formbasedocs
Go to appApp

Sharing & Publishing

Authentication gate

Control who can access your form. Require sign-in to tie responses to verified identities, or add a password to limit access to people who have the code.


Public links only

Both gates apply to the public share link. A request is addressed to one recipient and opens from a signed link, so it skips them.

Require authentication

In Form settings → Access, toggle Require authentication. Respondents must sign in before they can view or fill out the form.

What’s enforced

  • The respondent must sign in — the only two methods are Google and an email magic link (they enter their email and receive a sign-in link)
  • Their identity is recorded with the submission
  • Drafts are tied to the account, not a browser cookie — so they can resume from any device
  • Without authentication, duplicate-submission blocking is per-browser only. With authentication, it’s per-account across all devices

Internal forms

With authentication enabled, anyone who opens the form must sign in first. Their email address is recorded with each submission, so you can verify respondents belong to your company domain — no single sign-on setup needed. Share the link with your team and you’re done.

When to use it

  • Internal forms — share the link internally and require sign-in so every response has a verified company email attached
  • Member-only flows — only existing customers should respond
  • Anti-fraud — financial or high-value forms where anonymous submissions are too risky

When NOT to use it

Public-facing forms like newsletter signups, contact forms, and lead-gen pages tend to lose conversions when sign-in is required. For those, CAPTCHA is usually a better fit.

One response per user

When authentication is enabled and Allow another response (in Form settings → Submissions) is off — the default — each signed-in user can only submit once. Further attempts from the same account are blocked on every device. To cap the total number of respondents as well, add a response limit to the share link.

Looking to verify an email answer instead of who opens the form? The gate verifies the person signing in. Respondent email verification confirms the address typed into an Email question with a one-time code — no sign-in needed.

Password protect

Turn on Password protect in Form settings → Access and type a password. The form stays publicly reachable by URL, but respondents see “Password required” until they enter it.

How it works

  • The password is checked on the server against a salted hash. The form’s questions are never sent to the browser before it matches
  • A wrong entry shows “Incorrect password” and nothing else is revealed
  • Share the password through whichever channel you trust: email, internal docs, a payment receipt
  • Anyone with the password can submit

Rotating the password

You can change the password at any time. Respondents who are already filling the form keep their session, because their access key was minted before the change. New visitors need the updated password.

Pair with response limits

For paid content, combine the password with a response limit on the share link so a single password isn’t shared and reused infinitely. You can also set the limit to 1 to make a link single-use.

Next steps