Skip to main content
Google Forms is an intake channel only. Supabase remains the system of record, and Resend continues to deliver verification, approval, denial, usage, revocation, and management emails.

Form questions

Create a form that does not require a Google account and add these question titles exactly: Test access should be described as non-expiring, limited development and early-stage access. Production access should be described as a paid capacity review.

Connect the form

  1. Open the form’s Apps Script project.
  2. Paste integrations/google-forms/Code.gs into the project.
  3. In Project Settings → Script Properties, add:
    • HFSAA_INGEST_URL: the target Worker’s URL ending in /v1/integrations/google-forms/applications.
    • HFSAA_INGEST_TOKEN: a dedicated random ingestion secret. Never use the administrator token.
  4. Run installFormSubmitTrigger once and approve the requested Google permissions.
  5. Link responses to a restricted Google Sheet for operational review. Limit Sheet and Script access to HFSAA administrators.
The trigger sends each response to the Worker. The Worker validates the dedicated secret, stores the request in Supabase, and asks Resend to verify the applicant’s email. Retries use a deterministic verification token and Resend idempotency key, so a repeated trigger does not create multiple active applications or different verification links.

Staging verification

Submit a test response using an HFSAA-controlled inbox. Confirm that:
  1. The form response appears in the restricted Sheet.
  2. The Worker returns HTTP 202 to Apps Script.
  3. The verification email arrives through Resend.
  4. Clicking the verification link moves the Supabase application to pending_review.
  5. The application appears in the HFSAA admin dashboard.
Do not connect the production Worker until the staging flow passes end to end.

Production intake

For the MVP, use one public form as the production intake after the staging flow has passed. Keep its existing authorized onFormSubmit trigger, create a new production ingestion token, and update the bound script properties to:
  • HFSAA_INGEST_URL: https://api.hfsaa.org/v1/integrations/google-forms/applications
  • HFSAA_INGEST_TOKEN: the production Worker’s dedicated GOOGLE_FORMS_INGEST_TOKEN value
Publish the form without requiring a Google account and set the production Worker’s DEVELOPER_APPLICATION_FORM_URL variable to its responder URL. New applications then enter the production review queue. Approved test keys still use the staging API base URL, while approved production keys use https://api.hfsaa.org. Run a controlled HFSAA-owned test submission before sharing the form publicly. If a separately isolated staging intake is needed later, copy the form and script and give that copy its own staging-only ingestion token.