# QlickCRM exact source URL question, UNSENT revision 4

Status: prepared, UNSENT. No recipient/channel or provider-send approval is inferred. Supersedes the earlier draft because the official CF7 writer has now been tested.

Subject: Supported exact source-URL storage through integration API

We need to store this exact source string in the existing custom text field `forrasoldal-url-je-49`:

```text
https://example.invalid/landing/?utm_source=qa&utm_campaign=raw-url
```

On synthetic controls, the public v2 object writer and the official CF7 module and modulepartner routes accept the normal JSON value, but raw-detail custom-field values, documented API readers and the opened request contain literal `&amp;`. A standard JSON Unicode-escaped ampersand variant also produces `&amp;` in the readers. We did not inspect your database directly.

The same tenant's normal native edit has stored the exact `&` value on an existing synthetic request. Native authenticated browser access works. We are distinguishing its Bearer session from the public API's AuthToken key.

Please provide the supported integration contract that preserves the exact string: endpoint, payload/field type, create and existing-record behavior, omitted-field behavior, and any required encoding. If it uses native Bearer authentication, please identify the supported issuance, expiry and renewal lifecycle suitable for a repeatable integration. A whole-form save or manual edit for each request would not meet the requirement.

We also observed null date/boolean storage being rendered as 1970-01-01/false by the separate formatted custom-fields endpoint. We have kept the raw nulls intact. Please confirm that formatter behavior separately from actual stored values.

The [sanitized reproduction](r4-vendor-reproduction.md) includes no personal data or credentials. The real original diagnostic receipts are available for internal review. No screenshot or private payload is attached for external transmission.
