Form questions
Create a form that does not require a Google account and add these question titles exactly:
Test access should be described as non-expiring, limited development and early-stage access. Production access should be described as a paid capacity review.
Connect the form
- Open the form’s Apps Script project.
- Paste
integrations/google-forms/Code.gsinto the project. - In Project Settings → Script Properties, add:
HFSAA_INGEST_URL: the target Worker’s URL ending in/v1/integrations/google-forms/applications.HFSAA_INGEST_TOKEN: a dedicated random ingestion secret. Never use the administrator token.
- Run
installFormSubmitTriggeronce and approve the requested Google permissions. - Link responses to a restricted Google Sheet for operational review. Limit Sheet and Script access to HFSAA administrators.
Staging verification
Submit a test response using an HFSAA-controlled inbox. Confirm that:- The form response appears in the restricted Sheet.
- The Worker returns HTTP
202to Apps Script. - The verification email arrives through Resend.
- Clicking the verification link moves the Supabase application to
pending_review. - The application appears in the HFSAA admin dashboard.
Production intake
For the MVP, use one public form as the production intake after the staging flow has passed. Keep its existing authorizedonFormSubmit trigger, create a new production ingestion token, and update the bound script properties to:
HFSAA_INGEST_URL:https://api.hfsaa.org/v1/integrations/google-forms/applicationsHFSAA_INGEST_TOKEN: the production Worker’s dedicatedGOOGLE_FORMS_INGEST_TOKENvalue
DEVELOPER_APPLICATION_FORM_URL variable to its responder URL. New applications then enter the production review queue. Approved test keys still use the staging API base URL, while approved production keys use https://api.hfsaa.org.
Run a controlled HFSAA-owned test submission before sharing the form publicly. If a separately isolated staging intake is needed later, copy the form and script and give that copy its own staging-only ingestion token.