Lawllama is intake software for law firms: every potential client, from first contact to signed matter.
Base URL: https://lawllama.tone.fyi
Authentication
Create an API key in the Lawllama console under API keys. Keys carry scopes; a request that needs a scope the key doesn't have gets 403 with insufficient_scope.
Authorization: Bearer YOUR_API_KEY
Scopes
leads:read | Read leads |
users:read | Read users |
leads:write | Create and update leads |
notes:write | Add notes to leads |
webhooks:manage | Manage webhooks |
admin | Full account administration |
Rate limits
Each account can make 120 requests per 60 seconds. Over the limit, requests get 429 with a Retry-After header. Responses carry X-Rate-Limit-Limit, X-Rate-Limit-Remaining and X-Rate-Limit-Window.
Pagination
List endpoints return data, has_more and next_cursor. Pass next_cursor as cursor to get the next page.
Times
Timestamps are milliseconds since the Unix epoch.
Errors
Errors return a JSON body: {"error": {"code": "...", "message": "..."}}.
Endpoints
GET /v1/leads
Leads, most recently updated first.
Scope: leads:read
updated_since | Only leads updated at or after this time. |
include | Related resources to include. Supported: contact. |
limit, cursor | Page size (max 100) and the next_cursor from the previous page. |
GET /v1/leads/:id
Get one lead. Accepts include.
Scope: leads:read
GET /v1/contacts/:id
Get one contact.
Scope: leads:read
GET /v1/lead_statuses
The statuses a lead can have.
Scope: leads:read
POST /v1/leads/:id/notes
Add a note to a lead.
Scope: notes:write
Body: JSON
body | Note text (required). |
GET /v1/webhooks
List webhook subscriptions.
Scope: webhooks:manage
POST /v1/webhooks
Subscribe a URL to events. Returns the signing secret once.
Scope: webhooks:manage
Body: JSON
url | HTTPS endpoint (required). |
events | Event types, e.g. ["lead.created", "lead.updated"], or ["*"]. |
DELETE /v1/webhooks/:id
Delete a webhook subscription.
Scope: webhooks:manage
Webhooks
Webhooks are signed following the Standard Webhooks specification (webhook-id, webhook-timestamp, webhook-signature). Deliveries are retried on failure, and may occasionally arrive more than once.