# Z League — MEGA Public CRM Lead API > Z League is an a16z-backed startup that operates MEGA (gomega.ai), a suite of AI marketing agents for SEO, ads, and growth with a built-in CRM. The MEGA public CRM Lead API is a server-to-server REST API to pull/search leads (keyset cursor pagination), push leads (single + bulk up to 500, idempotent, email/phone de-duplication), and manage HMAC-signed `lead.created` webhooks. Auth is an admin-issued, customer-locked, scoped Bearer PAT (`mega_...`) plus an `x-customer-id` header. Base URL: https://app.gomega.ai. This llms.txt was generated by the API Evangelist enrichment pipeline from the provider's public OpenAPI and docs. ## API - [MEGA Public CRM Lead API — OpenAPI 3.1](https://raw.githubusercontent.com/api-evangelist/z-league/refs/heads/main/openapi/z-league-crm-lead-openapi.json): 7 operations across Leads and Webhooks. ## Docs - [Developer portal / API reference](https://docs.gomega.ai) - [Quickstart](https://docs.gomega.ai/quickstart) - [Authentication](https://docs.gomega.ai/authentication) - [Pull leads](https://docs.gomega.ai/pull-leads) - [Push leads](https://docs.gomega.ai/push-leads) - [Webhooks](https://docs.gomega.ai/webhooks) - [Rate limits](https://docs.gomega.ai/rate-limits) - [Errors](https://docs.gomega.ai/errors) - [Changelog](https://docs.gomega.ai/changelog) ## Operations - listLeads — GET /api/agents/crm/leads (scope public_api:leads:read) - createLead — POST /api/agents/crm/leads (scope public_api:leads:write) - bulkImportLeads — POST /api/agents/crm/leads/bulk (scope public_api:leads:write) - listWebhooks — GET /api/agents/crm/lead-webhooks (scope public_api:webhooks:manage) - createWebhook — POST /api/agents/crm/lead-webhooks (scope public_api:webhooks:manage) - updateWebhook — PATCH /api/agents/crm/lead-webhooks/{id} (scope public_api:webhooks:manage) - deleteWebhook — DELETE /api/agents/crm/lead-webhooks/{id} (scope public_api:webhooks:manage) ## Conventions - Auth: `Authorization: Bearer mega_` + `x-customer-id: `. Server-to-server only. - Idempotency: send `Idempotency-Key` on creates; replay returns the original response; reuse with a different body returns 409. - Pagination: keyset `cursor`/`next_cursor` (valid only for the same sort); `limit` 1–100 (default 20); offset fallback. - Errors: `{ "error": { "type", "code", "message" } }` (not RFC 9457). - Rate limits: 60/min + 1000/hour default; bulk 10/min; `RateLimit-*` headers + `Retry-After` on 429. - Webhooks: `lead.created`, HMAC-SHA256 `X-Mega-Signature` over `${timestamp}.${rawBody}`, at-least-once with retries. ## Company - [Website](https://www.gomega.ai) - [Blog](https://www.gomega.ai/blog/) - [Pricing](https://www.gomega.ai/pricing) - [GitHub organization](https://github.com/zleague) - Support: support@gomega.ai