> ## Documentation Index
> Fetch the complete documentation index at: https://hfsaa.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Forms intake setup

> Connect the public API application form to the HFSAA Worker.

Google Forms is an intake channel only. Supabase remains the system of record, and Resend continues to deliver verification, approval, denial, usage, revocation, and management emails.

## Form questions

Create a form that does not require a Google account and add these question titles exactly:

| Question | Type | Required |
| - | - | - |
| Name | Short answer | Yes |
| Email | Short answer with email validation | Yes |
| Organization | Short answer | No |
| Website | Short answer with URL validation | No |
| Access type | Multiple choice: `Test` or `Production` | Yes |
| Expected monthly requests | Short answer with number validation | No |
| How will you use the API? | Paragraph | Yes |

Test access should be described as non-expiring, limited development and early-stage access. Production access should be described as a paid capacity review.

## Connect the form

1. Open the form's Apps Script project.
2. Paste `integrations/google-forms/Code.gs` into the project.
3. In **Project Settings → Script Properties**, add:
   * `HFSAA_INGEST_URL`: the target Worker's URL ending in `/v1/integrations/google-forms/applications`.
   * `HFSAA_INGEST_TOKEN`: a dedicated random ingestion secret. Never use the administrator token.
4. Run `installFormSubmitTrigger` once and approve the requested Google permissions.
5. Link responses to a restricted Google Sheet for operational review. Limit Sheet and Script access to HFSAA administrators.

The trigger sends each response to the Worker. The Worker validates the dedicated secret, stores the request in Supabase, and asks Resend to verify the applicant's email. Retries use a deterministic verification token and Resend idempotency key, so a repeated trigger does not create multiple active applications or different verification links.

## Staging verification

Submit a test response using an HFSAA-controlled inbox. Confirm that:

1. The form response appears in the restricted Sheet.
2. The Worker returns HTTP `202` to Apps Script.
3. The verification email arrives through Resend.
4. Clicking the verification link moves the Supabase application to `pending_review`.
5. The application appears in the HFSAA admin dashboard.

Do not connect the production Worker until the staging flow passes end to end.

## Production intake

For the MVP, use one public form as the production intake after the staging flow has passed. Keep its existing authorized `onFormSubmit` trigger, create a new production ingestion token, and update the bound script properties to:

* `HFSAA_INGEST_URL`: `https://api.hfsaa.org/v1/integrations/google-forms/applications`
* `HFSAA_INGEST_TOKEN`: the production Worker's dedicated `GOOGLE_FORMS_INGEST_TOKEN` value

Publish the form without requiring a Google account and set the production Worker's `DEVELOPER_APPLICATION_FORM_URL` variable to its responder URL. New applications then enter the production review queue. Approved test keys still use the staging API base URL, while approved production keys use `https://api.hfsaa.org`.

Run a controlled HFSAA-owned test submission before sharing the form publicly. If a separately isolated staging intake is needed later, copy the form and script and give that copy its own staging-only ingestion token.
