Skip to main content

Google Sheets

The Google Sheets action posts JSON to an Apps Script web app. It does not use service-account credentials or OAuth.

Setup

  1. Copy the maintained receiver into an Apps Script project.
  2. Add script properties: CF_SHARED_SECRET (a random secret), SPREADSHEET_ID, and optionally SHEET_NAME.
  3. Put field names in the first row of the destination sheet. Add _form_title and _submitted_at headers if wanted.
  4. Deploy as a web app, execute as yourself, and allow anyone to call it. The receiver rejects requests without the secret.
  5. In Core Forms → Actions → Google Sheets, enter the deployment URL and the same secret. Optionally list which fields to send.

The script returns JSON with ok: true after appending. Invalid secrets or append errors return ok: false, which Core Forms records as an action failure. Existing receivers returning plain OK continue to work; leave the secret empty for those legacy scripts.

Zero and false values are preserved. Visitor-entered formulas are stored as text. The shared secret is checked before appending and is never added to a row. API acceptance is not proof that a user has read the sheet.

Background execution uses saved submissions. If submission storage is disabled, the action runs synchronously. See delivery and retries.

Settings

Setting Required Purpose
Web App URL Yes Deployment URL ending in /exec
Shared secret For the maintained receiver Same value as CF_SHARED_SECRET in Script Properties
Fields No Comma-separated exact field names; empty sends all submission fields
Run in the background No Queue delivery when submission storage is enabled

Headers and metadata

For a form using NAME, EMAIL, and MESSAGE, put those names in the sheet’s header row. Matching is case-sensitive. To include metadata, add _form_title and _submitted_at columns. Column order does not matter.

The receiver validates and removes _cf_shared_secret before appending, so it never becomes a spreadsheet value. Do not add credentials to the sheet. Use a random secret stored only in Script Properties and the action settings.

Troubleshooting

  • Use the deployed /exec URL, not the Apps Script editor URL.
  • Deploy as your account and allow web access; the shared secret authenticates incoming payloads.
  • Ensure the spreadsheet ID and optional sheet name resolve to an existing sheet with headers.
  • An unauthorized response means the secrets do not match.
  • An HTML login page or an unrecognized response is not confirmation of a row append and is logged as a failure.
  • Apps Script may have cold starts; the integration uses a 30-second request timeout.
  • The receiver does not provide exactly-once delivery. If a response is lost after append, a retry can add another row; use a submission identifier in custom workflows that need deduplication.