.png)
Formstack Integration Guide
Connect Formstack Forms, Documents, and Sign with enterprise systems through REST APIs, selected webhook events, OAuth 2.0, and orchestrated workflows.
Formstack integration options at a glance
Formstack’s primary integration model is product-specific REST APIs covering resources such as Forms, Submissions, Fields, Documents, Templates, and signature-related objects. Selected events, particularly form submission events, can generate webhook-style notifications, while scheduled polling is appropriate where event coverage is unavailable. OAuth 2.0 is the primary documented authentication method, although some products or account configurations may use additional credentials. File and attachment handling depends on the relevant product and endpoint. Martini can consume these APIs, receive callbacks through a Martini API, paginate and batch retrievals, transform JSON, route files, and orchestrate downstream systems with validation, retries, and durable processing state.
Common Formstack integration patterns
Common Formstack data objects used in integrations
Authentication and security considerations
Product-specific authentication
Formstack authentication varies across Forms, Documents, and Sign. OAuth 2.0 is the primary documented pattern, while additional product-specific credentials may apply.
Credential protection
- Store client credentials, tokens, and other secrets in Martini environment secrets.
- Do not embed credentials in workflow definitions or log sensitive form values.
- Request only the permissions required by the relevant Formstack product and resources.
Webhook protection
Validate callback payloads and use the product’s documented verification mechanism where available. If validation is limited, protect the Martini endpoint with authentication, a secret path, source restrictions where practical, and strict payload checks.
Operational considerations for Formstack integrations
Rate limits and pagination
Use the documented rate limits for the relevant Formstack API. Limit concurrency, process collections in controlled batches, handle pagination explicitly, and retry transient 429 and 5xx responses with backoff.
Idempotency and replay
Persist stable Formstack identifiers such as Submission, Document, or signature-request IDs with processing state. This prevents duplicate writes when webhook delivery or polling repeats an item and enables controlled replay.
Schema and product boundaries
Confirm the Formstack product, API version, account plan, object coverage, and event support. Form owners may add, remove, or rename fields, so mappings should validate required values, tolerate unknown fields where possible, and be versioned when necessary.
Files and sensitive data
Define whether workflows transfer file content, download URLs, or metadata. Apply retention, encryption, access, and deletion rules, and prevent personal or sensitive form values from appearing in logs.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration across systems
Martini coordinates Formstack APIs, callbacks, scheduled polling, databases, CRMs, storage systems, and messaging endpoints in maintainable workflows instead of scattering logic across scripts.
Reusable integration logic
Reusable workflows and APIs can centralize authentication, validation, mapping, business rules, idempotency, and exception handling across Forms, Documents, and Sign processes.
Operational reliability
Martini provides structured workflow execution, controlled batching, retry paths, durable processing state, and monitoring-oriented logging. This makes it easier to distinguish transient Formstack failures from invalid submissions and to replay work safely.
Controlled API access
Martini can expose a controlled REST API for internal consumers while keeping Formstack credentials, product boundaries, and downstream orchestration behind a managed integration layer.