Interface A REST API covering forms, submissions, fields, webhooks, folders and partial submissions, with additional product-specific surfaces for Formstack Documents, Formstack Sign and Formstack Workflows.
Authentication OAuth 2.0. You register an API application, which issues a client ID, client secret and access token. Treat all three as production secrets with a rotation plan.
Rate limiting Daily rate limiting applied per access token, with the limit varying by plan type. Exceeding the quota returns HTTP 429, and quotas reset daily.
Webhook delivery Formstack posts submission data to a URL you specify at the moment a submission occurs — a push model, so latency is low and your endpoint must be available.
Webhook security Two options. A Shared Secret is a key sent with each request so you can confirm it came from Formstack. An HMAC Key signs the payload so you can verify both its authenticity and that it has not been altered.
Partial submissions Exposed as a resource, which matters when Save & Resume is in use and you need to reason about incomplete data — including whether your integration should see it at all.
Budget the quota before you design. A daily per-token rate limit is a
capacity constraint, not an edge case. A polling integration that checks every minute
consumes quota whether or not anything has changed, and a webhook-driven design consumes
almost none — which is frequently the deciding argument between the two patterns regardless
of what the requirements document says about latency.