Leads

Lead forms, consent & webhooks

Collect leads with a consent checkbox, deliver them to a webhook (Zapier, Make, n8n) or by email, and verify webhook signatures.

Any page can collect leads: email sign-ups for a lead magnet, quote requests, or a qualifying step before an offer. Leads are stored in your workspace and can be delivered automatically to the tools you already use.

Adding a form

Add a form section to the page (lead capture templates already include one). In the side panel you can:

  • choose the fields — email, name, phone and your own custom fields — and which are required;
  • write the consent text shown next to the checkbox;
  • choose what happens after a submission: show a success message, or redirect to another URL such as a thank-you page or the offer.

Forms include built-in spam protection, and they don’t submit in the editor, so testing your layout won’t create leads.

The consent checkbox records that the visitor agreed to what your consent text says. Make the text specific — who will contact them, about what, and how to opt out — and link to your privacy notice. You are responsible for having a lawful basis to collect and use the data, and for honoring opt-outs, in each country you advertise in. For your visitors’ data, you are the controller and we process it on your behalf; see our privacy policy.

Where leads go

Every lead is stored first, so nothing is lost if a delivery fails. Open Leads to see them, filter by page, and export as CSV at any time.

To deliver leads automatically, add an integration under Integrations:

  • Webhook: we send each new lead as a JSON POST request to the URL you enter.
  • Email: we email each new lead to the address you enter.

Integrations apply to every page by default; you can limit one to specific pages. Use the Test button to send a sample lead and confirm everything is wired up.

Zapier, Make and n8n

You don’t need a dedicated integration: these tools accept webhooks.

  • Zapier: create a Zap with the Webhooks by Zapier → Catch Hook trigger and paste its URL into a webhook integration.
  • Make: add a Webhooks → Custom webhook module and paste its address.
  • n8n: add a Webhook node set to POST and paste its production URL.

Send a test lead, then map the fields to your email platform, CRM or spreadsheet.

What a webhook receives

Each new lead is sent as a JSON POST with a 10-second timeout. Redirects aren’t followed, so use your endpoint’s final URL.

An example request body (the values are illustrative):

{
  "event": "lead.created",
  "test": false,
  "workspaceId": "ws_…",
  "lead": {
    "id": "lead_…",
    "createdAt": "2026-10-03T12:00:00.000Z",
    "pageId": "pg_…",
    "pageName": "Spring guide",
    "variantId": "var_…",
    "email": "reader@example.com",
    "data": { "name": "Sam" },
    "consent": true,
    "consentText": "Yes, email me the guide and occasional offers."
  }
}

Test sends from the Test button have "test": true, so you can filter them out.

Verifying webhook signatures

Every request carries an X-NuPages-Signature header in the form t=<unix seconds>,v1=<signature>. The signature is a hex-encoded HMAC-SHA256 of the timestamp, a period, and the raw request body, computed with the secret shown on your integration:

expected = hex(HMAC_SHA256(secret, t + "." + raw_body))

Compare it with v1 using a constant-time comparison, and reject requests whose timestamp is more than a few minutes old. Always use the raw body exactly as received — re-serializing the JSON changes it. Keep the secret private, and regenerate it if it’s exposed.

If a delivery fails

If your endpoint is down, times out or returns an error, we retry automatically after about 1 minute, 5 minutes, 30 minutes, 2 hours and 6 hours. After the last attempt the delivery is marked as failed, and you can send it again from the lead once your endpoint is fixed. The lead itself is always kept in Hooklander, so you can see it in Leads and export it in the meantime.