Hubflo form API

The form API from Hubflo — 17 operation(s) for form.

OpenAPI Specification

hubflo-form-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Hubflo chat_room form API
  version: v2
  description: "The Hubflo API allows you to write and read data from the Hubflo application.\nIt conforms to [REST](https://en.wikipedia.org/wiki/REST).\nIt has predictable resource-oriented URLS, accepts JSON request bodies, returns JSON and uses standard HTTP status codes\nand verbs.\n\n# Authentication\n\nThe Hubflo API requires authentication.\nIt's a bearer authentication, also called token authentication.\n\nTo start your integration journey with the Hubflo API, you must send your **authentication token** in the\n`Authorization` header when making requests to the API.\n\n```\nAuthorization: Bearer <token>\n```\n\n# Getting started\n\nNavigate to [https://app.hubflo.com/organizations/](https://app.hubflo.com/organizations/).\nIn the **Integrations** settings panel, click on the **Generate key** button if you don't already have an API key.\n\nThe generated API key is the required authentication token you must send in the `Authorization` header.\nLet's copy it.\n\nYou can use the `/pings` endpoint to check that you can successfully make an authenticated request.\nDo it directly from this documentation, using the **Authorize** button to paste your authentication token, then push\nthe **Try it out** button.\n\nAlternatively, you can run the following cURL command in a terminal:\n\n```\ncurl -X 'POST' \\\n  'https://app.hubflo.com/api/v2/pings' \\\n  -H 'accept: application/json' \\\n  -H 'Authorization: Bearer <token>' \\\n  -d ''\n```\n\nIf you're successfully authenticated, you receive:\n\n```json\n{\n  \"pong\": \"ok\"\n}\n```\n\nOtherwise you get a `401 - Unauthorized` error. For example:\n\n```json\n{\n  \"status\": 401,\n  \"title\": \"Unauthorized\",\n  \"message\": \"API token not found\"\n}\n```\n\n# Versioning\n\nThe API is versioned. The current version is 2.0 (referenced as v2 in the endpoints).\n\n# Routes\n\nThe API endpoints are accessible through a route of the form: `https://<domain>/api/<version>/<endpoint>`.\n\nWhere:\n\n- `domain` is the domain to use, usually \"app.hubflo.com\"\n- `version` is the API version\n- `endpoint` is the endpoint name\n\nFor example, we will have: `https://app.hubflo.com/api/v2/pings`.\n\n# Request headers\n\nEvery request should include the header `Content-Type: application/json`, except for file uploads.\n\n# Requests and parameters\n\nThe API adheres to REST principles:\n\n- `GET` requests: read without modification\n- `POST` requests: create a new resource\n- `PATCH` requests: update an existing resource\n- `DELETE` requests: delete a resource\n\nThe parameters for `GET` requests should be sent via the query string of the request.\n\nThe parameters for `POST` and `PATCH` requests should be transmitted in the request body in a valid JSON format.\n\nThe parameters should follow the following formats:\n- `date`: \"YYYY-MM-DD\", for example: \"2021-10-21\"\n- `time`: \"H:m[:s]\", for example: \"10:30\"\n- `date-time`: \"YYYY-MM-DDThh:mm:ssZ\", which is the [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601#Combined_date_and_time_representations) format, using UTC\n\n# Response headers\n\nAs specified for each endpoint, the response headers contain:\n- `Content-Type`: the response content type\n- `X-Organization-ID`: your organization ID\n- `X-Rate-Limit` the maximum allowed requests in a given period\n- `X-Remaining-Requests`: the remaining requests count in the current period\n\n# Response format\n\nThe API only supports JSON format.\nAll responses sent by the API will contain the header `Content-Type: application/json` and their content is present in\nthe body in a JSON format to be de-serialized.\n\n# Rate limit\n\nThe use of the API is limited.\nYou can make a maximum of 1000 calls per minute.\nIf you exceed this limit, you receive a `429 - Too Many Requests` error and are blocked for one minute.\n\n# Pagination\n\nAll endpoints that return lists are paginated.\nIn general, any endpoint that returns a list can return an empty list.\n\nThe (optional) `page` parameter allows you to access a specific page.\n\nThe (optional) `per_page` parameter allows you to change the number of items on a given page.\nThe default value is 20 and it is limited to a maximum of 100.\n\n# Response codes\n\nThe API may return the following codes:\n\n| Code  | Name                  | Description                                                                      |\n| ----  | --------              | --------                                                                         |\n| `200` | Success               | Success                                                                          |\n| `201` | Created               | Resource created                                                                 |\n| `204` | No Content            | Success but the response does not contain any data (e.g., deletion)              |\n| `400` | Bad Request           | The request is invalid                                                           |\n| `401` | Unauthorized          | Authentication failed                                                            |\n| `403` | Forbidden             | Insufficient rights to perform the requested action                              |\n| `404` | Not Found             | The resource is not found                                                        |\n| `422` | Unprocessable Content  | The transmitted data is malformed                                                |\n| `429` | Too Many Requests     | Too many requests have been made                                                 |\n| `500` | Internal Server Error | An internal server error occurred (the technical team is automatically notified) |\n\n# Errors\n\nWhen an error occurs, the response code informs you about what is happening.\nThe response body contains:\n- the status code,\n- the status name, a.k.a the error title,\n- a human readable message.\n\nSee the error schemas below.\n\n# Resources\n\nAll resources are identified by a unique ID that looks like this: \"16242d6f-a808-41b7-8c4d-fe29b9b3245f\".\n\nJSON data types are used at most: `string`, `number`, `float`, `object`, `array`, `boolean` and `null`.\nDates and datetimes attributes are serialized with UTC [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601#Combined_date_and_time_representations) format.\n\n\n"
servers:
- url: https://app.hubflo.com
  description: The production API server
- url: https://staging.hubflo.com
  description: The staging API server
- url: http://localhost:3000
  description: The local API server
tags:
- name: form
paths:
  /api/v2/forms/{form_id}/answers:
    parameters:
    - name: form_id
      in: path
      required: true
      description: Form ID
      schema:
        type: string
    get:
      summary: Retrieves the answers
      security:
      - bearer_auth: []
      description: Returns the answers
      tags:
      - form
      parameters:
      - name: page
        in: query
        required: false
        description: Page number
        example: 1
        schema:
          type: number
      - name: per_page
        in: query
        required: false
        description: Number of items per page (max 100)
        example: 10
        schema:
          type: number
      - name: contact_id
        in: query
        required: false
        description: Filter by contact ID
        schema:
          type: string
      - name: assignment_id
        in: query
        required: false
        description: Filter by assignment ID
        schema:
          type: string
      - name: submission_id
        in: query
        required: false
        description: Filter by submission ID
        schema:
          type: string
      responses:
        '200':
          description: Answers retrieved
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
            X-Page:
              schema:
                type: integer
              description: Current page number
            X-Per-Page:
              schema:
                type: integer
              description: Number of items per page
            X-Total-Pages:
              schema:
                type: integer
              description: Total number of pages
            X-Next-Page:
              schema:
                type: integer
                nullable: true
              description: Next page number
            X-Prev-Page:
              schema:
                type: integer
                nullable: true
              description: Previous page number
            X-Total-Count:
              schema:
                type: integer
              description: Total number of items
          content:
            application/json:
              examples:
                example:
                  value:
                  - id: 43ce545a-23b8-4611-8181-c9ce4e5466c0
                    value: short text
                    values: []
                    item_id: 9c2834c9-f693-40d2-8687-672dbf35aaa6
                    title: What is your favorite color?
                    description: null
                    choices: []
                    type: short_text
                    matching_field: null
                  - id: 73f97e41-ac84-40aa-960a-66fd1e0c06b1
                    value: short text
                    values: []
                    item_id: aa1b9190-0287-4541-a137-15df3a4641f5
                    title: What is your favorite color?
                    description: null
                    choices: []
                    type: short_text
                    matching_field: null
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
  /api/v2/forms/{form_id}/answers/{id}:
    parameters:
    - name: form_id
      in: path
      required: true
      description: Form ID
      schema:
        type: string
    - name: id
      in: path
      required: true
      description: Answer ID
      schema:
        type: string
    get:
      summary: Retrieves an answer
      security:
      - bearer_auth: []
      description: Returns an answer
      tags:
      - form
      responses:
        '200':
          description: Answer retrieved
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    id: 7e1c9f2e-7378-496a-b5a2-e1f1e8d28887
                    value: short text
                    values: []
                    item_id: 94ffdd4b-8e14-46b1-aa6e-304798039e82
                    title: What is your favorite color?
                    description: null
                    choices: []
                    type: short_text
                    matching_field: null
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
  /api/v2/forms/{form_id}/assignments:
    parameters:
    - name: form_id
      in: path
      required: true
      description: Form ID
      schema:
        type: string
    get:
      summary: Retrieves the assignments
      security:
      - bearer_auth: []
      description: Returns the assignments
      tags:
      - form
      parameters:
      - name: page
        in: query
        required: false
        description: Page number
        example: 1
        schema:
          type: number
      - name: per_page
        in: query
        required: false
        description: Number of items per page (max 100)
        example: 10
        schema:
          type: number
      - name: status
        in: query
        required: false
        description: Filter by status (pending, completed)
        schema:
          type: string
      responses:
        '200':
          description: Assignments retrieved
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
            X-Page:
              schema:
                type: integer
              description: Current page number
            X-Per-Page:
              schema:
                type: integer
              description: Number of items per page
            X-Total-Pages:
              schema:
                type: integer
              description: Total number of pages
            X-Next-Page:
              schema:
                type: integer
                nullable: true
              description: Next page number
            X-Prev-Page:
              schema:
                type: integer
                nullable: true
              description: Previous page number
            X-Total-Count:
              schema:
                type: integer
              description: Total number of items
          content:
            application/json:
              examples:
                example:
                  value:
                  - id: 78a893f7-c6c4-458f-84f6-089eac032251
                    form_id: 6802882b-e064-4141-b167-ed127bec1f1f
                    creator_id: 4d2b0431-df5d-481c-ac27-9089da2b7aa7
                    contact_id: 3c454578-cea5-447a-8561-acb82f358277
                    url: http://client.localhost:3000/forms/6802882b-e064-4141-b167-ed127bec1f1f/assignments/78a893f7-c6c4-458f-84f6-089eac032251?public=false
                    status: pending
                    self_service: false
                    created_at: '2026-07-17T13:09:17Z'
                  - id: 54f0f55f-1575-4f9b-b5ff-4ae77ba6761b
                    form_id: 6802882b-e064-4141-b167-ed127bec1f1f
                    creator_id: 4d2b0431-df5d-481c-ac27-9089da2b7aa7
                    contact_id: f3325a55-10b6-4561-b60b-349b676af76e
                    url: http://client.localhost:3000/forms/6802882b-e064-4141-b167-ed127bec1f1f/assignments/54f0f55f-1575-4f9b-b5ff-4ae77ba6761b?public=false
                    status: pending
                    self_service: false
                    created_at: '2026-07-17T13:09:17Z'
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
    post:
      summary: Creates an assignment
      security:
      - bearer_auth: []
      description: Creates an assignment
      tags:
      - form
      parameters: []
      responses:
        '201':
          description: Assignment created
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    id: 32ad1699-0494-4f95-aa1f-52fa288c1c62
                    form_id: 1f3ced21-0e99-4207-9e2a-a0d604db73e1
                    creator_id: e68a6422-fdb4-4c64-922a-8ac109b3ed33
                    contact_id: 5bd17e2a-0b8c-4ca9-b093-f5a4ed623179
                    url: http://client.localhost:3000/forms/1f3ced21-0e99-4207-9e2a-a0d604db73e1/assignments/32ad1699-0494-4f95-aa1f-52fa288c1c62?public=false
                    status: pending
                    self_service: false
                    created_at: '2026-07-17T13:09:18Z'
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                contact_id:
                  type: string
                  example: 12da2ce9-3490-432b-81c0-b9bace2469cc
              required:
              - contact_id
        required: true
        description: Assignment attributes
  /api/v2/forms/{form_id}/assignments/{id}:
    parameters:
    - name: form_id
      in: path
      required: true
      description: Form ID
      schema:
        type: string
    - name: id
      in: path
      required: true
      description: Assignment ID
      schema:
        type: string
    get:
      summary: Retrieves an assignment
      security:
      - bearer_auth: []
      description: Returns an assignment
      tags:
      - form
      responses:
        '200':
          description: Assignment retrieved
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    id: 473beadd-cbf0-4b56-8e43-88a346c6f4b7
                    form_id: 77d7347d-d995-4f7c-8f61-968f5ee626bc
                    creator_id: 4d2b0431-df5d-481c-ac27-9089da2b7aa7
                    contact_id: b3c6d030-356b-4d73-8ee1-5d406cb6b168
                    url: http://client.localhost:3000/forms/77d7347d-d995-4f7c-8f61-968f5ee626bc/assignments/473beadd-cbf0-4b56-8e43-88a346c6f4b7?public=false
                    status: pending
                    self_service: false
                    created_at: '2026-07-17T13:09:18Z'
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
  /api/v2/forms/{form_id}/items/{item_id}/condition_group:
    parameters:
    - name: form_id
      in: path
      required: true
      description: Form ID
      schema:
        type: string
    - name: item_id
      in: path
      required: true
      description: Item ID
      schema:
        type: string
    get:
      summary: Retrieves the condition group
      security:
      - bearer_auth: []
      description: Retrieves the condition group for a specific item in a form
      tags:
      - form
      responses:
        '200':
          description: Condition group retrieved
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    operator: or
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
    post:
      summary: Creates a condition group
      security:
      - bearer_auth: []
      description: Creates a condition group for a specific item in a form
      tags:
      - form
      parameters: []
      responses:
        '201':
          description: Condition group created
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    operator: or
        '400':
          description: 'bad request: the request is invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 400
                    title: Bad Request
                    message: '''wrong1234'' is not a valid operator'
              schema:
                $ref: '#/components/schemas/error_bad_request'
        '401':
          description: 'unauthorized: the Authorization header is missing or invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 401
                    title: Unauthorized
                    message: Invalid API token
              schema:
                $ref: '#/components/schemas/error_unauthorized'
        '404':
          description: 'not found: the resource is not found'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 404
                    title: Not Found
                    message: Resource not found
              schema:
                $ref: '#/components/schemas/error_not_found'
        '429':
          description: 'too many requests: the user has reached the rate limit'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 429
                    title: Too Many Requests
                    message: Rate limit reached. Please wait for a couple of minutes.
              schema:
                $ref: '#/components/schemas/error_too_many_requests'
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                operator:
                  type: string
                  enum:
                  - or
                  - and
                  example: or
              required:
              - operator
        required: true
        description: Condition group attributes
    patch:
      summary: Updates a condition group
      security:
      - bearer_auth: []
      description: Updates a condition group for a specific item in a form
      tags:
      - form
      parameters: []
      responses:
        '200':
          description: Condition group updated
          headers:
            Content-Type:
              schema:
                type: string
              description: application/json; charset=utf-8
            X-Organization-ID:
              schema:
                type: string
              description: The organization ID
            X-Rate-Limit:
              schema:
                type: integer
              description: Max allowed requests in the current period
            X-Remaining-Requests:
              schema:
                type: integer
              description: Remaining requests in the current period
          content:
            application/json:
              examples:
                example:
                  value:
                    operator: or
        '400':
          description: 'bad request: the request is invalid'
          content:
            application/json:
              examples:
                example:
                  value:
                    status: 400
                    title: Bad Request
                    message: '''wrong1234'' is not a valid operator'
              schema:
                $ref: '#/components/schemas/error_bad_request'
        '401

# --- truncated at 32 KB (99 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/hubflo/refs/heads/main/openapi/hubflo-form-api-openapi.yml