Skip to main content
GET
Downloads a lead list’s entries as a CSV or Excel file.
Requires a Management API key with MANAGEMENT_API (or MANAGEMENT_API_SANDBOX) quota, and the LEAD_GENERATION_ENTRY_CAN_VIEW permission, sent as the raw Authorization header value — see the Management API overview.
string
required
The lead list’s lead_id.
string
default:"csv"
csv, xls, or xlsx.
string
Only entries created on or after this date (YYYY-MM-DD).
string
Only entries created on or before this date (YYYY-MM-DD).
string
Comma-separated entry UUIDs to scope the export to a specific selection — mirrors the dashboard’s “download selected” action. Invalid UUIDs are silently ignored rather than rejected.
Same substring search as List lead entries — mirrors “download filtered results”.
The response is a file download (Content-Type: text/csv, or the XLSX MIME type for xls/xlsx), not JSON, with Content-Disposition: attachment; filename=<LeadListName>-<timestamp>.<ext>.
The exported file always includes a tracking_id column, regardless of tracking permissions elsewhere on the account. If a submitting QR Code has since been deleted, its column value renders as <qrid> (Deleted) rather than failing the export. With zero matching entries, the file still contains a header row (derived from the lead form’s own question labels) rather than being empty.
On a free-plan account (plan_type 1), the export is capped at 25 rows — if more entries matched, two trailing rows are appended noting the cap and prompting an upgrade.
400 with a plain-text body (not the standard DRF error shape) if file_format isn’t one of csv, xls, xlsx:
400

Authorizations

Authorization
string
header
required

Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: 401f7ac837da42b97f613d789819ff93537bee6a. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.

Response

200

CSV or XLSX file download.