Google Sheets
The Google Sheets action posts JSON to an Apps Script web app. It does not use service-account credentials or OAuth.
Setup
- Copy the maintained receiver into an Apps Script project.
- Add script properties:
CF_SHARED_SECRET(a random secret),SPREADSHEET_ID, and optionallySHEET_NAME. - Put field names in the first row of the destination sheet. Add
_form_titleand_submitted_atheaders if wanted. - Deploy as a web app, execute as yourself, and allow anyone to call it. The receiver rejects requests without the secret.
- In Core Forms → Actions → Google Sheets, enter the deployment URL and the same secret. Optionally list which fields to send.
The script returns JSON with ok: true after appending. Invalid secrets or append errors return ok: false, which Core Forms records as an action failure. Existing receivers returning plain OK continue to work; leave the secret empty for those legacy scripts.
Zero and false values are preserved. Visitor-entered formulas are stored as text. The shared secret is checked before appending and is never added to a row. API acceptance is not proof that a user has read the sheet.
Background execution uses saved submissions. If submission storage is disabled, the action runs synchronously. See delivery and retries.
Settings
| Setting | Required | Purpose |
|---|---|---|
| Web App URL | Yes | Deployment URL ending in /exec |
| Shared secret | For the maintained receiver | Same value as CF_SHARED_SECRET in Script Properties |
| Fields | No | Comma-separated exact field names; empty sends all submission fields |
| Run in the background | No | Queue delivery when submission storage is enabled |
Headers and metadata
For a form using NAME, EMAIL, and MESSAGE, put those names in the sheet’s header row. Matching is case-sensitive. To include metadata, add _form_title and _submitted_at columns. Column order does not matter.
The receiver validates and removes _cf_shared_secret before appending, so it never becomes a spreadsheet value. Do not add credentials to the sheet. Use a random secret stored only in Script Properties and the action settings.
Troubleshooting
- Use the deployed /exec URL, not the Apps Script editor URL.
- Deploy as your account and allow web access; the shared secret authenticates incoming payloads.
- Ensure the spreadsheet ID and optional sheet name resolve to an existing sheet with headers.
- An unauthorized response means the secrets do not match.
- An HTML login page or an unrecognized response is not confirmation of a row append and is logged as a failure.
- Apps Script may have cold starts; the integration uses a 30-second request timeout.
- The receiver does not provide exactly-once delivery. If a response is lost after append, a retry can add another row; use a submission identifier in custom workflows that need deduplication.