope, pagination, versioning, tracing, gaps - `errors/sharpspring-problem-types.yml` — all 38 published error codes, classed - `rate-limits/sharpspring-rate-limits.yml` — the five published limits and the missing headers - `data-model/sharpspring-data-model.yml` — 20 entities, 17 relationships, 121 methods indexed - `asyncapi/sharpspring-postbacks-webhooks.yml` — the Postback event surface - `lifecycle/sharpspring-lifecycle.yml` — versioning, status page, absent deprecation policy - `conformance/sharpspring-conformance.yml` — what it does and does not conform to - `packages/sharpspring-packages.yml` — zero first-party SDKs; every client library is stale - `plans/sharpspring-plans-pricing.yml` — no published prices - `well-known/sharpspring-well-known.yml` — the /.well-known/ probe matrix - `security/sharpspring-domain-security.yml`, `security/sharpspring-vulnerability-disclosure.yml`