Webhooks and API
Webhooks and a REST API
Send every response to your own systems as it arrives, or read and manage forms from a script.
Webhooks
Add an endpoint to a workspace and Formwork posts a JSON payload each time a response is submitted. Every delivery carries an event name, a delivery id, a timestamp and a signature computed with your endpoint's secret, so you can check the request really came from your workspace.
POST /your/endpoint
X-Formwork-Event: response.submitted
X-Formwork-Timestamp: 1790000000
X-Formwork-Signature: sha256=…
If your server answers with an error, Formwork retries with growing delays. The delivery log shows every attempt with its status, and you can replay a delivery by hand. Endpoints that point at private or internal network addresses are refused.
REST API
The API returns JSON over HTTPS. Create a key under Account, API keys. A key belongs to one workspace and is either read-only or read and write; it can never do more than you can do yourself.
curl https://your-host/api/v1/forms \
-H "Authorization: Bearer fwk_…"
There are no cookies or CSRF tokens on the API. Each key is limited to 120 requests per minute.
Plans
Webhooks and API access are part of paid plans; the limits per plan are on the pricing page.