Developers
API overview
A single JSON-RPC endpoint authenticated with API tokens. Call any method by name.
No code needed?
The Guides set formbase up in Zapier click by click, without calling the API yourself.
Endpoint
All requests go to a single URL via POST. Pass the method name and parameters as JSON.
Authentication
Pass your API token as a bearer token in the Authorization header. Tokens are scoped to a workspace — create them from
OAuth and API Keys in the sidebar.
curl -X POST https://api.formbase.so/api/v1 \
-H "Authorization: Bearer fb_..." \
-H "Content-Type: application/json" \
-d '{"method": "forms.list", "params": {}}'const res = await fetch('https://api.formbase.so/api/v1', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.FORMBASE_TOKEN}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ method: 'forms.list', params: {} }),
})
const data = await res.json()import os, requests
res = requests.post(
"https://api.formbase.so/api/v1",
headers={"Authorization": f"Bearer {os.environ['FORMBASE_TOKEN']}"},
json={"method": "forms.list", "params": {}},
)
data = res.json()Keep tokens server-side
Never embed tokens in browser code. Use a backend proxy for client-side calls.
Request format
Every request is a JSON object with two fields:
{
"method": "forms.list",
"params": {
"workspaceId": "abc123..."
}
}Response format
Every response is a JSON object with an ok field. On success:
{
"ok": true,
"data": { ... }
}Errors
On failure, ok is false and an error object contains a machine-readable code and human-readable
message:
{
"ok": false,
"error": {
"code": "VALIDATION_ERROR",
"message": "Field 'name' is required."
}
}Common error codes:
VALIDATION_ERROR(400) — invalid or missing parametersUNAUTHORIZED(401) — missing or invalid API tokenUPGRADE_REQUIRED(402) — the feature requires a higher subscription tierFORBIDDEN(403) — token lacks access to the resourceCONFLICT(409) — resource state conflict, such as a duplicate nameNOT_FOUND(404) — resource does not existMETHOD_NOT_FOUND(404) — unknown method nameRATE_LIMITED(429) — too many requestsINTERNAL_ERROR(500) — unexpected server error
Rate limits
API requests are rate-limited to 120 requests per minute per token. Exceeding the limit returns
429 Too Many Requests.