Zoho CRM call tracking integration

Zoho Flow's webhook trigger receives our payload and writes into Zoho CRM: find-or-create the lead by phone, then log a call activity with the campaign name and duration.

Integrations / Zoho CRM

What you get

Every qualified call (passing your duration and screening rules) is delivered to Zoho CRM within about a minute: caller number, duration, timestamps, the campaign that generated the call, ad click IDs when present, and a recording link.

Step A — callstracking.com side

  1. Create an account and set up your campaign (2 minutes).
  2. Go to Dashboard → Integrations → Webhook / CRM.
  3. Paste the webhook URL from Zoho CRM (Step B) and choose a signing secret.
  4. Save. Qualified calls now POST to that URL automatically.

Step B — Zoho CRM side

  1. In Zoho Flow, create a flow with the "Webhook" trigger. Copy the webhook URL.
  2. Paste it into the callstracking.com webhook integration (Step A above) and save.
  3. Send a qualified test call so Flow captures the payload.
  4. Add a Zoho CRM "Fetch Lead" step matching phone = fromE164, with a Create Lead branch when none exists.
  5. Add a Zoho CRM "Create Call" step: subject = campaignName, duration = durationSec, call start = startedAt.
  6. Enable the flow.

The payload

Sent as JSON with content-type application/json. The recordingUrl opens in a signed-in callstracking.com session.

{
  "type": "qualified_call",
  "callId": "clx1abc...",
  "source": "DNI",
  "startedAt": "2026-08-14T17:21:09.000Z",
  "qualifiedAt": "2026-08-14T17:23:41.000Z",
  "durationSec": 152,
  "fromE164": "+15551234567",
  "toE164": "+12138321924",
  "campaignId": "cmsam...",
  "campaignName": "Google Ads — Plumbing",
  "channel": "GOOGLE_ADS",
  "recordingUrl": "https://callstracking.com/api/recordings/clx1abc...",
  "clickIds": { "gclid": "..." },
  "utm": { "utm_source": "google", "utm_campaign": "plumbing" }
}

Verifying the signature

Every delivery is signed with your secret: header x-ct-signature: sha256=<hmac> over the raw body, plus x-ct-event: call.qualified. Platforms like Zapier and GoHighLevel can skip verification (the URL itself is secret); verify when posting to your own server:

// Node.js — verify the x-ct-signature header
import { createHmac } from "node:crypto";

const expected = "sha256=" +
  createHmac("sha256", process.env.CT_WEBHOOK_SECRET)
    .update(rawRequestBody)   // the exact raw body string
    .digest("hex");

const valid = expected === req.headers["x-ct-signature"];

Troubleshooting