Integrate Your Website with Salesforce: REST API, OAuth 2.0, Lead Sync
Up to 30% of leads are lost because form submissions never reach the CRM. Managers waste hours on manual data entry. Integrating your website with Salesforce via REST API solves this. REST API supports up to 5,000 requests per day (Salesforce REST API Developer Guide) and is ten times more flexible than Web-to-Lead. Platform Events enables real-time bidirectional sync, albeit with more complex setup. Our engineers are Salesforce certified (PD I, App Builder) with over 5 years of experience and 50+ projects in retail and services.
Each lead automatically created in Salesforce saves significant manual entry costs. For 500 leads per month, savings exceed 80,000 rubles, and processing time drops from 10 minutes to 30 seconds – a 20x improvement. Integration cost starts from 300,000 rubles, with most clients seeing ROI within 3 months.
Integration Methods Compared
| Method |
Complexity |
Flexibility |
Performance |
Best For |
| REST API (OAuth 2.0) |
Medium |
High |
5,000 req/day* |
Landing pages, customizable e-commerce |
| Web-to-Lead |
Low |
Low |
No limit |
Simple contact forms |
| Platform Events |
High |
High |
License-limited |
Real-time two-way sync |
*Limit can be increased by request to Salesforce.
Setting Up Connected App for OAuth 2.0
- In Salesforce: Setup → App Manager → New Connected App
- Enable OAuth settings, add callback URL
- Select scopes:
api, refresh_token
- Retrieve Consumer Key and Consumer Secret
Creating Leads from Website Forms
use Omniphx\Forrest\Providers\LaravelServiceProvider;
// composer require omniphx/forrest
// config/forrest.php
'credentials' => [
'consumer_key' => env('SF_CONSUMER_KEY'),
'consumer_secret' => env('SF_CONSUMER_SECRET'),
'username' => env('SF_USERNAME'),
'password' => env('SF_PASSWORD'),
]
// In controller
Forrest::authenticate();
$lead = Forrest::sobjects('Lead', 'post', [
'body' => [
'FirstName' => $request->first_name,
'LastName' => $request->last_name,
'Email' => $request->email,
'Phone' => $request->phone,
'Company' => $request->company ?? 'Individual',
'LeadSource' => 'Website',
'Description' => "UTM: {$request->utm_source}/{$request->utm_campaign}"
]
]);
Uploading Orders as Opportunities
Confirmed orders on your site become Opportunities in Salesforce, linked to the Contact/Account. This lets managers see purchase history directly in the CRM.
Forrest::sobjects('Opportunity', 'post', [
'body' => [
'Name' => "Order #{$order->id}",
'AccountId' => $salesforceAccountId,
'Amount' => $order->total / 100,
'CloseDate' => $order->created_at->format('Y-m-d'),
'StageName' => 'Closed Won',
'Order_ID__c' => $order->id // custom field
]
]);
Why Contact Deduplication Is Critical
Salesforce often contains duplicates. You need logic: before creating a new Lead or Contact, check for existing records with the same email using SOQL queries.
$existing = Forrest::query(
"SELECT Id, Email FROM Lead WHERE Email = '{$email}' LIMIT 1"
);
if ($existing['totalSize'] > 0) {
// Update existing lead
Forrest::sobjects("Lead/{$existing['records'][0]['Id']}", 'patch', [...]);
} else {
// Create new
}
Platform Events and Bidirectional Sync
Platform Events are a mechanism for real-time event delivery. They enable two-way sync: changes in Salesforce automatically send events that your site can receive via CometD or gRPC. Platform Events are 3x faster than Outbound Messages but require event subscription setup on the site side.
For bidirectional synchronization, you can use Outbound Messages or Platform Events: Salesforce sends a webhook to your site when an object changes. Alternatively, poll every 15 minutes: SELECT Id, ... FROM Lead WHERE LastModifiedDate > {timestamp} via SOQL.
Field Mapping and Common Errors
Custom fields in Salesforce are created via Setup → Object Manager. The API name of a custom field ends with __c (e.g., UTM_Source__c). Store field mappings in a config file to avoid code changes when structure changes.
Example field mapping for a typical e‑commerce site
{
"site_field": "email",
"sf_field": "Email",
"type": "string"
}
| Error |
Cause |
Solution |
| Duplicate leads |
No email check before create |
SOQL query before insert |
| 401 Unauthorized |
Expired or invalid refresh token |
Refresh token in background, store in DB |
| Timeout on high request count |
Exceeded API limit |
Use queue and throttling |
Error Handling and Queues
Salesforce API has limits (24-hour call limits). All Salesforce requests should go through a queue (e.g., Laravel Queue/Horizon) to avoid blocking the user response and to retry on temporary failures. For 500 leads per month, manual entry savings exceed 80,000 rubles. We cut lead processing time from 10 minutes to 30 seconds – a 20x reduction. Integration errors drop by 90% with proper queue setup.
What’s Included in the Integration
- Audit of current forms and Salesforce objects
- Connected App creation and OAuth token acquisition
- Field mapping: site → Salesforce (custom fields with __c suffix)
- Task queue (Laravel Horizon) for API requests
- Bidirectional sync testing
- API documentation and training (2 hours)
- Credentials and access provisioning
- 3 months of support
- Manager training on new data usage
Timeline: 4–6 weeks for full bidirectional integration with custom objects and order sync.
Start with a free CRM audit – it takes one day. Get a consultation from our Salesforce integration engineer – we'll evaluate your CRM in one day. Contact us to discuss your project.
Website CRM Integration: Bitrix24, amoCRM, Salesforce, HubSpot
A sales manager manually copies leads from email into the CRM. Half of them never make it. Follow‑up calls are missed. This isn’t a people problem — it’s an architectural gap between the website and the company’s core system. We close that gap with a direct site‑to‑CRM connection: leads land in the pipeline within 30 seconds after form submission, duplication is blocked, and status changes flow both ways automatically. Request a free integration audit to identify the bottlenecks in your current flow.
Integration isn’t just a POST to an API endpoint. It’s a battle against timeouts, duplicate records, data loss, and desynchronised states. We handle three core problems at once: asynchronous delivery (so the user never waits for the CRM), deduplication by email (one address – one lead), and two‑way feedback (a status change in the CRM instantly appears on the site). Below is how we tackle each.
Bitrix24: REST API and Event Handlers
Bitrix24 dominates the Russian B2B space. Its REST API works via OAuth 2.0 or an incoming webhook (webhook is simpler but less secure for production). Main entities are lead, deal, contact, and company.
Creating a lead requires POST /rest/crm.lead.add with the correct field set. Attaching it to a funnel means passing SOURCE_ID. Adding a timeline comment uses crm.timeline.comment.add. Real‑time tracking is done through Event Handlers: register a hook with event.bind; Bitrix24 pushes a POST to your endpoint when any deal status changes.
The real complexity lies in custom fields. Every Bitrix24 installation has its own set, and their IDs must be fetched via crm.lead.fields. Mapping those fields between the site and the CRM can be done manually or automatically — we use an automatic detection mechanism that works even in non‑standard configurations (proven on 20+ projects). We guarantee correct matching, so no lead arrives without the right pipeline stage or source tag.
amoCRM: Clean REST with Predictable Endpoints
amoCRM (now Kommo for international markets) offers a cleaner API. OAuth 2.0 with refresh token, JSON API, and well‑structured endpoints. Pipelines are pipelines, deals are leads, contacts are contacts.
A common mistake: when creating a deal you must supply pipeline_id and status_id explicitly. Without them the deal lands in the default pipeline – often the wrong one. Tags for source classification go into _embedded.tags. Incoming webhooks are configured in the admin panel; they support add, update, delete, status, and note events. We always verify the webhook signature using the API key and make sure the endpoint responds with 200 OK in under 5 seconds – otherwise the CRM marks delivery as failed.
Salesforce and HubSpot: Enterprise‑Grade Integration
Salesforce is the enterprise standard. It offers REST API, SOQL for complex queries, and Apex for server‑side logic. Integration can be direct via Salesforce REST API or through middleware like Zapier or MuleSoft. For PHP projects we use phpforce/soap-client or the Force.com‑Toolkit. The main challenge is mapping hundreds of custom objects and fields; we solve it with Describe Global to collect metadata automatically – cutting setup time by three‑quarters compared to reading documentation manually (Salesforce Developer Guide).
HubSpot is popular among SaaS companies and international B2B. Its API v3 provides a REST interface with solid SDKs for PHP and Node.js (@hubspot/api-client). Contacts, Companies, Deals are standard objects. The Forms API lets you send data from any custom form directly to HubSpot without using the native widget. One pitfall: the access_token must include the right scopes; a misconfigured token returns 403 Forbidden with a vague message. We include error_logging that captures the error code – debugging takes minutes instead of hours.
Which CRM fits your business: Bitrix24, amoCRM, or HubSpot?
| Criteria |
Bitrix24 |
amoCRM |
HubSpot |
| API complexity |
Medium (REST + webhooks, custom fields) |
Low (clean JSON API) |
Medium (REST + SDK, OAuth 2.0) |
| Typical synchronous latency |
200‑600 ms |
100‑300 ms |
150‑400 ms |
| Built‑in deduplication by email |
crm.duplicate.findByComm |
Contact search |
contacts/search |
| Webhook events |
Event Handlers (push) |
Admin panel configuration |
Webhook + Automations |
| Best suited for |
Russian B2B, government, custom fields |
Small‑ to medium‑sized business |
International B2B, SaaS |
Why is asynchronous sending important?
Calling a CRM API synchronously from the form handler is a mistake. The API may respond in 2 seconds – or time out. The user sits waiting. The correct pattern: form submission → save to database → queue a job → return 200 to the user immediately. A background worker then pushes the lead to the CRM. If the CRM is down, the worker retries with exponential backoff. We use Redis + Bull on Node.js or Laravel Queue on PHP – this guarantees delivery even during temporary outages.
Deduplication – how we stop duplicate leads
The same contact may fill the form twice. Without deduplication the CRM ends up with two identical leads. Before creating a new lead we search by email: for Bitrix24 we call crm.duplicate.findByComm, for HubSpot we use contacts/search. If a match is found we attach a task or comment to the existing lead instead of creating a new one. In our projects this cuts duplicate entries by 95%.
Two‑way synchronization – what happens when a manager changes a deal status
If a manager updates a deal status in the CRM, the website needs to reflect that change – especially if the client has a personal account. We configure webhooks from the CRM to an endpoint on the site, then update the local database and notify the client. Critical details: verify the webhook signature and respond with 200 OK within 5 seconds, otherwise the CRM assumes delivery failed. We guarantee that the delay between a status change in the CRM and its appearance on the site never exceeds 3 seconds.
How do we conduct integration in 5 steps?
- Audit of data flows – analyse current lead transfer, CRM field structure, and performance bottlenecks. Deliverable: “as‑is” and “to‑be” data flow diagrams.
- Architecture design – choose the queue mechanism (Redis Bull or Laravel Queue), define the deduplication method, and prepare a field mapping specification.
- Implementation on staging – write code on Laravel or Node.js, configure webhooks, and test with real data: lead creation, status updates, and error handling.
- Load testing – simulate peak traffic (e.g. 500 requests per minute) and adjust retry policies and timeout settings.
- Deployment and documentation – push to production, train the team on monitoring and retry cleanup, and deliver full endpoint documentation.
What is included in the work
- Audit report with current data flow diagrams and typical error patterns.
- Architecture design document specifying queue, deduplication, and mapping.
- Production‑ready integration code on Laravel or Node.js.
- Webhook configuration and signature verification.
- Team training on support tasks and retry cleanup.
- 30‑day warranty support for bug fixes and mapping adjustments.
Real‑world case: real‑estate agency with 400 leads per month
Click to expand
A real‑estate agency processed every incoming lead manually – 400 leads per month. Each lead took 3 minutes to enter, and 15% were lost because emails were missed. We integrated their site with amoCRM using asynchronous queue delivery and automatic deduplication. Leads now appear in the pipeline within 5 seconds, and leftover tasks are automatically assigned to the next available agent. Result: 30% increase in conversion and $12,000 saved annually in administrative overhead.
Timelines
| Scenario |
Duration |
| One CRM, lead transfer from forms |
1‑2 weeks |
| Two‑way synchronization + statuses |
3‑5 weeks |
| Multiple CRM + custom field mapping |
4‑8 weeks |
The exact cost is calculated after an audit of your current processes and CRM data structure. Contact us for a project estimate – we will send a commercial proposal within one business day. With 5+ years of experience and more than 20 completed integrations, you get a solution that works from day one. Get an engineer consultation to see how your sales funnel can run without manual lead transfer.
Additional sources: Customer relationship management (Wikipedia) · REST API (Wikipedia)