Deliver feedback responses
In the campaign editor's “Content” step, enable “Send data to an external system” and fill in “Response delivery URL”. Your receiver needs a public HTTPS address. Flowtomate first saves the form response, then makes one JSON POST. A failed external delivery does not undo the saved response.
The request contains three headers:
text
Content-Type: application/json
Idempotency-Key: <requestId>
X-Flowtomate-Event: feedback.response.createdThe first request body has this structure; the example values are fictional:
json
{
"event": "feedback.response.created",
"responseId": "response_123",
"requestId": "request_123",
"projectId": "project_123",
"widgetId": "widget_123",
"widgetKey": "nps",
"widgetName": "Product rating",
"widgetRevision": 1,
"responseKind": "rating",
"primaryScore": 5,
"message": "",
"contactEmail": "",
"answers": [
{
"fieldId": "rating_1",
"type": "rating",
"question": "How would you rate the product?",
"value": 5
}
],
"context": {},
"visitorId": "visitor_123",
"userId": null,
"submittedAt": "2026-08-23T12:00:00.000Z"
}Idempotency-Key equals requestId. responseKind accepts rating, text, or survey. primaryScore and userId can be null; message and contactEmail are always strings, which may be empty. answers contains 1 to 20 answers in the form { fieldId, type, question, value, optionSnapshots? }. The field type can be rating, text, textarea, email, phone, date, or choice. For rating, the value is an integer from 0 to 10 or null. For choice, the value can be an empty string, an option ID, or an array of up to 50 distinct IDs; optionSnapshots contains the IDs and labels of the selected options. Other values are strings: text up to 500 characters, textarea up to 4,000, email up to 254, phone up to 64, and date in YYYY-MM-DD format or empty. The contents of context depend on the form and page.
Responses may contain personal data. Validate the method, size, and schema of incoming JSON; store requestId with a uniqueness constraint to avoid processing the same response twice. Do not log response text, email, the external user ID, answers, or context.
What delivery means
Flowtomate does not sign the request or add a shared secret. The Idempotency-Key header alone does not prove where the request came from. Use HTTPS and restrict access to your receiver by your own means; do not put a secret in the endpoint's query parameters.
Flowtomate waits up to five seconds for a response, treats any 2xx status as success, and does not retry a failed request. A slow or failed attempt leaves the response in the dashboard but does not deliver it to your system. Do not use the endpoint as the only store for responses or as a channel for payments and irreversible commands.
To verify, submit a test form. Find the response in the dashboard, then inspect the response to the submission in DevTools → Network: on the first attempt, the externalDelivery field is delivered, failed, or disabled. It reports the result of that attempt but is not a persistent log. Match requestId and responseId against the record at your receiver. A repeated submission of the same request may receive a response without externalDelivery, because Flowtomate has already saved it.