How to Authenticate with the FormRobin API

The FormRobin API accepts Bearer tokens. Create a Personal Access Token under Settings → API, or get a token from the login endpoint with your email and password.

Which authentication methods can I use?

Every API request needs a token in the Authorization: Bearer header. There are two ways to get one:

  • Personal Access Token - created in your account under Settings → API. Best for integrations and scripts: no password is sent.
  • Login endpoint - send your email and password to /api/jwt/login and receive a token in the response. Useful when a script has to obtain its own token.
Method Where you get it Best for
Personal Access Token Settings → API → Create New Token Integrations and scripts; no password is sent
Login endpoint POST your email and password to /api/jwt/login Scripts that obtain their own token
OAuth client Settings → API → Create New Client Another application requesting access through the OAuth sign-in flow

Both kinds of token work the same way, last one year, and appear in the Personal Access Tokens list on the API page, where you can delete them. The API page also manages OAuth clients:

FormRobin API Settings page showing Developer API, Personal Access Tokens, and OAuth Clients sections

The API is available on both plans, Free Plan and Individual Plan.

Method 1: Personal Access Tokens

How do I create a token?

  1. Open the account menu in the top right and click Settings, then API in the Settings sidebar.
  2. In Personal Access Tokens, click Create New Token.
  3. Enter a Token Name that tells you where the token is used (for example "Zapier Connection").
  4. Click Create Token.
  5. The token appears in a yellow banner at the top of the page ("Copy your token now. You won't be able to see it again!"). Click Copy and store it somewhere safe.

Important: the token is shown only once. If you lose it, delete it and create a new one.

How do I use a Personal Access Token?

Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN
curl https://formrobin.com/api/v1/forms \
  -H "Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN" \
  -H "Accept: application/json"

How do I manage my tokens?

The Personal Access Tokens table lists every token with its Name, Created date and a Delete button. Tokens that came from the login endpoint are listed too, named "FormRobin". Deleting a token asks you to confirm ("This cannot be undone."); anything using that token loses access immediately.

Method 2: The Login Endpoint

Login Endpoint

POST https://formrobin.com/api/jwt/login

Request Format

Content-Type: application/json

{
  "email": "your-email@example.com",
  "password": "your-password"
}

You can send username instead of email; its value is used as the email address.

Success Response

{
  "access": "eyJ0eXAiOiJKV1QiLCJhbGc...",
  "token_type": "bearer",
  "expires_in": 31536000
}
  • access - your token; send it as the Bearer token
  • token_type - always "bearer"
  • expires_in - the token lifetime in seconds (one year)

Each successful login creates a new token, which then appears in your Personal Access Tokens list. Reuse a token until it expires instead of logging in for every request.

Error Response

Wrong email or password returns HTTP 401:

{
  "error": "Unauthorized"
}

OAuth Clients

OAuth clients let another application request access to a FormRobin account through the OAuth sign-in flow, instead of asking for a token.

How do I create an OAuth client?

  1. Go to Settings → API.
  2. In OAuth Clients, click Create New Client.
  3. Enter a Client Name and a Redirect URL (where users are sent after authorizing, for example https://example.com/callback).
  4. Click Create Client.
  5. Copy the client secret from the yellow banner ("Copy your client secret now. You won't be able to see it again!").

Managing OAuth Clients

The OAuth Clients table shows each client's Name, Client ID and Redirect URL. Click Edit to change the name or redirect URL (the Client ID cannot be changed), or Delete to remove the client.

How do I use my token in requests?

Whichever way you got it, send the token in the Authorization header of every API request. The API answers in JSON; the Accept: application/json header is optional.

Complete Example Request

GET https://formrobin.com/api/v1/forms
Authorization: Bearer YOUR_TOKEN
Accept: application/json

How do I check that my token works?

To confirm a token works and see which account it belongs to:

GET https://formrobin.com/api/v1/me
Authorization: Bearer YOUR_TOKEN
{
  "data": {
    "id": 123,
    "name": "Your Name",
    "email": "your-email@example.com",
    "created_at": "2026-01-15T10:30:00.000000Z",
    "updated_at": "2026-01-15T10:30:00.000000Z"
  }
}

Rate Limiting

The API allows 60 requests per minute, counted per user (or per IP address for requests without a valid token). Over the limit you receive HTTP 429 Too Many Requests; wait for the next minute and retry, ideally with exponential backoff.

Code Examples

cURL Example

# Step 1: log in and get a token
curl -X POST https://formrobin.com/api/jwt/login \
  -H "Content-Type: application/json" \
  -d '{"email": "your-email@example.com", "password": "your-password"}'

# Step 2: use the token
curl https://formrobin.com/api/v1/forms \
  -H "Authorization: Bearer YOUR_TOKEN"

JavaScript (Fetch API) Example

// Server-side JavaScript (for example Node.js)
const login = await fetch('https://formrobin.com/api/jwt/login', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ email: 'your-email@example.com', password: 'your-password' })
});
const { access: token } = await login.json();

const res = await fetch('https://formrobin.com/api/v1/forms', {
  headers: { 'Authorization': `Bearer ${token}` }
});
const forms = await res.json();

Python (requests) Example

import requests

login = requests.post('https://formrobin.com/api/jwt/login',
                      json={'email': 'your-email@example.com', 'password': 'your-password'})
token = login.json()['access']

forms = requests.get('https://formrobin.com/api/v1/forms',
                     headers={'Authorization': f'Bearer {token}'}).json()

Token Expiration

Personal Access Tokens and login tokens both expire one year after they are created. After that, requests with the token return HTTP 401 Unauthorized. There is no refresh token: create a new Personal Access Token or log in again.

Recommended Strategy

// Pseudo-code
response = callApi(url, token)
if (response.status === 401) {
  token = getNewToken()   // new Personal Access Token or /api/jwt/login
  response = callApi(url, token)
}

How should I store my tokens?

  • Server-side only - keep tokens out of browser code and mobile apps, where anyone can read them
  • Environment variables - store tokens in environment variables or a secrets manager, not in code
  • Never commit tokens to version control
  • One token per integration - so you can delete one without breaking the others

Security Best Practices

  • Always call the API over HTTPS
  • Treat tokens like passwords
  • Delete tokens you no longer use under Settings → API
  • If a token may have leaked, delete it and create a new one

Limitations

  • No refresh tokens: get a new token when one expires
  • Account-level access: a token can do everything the API allows for your account
  • No scopes: you cannot limit a token to specific endpoints
  • Rate limit: 60 requests per minute

Troubleshooting

The login endpoint returns 401 Unauthorized

  • Check the email and password; log in on formrobin.com with the same details to confirm them.
  • Send JSON with Content-Type: application/json to https://formrobin.com/api/jwt/login.

API requests return 401 Unauthorized

  • Check the header format: Authorization: Bearer YOUR_TOKEN (with a space after "Bearer").
  • Use the access value from the login response, not the whole response.
  • Tokens expire after one year, and a deleted token stops working immediately. Create a new one under Settings → API.

429 Too Many Requests

  • You sent more than 60 requests in a minute. Wait for the next minute, cache responses and retry with backoff. Rate limits for every endpoint: FormRobin API: Getting Started.

I lost my Personal Access Token

  • Tokens are shown only once. Delete the old token and create a new one.

Still stuck? Email support@formrobin.com with the endpoint you called, the HTTP status and the time of the request (never send your token).

Frequently Asked Questions

How long do tokens last?

One year, for both Personal Access Tokens and tokens from the login endpoint. After that, create a new token.

Can I use the API without sending my password?

Yes. Create a Personal Access Token under Settings → API and send it as the Bearer token.

How do I revoke a token?

Go to Settings → API and click Delete next to the token. Tokens created by the login endpoint are listed there as "FormRobin".

What is the API rate limit?

60 requests per minute per user. See FormRobin API: Getting Started for the endpoints and Creating Forms via API for examples.