Before you start
- A HighLevel sub-account for your business, and permission to open its Settings.
- Agency-admin access for one step (importing the snapshot). If your HighLevel account is managed by an agency, they can do that step in two clicks; the rest is all yours.
- An email address you can receive codes at. There are no passwords to manage.
Sign in to the SpamShield portal
Go to the portal and enter your email address. We send you a six-digit code; enter it and you are in. The same email is your account for every location you manage, so use one you check regularly.
Find your Location ID
In your HighLevel sub-account, open
Settings > Business Profile. The
Location ID is shown near the top; use the copy
button next to it. It looks like a short scramble of letters and numbers, for example
ve9EPM428h8vShlRW1KT.
You can also read it out of your browser's address bar while inside the sub-account:
it is the segment after /location/ in the URL.
Create a Private Integration token
This token is how SpamShield talks to your account: it proves the location is yours, lets us wire up your webhook credentials, and lets us tag confirmed spammers so your workflows can block them.
- In the sub-account, open Settings > Private Integrations.
- Click Create new integration and name it
SpamShield. - When asked for scopes (permissions), select exactly these five:
- View Contacts
- Edit Contacts
- View Custom Values
- Edit Custom Values
- View Workflows
All five matter. The one people miss is View Custom Values; without it SpamShield cannot finish your setup even though everything else appears to work. If you have already created the token, you can add missing scopes any time by editing the integration; the token itself does not change.
Click Create and copy the token when it is shown. Treat it like a password: it grants access to your contacts.
Claim your location in the portal
Back in the SpamShield portal, click Claim a HighLevel location. Enter your business name, paste the Location ID from step 2 and the token from step 3, and submit.
SpamShield validates the token against your account on the spot, then automatically stores two values inside your HighLevel sub-account (as custom values named "SpamShield Secret" and "SpamShield Webhook URL"). The workflows you install in the next step read those values, which is why they work without any editing.
Import the SpamShield snapshot
The snapshot installs three small, ready-made workflows in your sub-account: one that reports a caller to the network when you block them, and two that block or unblock callers when the network reaches a verdict.
This step needs agency-admin access in HighLevel, because snapshots are imported at the agency level. If your account is managed by an agency, forward them this section; it is two clicks for them.
- While logged into HighLevel, open the SpamShield snapshot link and confirm the import. It lands in the agency's snapshot library.
- Go to Agency view > Sub-Accounts, find the sub-account, and open its management page.
- Choose Actions > Load Snapshot, pick the SpamShield snapshot, and proceed. If an asset list is shown, keep Workflows, Custom Values, and Tags all selected.
Loading is additive: it only adds the SpamShield workflows, tags, and custom values, and does not touch anything else in the account.
Run the setup check
In the portal, open your location and click Check setup. It verifies everything live against your HighLevel account. You want every row green:
- API token works: SpamShield can reach the account. If not, the token was deleted or mistyped; re-claim the location with a fresh token.
- Webhook secret is synced: your credentials are stored in the account. If not, add the two custom values scopes to the integration (step 3) and run the check again; it fixes itself.
- Three workflows installed and published: the snapshot landed. "Not found" means the snapshot has not been loaded into this sub-account yet (step 5). "Not published" means open that workflow in HighLevel and switch it to Publish.
- Reports are flowing: stays amber until your first report arrives, which is the next step.
Test it with one tap
Open any contact in the sub-account (a test contact is fine), and turn on Do Not Disturb for Inbound calls and SMS. That is the exact gesture you will use on real spam callers, from the web or from the one-tap DND button on the mobile app's incoming call screen.
Within a few seconds, run Check setup again: "Reports are flowing" should now be green, and the number appears in your reports. That is the whole loop working: your block just became a vote the entire network can see.
Day to day, from here on
Block spam callers like you always have. Tap DND on the contact. SpamShield reports it for you. When three different member businesses report the same number within 72 hours, it is blocked in every member account automatically, usually within seconds.
Your customers are safe. Numbers that have appointments or opportunities in your account are never blocked there, no matter what the rest of the network reports. Every location gets one vote per number per day, and every block expires after 90 days.
If a real caller is ever blocked, open your location in the portal, find the number under Blocked Numbers, and click Not spam. They are unblocked for your business immediately, and if a second business agrees, the block lifts for the whole network.
Ready to start?
Sign in with your email and claim your first location. The whole thing takes about ten minutes.
Open the portal