For AI agents: markdown of this page — /docs-content-en/entities/leads/list.md documentation index — /llms.txt
List leads
GET /v1/leads
Returns a list of leads with support for filtering, sorting and auto-pagination.
Parameters
| Parameter | Type | Default | Description |
|---|---|---|---|
limit |
number | 50 |
Number of records (up to 5000). When limit > 50, auto-pagination is applied |
offset |
number | 0 |
Skip N records. When offset > 0, limit <= 500 is recommended. For a full-collection walk a cursor is cheaper — order[id]=asc plus filter[>id] from meta.nextAfterId |
select |
string | — | Field selection: ?select=id,title,stageId,amount. Unknown fields are ignored |
sort |
string | — | Sorting via the short syntax: ?sort=-createdTime, the minus means descending |
order |
object | — | Sorting: ?order[createdTime]=desc. Sort field names come from GET /v1/leads/fields |
filter |
object | — | Filter by fields from GET /v1/leads/fields.Filtering syntax. Example: ?filter[stageId]=NEW |
withTotal |
string | — | Whether you need the count: true or false. false — do not request a count. This is the only way to guarantee that meta.total is absent from the response. Without the parameter: the API key setting applies, then the platform default — and in that case a short page still carries the exact count even without an explicit request. Paging and counts |
Examples
curl — personal key
curl "https://vibecode.bitrix24.com/v1/leads?limit=10&filter[stageId]=NEW&select=id,title,stageId,amount" \
-H "X-Api-Key: YOUR_API_KEY"
curl — OAuth application
curl "https://vibecode.bitrix24.com/v1/leads?limit=10&filter[stageId]=NEW&select=id,title,stageId,amount" \
-H "X-Api-Key: YOUR_APP_KEY" \
-H "Authorization: Bearer USER_SESSION_TOKEN"
JavaScript — personal key
const res = await fetch('https://vibecode.bitrix24.com/v1/leads?limit=10&filter[stageId]=NEW&select=id,title,stageId,amount', {
headers: {
'X-Api-Key': 'YOUR_API_KEY',
},
})
const { success, data, meta } = await res.json()
console.log(`Found ${meta.total} leads`)
JavaScript — OAuth application
const res = await fetch('https://vibecode.bitrix24.com/v1/leads?limit=10&filter[stageId]=NEW&select=id,title,stageId,amount', {
headers: {
'X-Api-Key': 'YOUR_APP_KEY',
'Authorization': 'Bearer USER_SESSION_TOKEN',
},
})
const { success, data, meta } = await res.json()
Response fields
| Field | Type | Description |
|---|---|---|
data |
array | Array of leads (fields — see Fields) |
meta.total |
number | Total number of records. An optional field: if no count was requested, it is absent from the response |
meta.hasMore |
boolean | Whether there are more records |
meta.nextAfterId |
string | The identifier of the last returned record. Returned when the sort is strictly id ascending, while hasMore is true. Pass it back as filter[>id] — a cheap replacement for a growing offset |
The card URL of any lead from the data array is built from its id:
https://<portal>.bitrix24.com/crm/lead/details/<id>/
<portal> — the Bitrix24 portal domain. Access is restricted by the employee's permissions in Bitrix24.
Response example
{
"success": true,
"data": [
{
"id": 42,
"title": "Website request #42",
"name": "John",
"lastName": "Smith",
"stageId": "NEW",
"opportunity": 1500,
"currencyId": "USD",
"assignedById": 1,
"sourceId": "WEB",
"createdTime": "2026-04-10T14:30:00+00:00"
}
],
"meta": {
"total": 834,
"hasMore": true
}
}
Error response example
403 — no scope:
{
"success": false,
"error": {
"code": "SCOPE_DENIED",
"message": "This endpoint requires 'crm' scope"
}
}
Errors
| HTTP | Code | Description |
|---|---|---|
| 403 | SCOPE_DENIED |
The API key does not have the crm scope |
| 401 | TOKEN_MISSING |
The API key has no configured tokens |
| 429 | RATE_LIMITED |
Rate limit exceeded: 300 requests per minute per portal, all API keys of the portal share one limit. The exact value arrives in the x-ratelimit-limit header (the cap is divided across replicas). Retry after the delay in the Retry-After header |
Full list of common API errors — Errors.
Known specifics
The phone filter is not suitable for every search. A value without an operator is compared against the whole stored string: a lead whose number is stored as +1 (202) 555-0123 matches that exact string, but not 12025550123, because the plus sign, spaces, parentheses, and hyphens are part of the value. The filter also checks only the first number stored on a record: if both a work number and a mobile number are stored, searching by the mobile one returns an empty list. To find a lead by phone number in any format and by any of its numbers, use Duplicate search.
Filtering and sorting by stage semantics. The stageSemanticId field takes three values — P for stages in progress, S for successful ones, and F for failed ones. It works in both filter and order. A value outside those three is not rejected: no record matches it, and data comes back empty. Grouping by this field is not supported in Aggregate leads.
Auto-pagination: when limit > 50, Vibecode automatically requests multiple pages.
When to use search: for compound conditions, use POST /v1/leads/search — parameters are passed in the request body. See Search leads.