Formbricks

by Formbricks GmbH HTTP API in Forms, surveys & structured intake

Hosted

Formbricks GmbH · formbricks.com since 2022 · status page · who's behind it

Formbricks is an open-source survey and experience management platform from Formbricks GmbH in Kiel, Germany. Agents create surveys, read responses and manage webhooks through a REST Management API or a hosted MCP server, on Formbricks Cloud or a self-hosted instance.

Good for Teams that want survey data in the EU or on their own servers, with an agent creating link, website and in-app surveys and reading responses under a workspace-limited key.

Is this your product? Claim this listing or verify it

Assessment. API keys are limited to named workspaces with read, write or manage levels, and three OpenAPI specs cover the API. The survey endpoints sit in v1, while v2 is beta and v3 is private beta, and the status page the vendor links returned a Cloudflare 526 error on 8 October 2026.

Facts

Transport
HTTP, Streamable HTTP
Endpoint
https://app.formbricks.com/api
Auth
OAuth or key
Pricing
Freemium · $74 / mo
x402
No
Licence
AGPLv3 for the core. Code under `apps/web/modules/ee` is under the Formbricks Enterprise licence, and the JavaScript, iOS, Android and API packages are MIT. Formbricks Cloud is governed by the terms of service
Tools exposed
30
Packages
npm @formbricks/js
npm @formbricks/api
llms.txt
published
Last release
GitHub stars
13k
npm / week
37k
APIs
Management API v1 at https://app.formbricks.com/api/v1 (32 operations in an OpenAPI 3.0.0 file, with surveys, responses, contacts, action classes, storage and webhooks), v2 at /api/v2 (40 operations, OpenAPI 3.1.0, labelled beta, no survey endpoints), v3 at /api/v3 (48 operations, private beta and unlisted). A public Client API takes survey displays and responses without authentication
MCP server
Streamable HTTP at https://app.formbricks.com/api/mcp, or /api/mcp on a self-hosted instance. The live docs list 30 tools for surveys, workflows and feedback records, counting list_workspaces. The repository docs add eight response tools and two survey block tools whose scopes the cloud metadata did not yet advertise on 8 October 2026
Credentials
API keys (fbk_ prefix) sent as x-api-key, created by a signed-in user, shown once, limited to chosen workspaces at read, write or manage, with separate organisation access. Scopes are fixed at creation. MCP uses OAuth 2.1 with PKCE S256 and dynamic client registration, 15-minute access tokens and a 30-day refresh window
Rate limits
100 requests a minute per API key on /api/v1/management/*, /api/v1/webhooks/*, v2 and v3. 5 a minute on storage uploads and deletes. 100 a minute per IP hash on client routes
Errors
v1 answers {code, message, details}, v2 and v3 answer {error: {code, message}}. Gateway 429s carry x-envoy-ratelimited. v3 feedback record errors use application/problem+json
Pagination
limit and skip on v1 and v2. v2 responses take sortBy, order, startDate, endDate, surveyId and contactId, with a default of 50 and a maximum of 250. v3 uses cursors
SDKs
@formbricks/js 5.1.0 (MIT) for website and in-app surveys and @formbricks/api 3.0.0 (MIT) on npm. iOS and Android SDKs are listed under the Pro plan
Plans
Hobby is free with 1 workspace and 250 responses a month. Pro is shown at $74 a month with 3 workspaces and 2,000 responses, Scale at $325 with 5 workspaces and 5,000 responses. API and MCP access is listed on Hobby
Self-hosting
Docker, a one-click installer and a Helm chart. The Community Edition is AGPLv3 with unlimited responses and one workspace. Code under apps/web/modules/ee needs an Enterprise licence
Releases
Semantic versions on GitHub Releases. 6.0.2 on 1 October 2026, 6.0.1 on 29 September, 6.0.0 on 16 September. Each minor is maintained for three calendar months
Certifications
The security page says SOC 2 Type II and ISO 27001 compliant, with an annual independent penetration test and a trust centre at trust.oneleet.com/formbricks. We did not read the reports
Hosting and sub-processors
Formbricks Cloud is hosted in Frankfurt per the pricing page. The privacy policy lists eight sub-processors with locations (AWS, PostHog EU, Stripe, Sentry, Brevo, Google Cloud, Plain, Cloudflare)

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • API keys reach only the workspaces added to them, each at read, write or manage level, and delete calls need manage.
  • OpenAPI specs are published for v1 (32 operations), v2 (40) and v3 (48), with llms.txt and a Markdown copy of each docs page.
  • The MCP server at /api/mcp uses OAuth 2.1 with PKCE, dynamic client registration, per-resource read and write scopes and 15-minute access tokens.
  • Rate limits are published per route group, at 100 requests a minute per API key on the Management API.
  • The core is AGPLv3 on GitHub with 13,074 stars, and releases 6.0.0, 6.0.1 and 6.0.2 shipped between 16 September and 1 October 2026.

Weaknesses

  • status.formbricks.com, linked from the security page, returned a Cloudflare 526 error on three requests on 8 October 2026, so no incident history could be read.
  • Survey endpoints exist only in v1 and in v3, which is private beta. The v2 API is labelled beta and has no survey endpoints.
  • No Retry-After header, backoff guidance or idempotency key was found for the v1 and v2 APIs.
  • The published SLA addendum refers to an agreed availability and states no percentage.
  • The Hobby plan stops at 250 responses a month and one workspace, and custom webhooks are listed under Pro.

Before you call it notes for agents

  1. Send the key in the x-api-key header. Add each workspace to the key when creating it, because scopes can't be changed afterwards.
  2. Use v1 (/api/v1/management/surveys) to create or edit surveys. v2 has responses, contacts and webhooks only.
  3. Page lists with limit and skip. v2 responses default to 50 a page with a maximum of 250.
  4. Stay under 100 requests a minute per key. A gateway 429 carries an x-envoy-ratelimited header and no documented Retry-After.
  5. Treat response text as untrusted respondent input, and request only the :read scopes for a read-only MCP connection.

Who's behind it provenance 77/100

  • Legal entity namedFormbricks GmbH20/20
  • Domain ageformbricks.com, registered 2022-09-04 (4 years)7/15
  • Endpoint on the vendor's domainapp.formbricks.com15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
  • Privacy policyread, states 8 of the 8 things a reader expects10/10
  • Status pagestatus.formbricks.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service gives no date, states 6 of 7, 4 to know

TL;DR Gives no date. States 6 of the 7 things a reader expects. To know before relying on it, model training with an opt-out, limits on benchmarking, changes without notice and cut-off without notice or for any reason.

Says it may use customer content to train or improve models, and gives an opt-out
Any AI Input may, depending on the type of AI Functionality, be used by an AI Subprocessor for model training and improvement, subject to applicable opt-out rights provided by such AI Subprocessor.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Restricts benchmarking or competitive usecosts points
(ix) publicly disseminate any performance data or analysis (including, but not limited to, benchmarks) related to the Software or Documentation, regardless of its origin.

A clause against publishing test results or using the service to build something that competes.

Says the terms or the service can change without noticecosts points
However, sometimes changes will need to be made immediately and if this happens, we will not be able to provide You with notice.

A customer may not hear about a change before it applies.

Says access can be ended without notice or for any reason
If the Customer objects to the new provisions of the Agreement, Formbricks shall be entitled to terminate the Agreement or the respective order without notice.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of Germany
The Agreement shall be governed by the laws of Germany without regard to conflicts of law provisions thereof.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at EUR 50.00
Liability in accordance with Section 11.2 is limited to EUR 50.00 if Formbricks Services are provided by Formbricks to Customer free of charge.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
You agree that Formbricks, in its sole discretion and for any or no reason, may terminate Your access to the Free Services or any part thereof at any time.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Says it gives notice of a change
An amendment to the Agreement initiated by Formbricks requires that Formbricks notify the Customer of the intended amendment via email, in-app notification, or website posting at least four (4) weeks before the proposed date of entry into force.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
if You do not have such authority, or if You do not wish to be bound by the terms of these ToS, You must not click the buttons, and You must not access or use the Services.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
The Parties agree on the service level with respect to Availability (as defined in the SLA) of the Software-as-a-Service, the response and resolution times in case of any errors of the Software, and the Update Frequency (as defined in the SLA) as outlined in the Service Level Agreement (or "SLA").

Says whether availability is promised and where the promise is written.

Liability for ordinary negligence is limited to 50 euros when the services are supplied free of charge.
Liability in accordance with Section 11.2 is limited to EUR 50.00 if Formbricks Services are provided by Formbricks to Customer free of charge.

Noted by a second reader on 2026-10-08.

Formbricks may use output generated by its AI functionality for its own internal business purposes.
Formbricks may use AI Output for its own internal business purposes.

Noted by a second reader on 2026-10-08.

Formbricks keeps customer data for 30 days after termination to allow migration, then deletes it unless the law requires otherwise.
Formbricks will retain your data for thirty (30) days post-termination to allow for migration, after which it will be deleted unless otherwise required by law.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 9,455 words

Privacy policy dated 2026-08-21, states 8 of 8

TL;DR Dated 2026-08-21. States all 8 things a reader expects. The rules found no clause to flag.

Gives the date it was last updated Last updated 2026-08-21
We keep our privacy policy under regular review and will place any updates on this web page. This privacy policy was last updated on 21st August 2026.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
For self-hosted instances, we collect and process the administrator's email address through our mail service provider Brevo.

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 90 days
All form data which has been deleted by the form Researcher is permanently deleted from our back-ups within 90 days.

Says when data sent to the service is deleted.

Says who else receives the data
For self-hosted instances, we collect and process the administrator's email address through our mail service provider Brevo.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
Formbricks does not sell personal data to third parties.

A plain statement either way.

Says what rights people have over their data
If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights, covered by GDPR.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact Gives an email address, hidden from our reader by the page
If you have any questions after reading this Privacy Policy, feel free to contact us at [email protected]

An address or officer to send a request to.

Says where data is transferred or stored
By using Formbricks, Researchers signify their acceptance of this policy.

The countries data goes to and the safeguard used.

The document · read 2026-10-08 · 2,722 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The terms of service name Formbricks GmbH, Kuhnkestr. 6, 24118 Kiel, Germany, cover the software as a service and on-premises software, and are governed by German law. No version date was found on the page.

The privacy policy was last updated on 21 August 2026 and says it applies to Formbricks Cloud at app.formbricks.com and the landing page, not to self-hosted instances apart from the administrator's email address.

The API and the MCP server answer at app.formbricks.com. GET /api/v2/health returned 200 and /.well-known/oauth-protected-resource returned the MCP resource metadata.

status.formbricks.com is linked from formbricks.com/security and returned a Cloudflare 526 error on three requests on 8 October 2026.

formbricks.com/.well-known/security.txt and formbricks.com/security.txt both return 404. SECURITY.md in the repository gives security@formbricks.com for reports.

RDAP gives a registration date of 2022-09-04 for formbricks.com and Porkbun LLC as registrar.

A DPA at formbricks.com/dpa and a Service Level Addendum at formbricks.com/sla are published as annexes to the terms.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 21:12 UTC

Right nowUpHTTP 404 · 72 ms · under a minute ago
Uptime 24h100.0%21 probes
Uptime 30 days100.0%21 probes
p50 24h73 msget
p95 24h122 msopen endpoint

Probed every five minutes at https://app.formbricks.com/api. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 1 hour ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/formbricks.json

Notable

  • API keys carry per-workspace read, write or manage levels, and there is no option for all workspaces source
  • The v2 API reference is labelled beta and the v3 reference private beta, unlisted and subject to change without notice. The MCP server is built on v3 source
  • The MCP server at https://app.formbricks.com/api/mcp uses OAuth 2.1 with dynamic client registration, 15-minute access tokens and a 30-day refresh window, and connected clients can be revoked under Authorised Apps source
  • Rate limits are published per route group, 100 requests a minute per API key on the Management API and 5 a minute on storage source
  • Each minor release is maintained for three calendar months, with security fixes for CVSS 7.0 or higher backported to every maintained minor source
  • Advisory GHSA-7229-q9pv-j6p4 (critical, CVSS 9.4, missing JWT signature verification on password reset) was published on 26 September 2025 and patched in 4.0.1 source
  • The only Formbricks entry found in the official MCP registry is a third-party stdio server, io.github.mrfentmen/formbricks-mcp, not the vendor's source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 7.0
Read with the hosted lines and scored on the Management API of Formbricks Cloud, the surface an agent would call with an API key. The security page links status.formbricks.com, which returned a Cloudflare 526 error on three requests on 8 October 2026, so the page is scored as absent today (0) and its history as unreadable (5). Limits are published per route group, 100 requests a minute per API key on v1, v2 and v3 and 5 a minute on storage (15). 429 is documented with a body for each API version and an x-envoy-ratelimited header on gateway responses. No Retry-After, backoff guidance or idempotency key was found for v1 or v2, and the docs say the application limiter fails open when Redis is down (5 of 15). A Service Level Addendum is published with service credits capped at 20 per cent, but it refers to an agreed availability, states no figure and still contains drafting notes (3 of 10). v1 carries no label, v2 is labelled beta and v3 private beta (7 of 10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 12.0
OpenAPI files are public for v1 (3.0.0, 32 operations), v2 (3.1.0, 40 operations) and v3 (3.1.1, 48 operations) in the repository and the docs (25). llms.txt with 281 lines, llms-full.txt and a Markdown copy of each page (10). The v1 descriptions are one sentence each, and the file's own description refers to a Postman collection. The v3 spec explains permissions, idempotency and failure cases at length, but it is private beta (10 of 20). v2 has 93 enums and typed query parameters with defaults and a maximum on limit. The v1 file declares no security scheme and repeats x-api-key as a header parameter on each operation (9 of 15). v1 operations carry example responses, with 400, 401 and 404 on some. v2 documents almost only 200 and 201 responses (9 of 15). Versions are in the path and releases are dated on GitHub with a migration guide. No changelog for the API itself was found (11 of 15).
Agent ergonomics 13%16.2 8.8
Lists take limit and skip, and v2 caps limit at 250 with a default of 50. No field selection was found. The MCP server lists 30 tools on the live docs, with independent scope groups that let a client load only one resource family (15 of 25). v2 responses filter by survey, contact and date range and sort by createdAt or updatedAt. v1 has limit, skip and surveyId only (14 of 20). Error bodies are documented as {code, message, details} on v1 and {error: {code, message}} on v2, with few per-operation error responses in the specs (11 of 20). No idempotency keys on v1 or v2. The MCP handbook shows readOnlyHint, destructiveHint and idempotentHint annotations and a confirmation step on response deletion, which the cloud did not yet advertise (8 of 20). Creating a survey needs a full survey document, v2 has no survey endpoints, and the official packages are JavaScript only (6 of 15).
Security & auth 14%17.5 12.1
API keys are limited to named workspaces at read, write or manage, are shown once and can be deleted to revoke them. Scopes can't be edited, and no expiry or rotation setting was found. The MCP server takes OAuth 2.1 with PKCE S256, dynamic client registration restricted to loopback and named hosted callbacks, 15-minute access tokens and per-resource read and write scopes. Credentials travel in headers, and the MCP route rejects them in the query string (28 of 30). Read-level keys and :read scopes give a read-only mode, and deletes need manage. Confirmation before deleting responses is in the repository docs only (15 of 20). Responses are respondent-written text. The docs tell owners to grant responses:read deliberately and supply count tools that return no text, but no prompt-injection guidance was found (5 of 15). Audit logging is an Enterprise option that writes JSON lines to stdout on a self-hosted instance. No audit log for Cloud customers was found, though authorised OAuth clients are listed in account settings (6 of 15). SECURITY.md sets out private disclosure with a 48-hour acknowledgement and no bounty. The security page claims SOC 2 Type II and ISO 27001 compliance and an annual penetration test, one advisory is published on GitHub, and there is no security.txt (15 of 20).
Payments & pricing 10%12.5 3.8
Read with the hosted rubric, because the grade is for Formbricks Cloud. No x402, MPP or L402 (0). Plan prices are public, with Hobby free and Pro and Scale shown at $74 and $325 a month. The API has no per-call price (10). The Hobby plan includes API and MCP access and the pricing page says no credit card is required (20). A person signs up in a browser and creates the API key, or approves the OAuth client on a consent screen (0). The self-hosted Community Edition is free and would score 60 under the self-hosted rule.
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.3
Release 6.0.2 is dated 1 October 2026 (30). 6.0.0 on 16 September, 6.0.1 on 29 September and 6.0.2, plus 5.4.x patches, fall inside the last 90 days (20). The repository shows 166 open issues and 21 open pull requests, and the default branch had commits on 8 October 2026. We did not sample reply times on issues (15 of 25). @formbricks/js 5.1.0 and @formbricks/api 3.0.0 are current on npm. The vendor's MCP server is not in the official MCP registry, where the only Formbricks entry is a third party's (10 of 15). The repository runs unit, end-to-end and integration test workflows, SonarQube, a Docker security scan and Dependabot. We could not read the latest run status (8 of 10).
Transparency & trusteditorial 78, provenance 77 7%8.8 6.8
The core is AGPLv3 and the SDK packages MIT. Code under apps/web/modules/ee is under a separate Enterprise licence in the same repository, so the project is open core (26 of 30). The privacy policy of 21 August 2026 covers Formbricks Cloud, a DPA is published, and deleted form data leaves backups within 90 days. Account data is kept until the customer deletes it, and no retention period for logs was found. The terms say AI input may be used by an AI sub-processor for model training, subject to that sub-processor's opt-out (22 of 30). A release and maintenance policy gives each minor three calendar months of fixes and the migration guide documents breaking changes by version. No notice period for API deprecations was found, and the v3 reference says it can change without notice (12 of 20). The privacy policy lists eight sub-processors with their data, purpose and location, and the pricing page says Cloud is hosted in Frankfurt. Self-hosted instances send a daily usage update that TELEMETRY_DISABLED turns off, except when an Enterprise licence is active (18 of 20).
Negative events≤15None recorded0
Total57.7 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 17 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Formbricks, or have the agent fetch /fixes/formbricks.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Formbricks

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/formbricks, the October 2026 research run, assessed 8 October 2026. Grade C, 57.7 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Formbricks: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 35 out of 100, up to 13 more on the total

Why it scored 35: Read with the hosted lines and scored on the Management API of Formbricks Cloud, the surface an agent would call with an API key. The security page links status.formbricks.com, which returned a Cloudflare 526 error on three requests on 8 October 2026, so the page is scored as absent today (0) and its history as unreadable (5). Limits are published per route group, 100 requests a minute per API key on v1, v2 and v3 and 5 a minute on storage (15). 429 is documented with a body for each API version and an `x-envoy-ratelimited` header on gateway responses. No `Retry-After`, backoff guidance or idempotency key was found for v1 or v2, and the docs say the application limiter fails open when Redis is down (5 of 15). A Service Level Addendum is published with service credits capped at 20 per cent, but it refers to an agreed availability, states no figure and still contains drafting notes (3 of 10). v1 carries no label, v2 is labelled beta and v3 private beta (7 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total

Why it scored 30: Read with the hosted rubric, because the grade is for Formbricks Cloud. No x402, MPP or L402 (0). Plan prices are public, with Hobby free and Pro and Scale shown at $74 and $325 a month. The API has no per-call price (10). The Hobby plan includes API and MCP access and the pricing page says no credit card is required (20). A person signs up in a browser and creates the API key, or approves the OAuth client on a consent screen (0). The self-hosted Community Edition is free and would score 60 under the self-hosted rule.

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Agent ergonomics, 54 out of 100, up to 7.5 more on the total

Why it scored 54: Lists take `limit` and `skip`, and v2 caps `limit` at 250 with a default of 50. No field selection was found. The MCP server lists 30 tools on the live docs, with independent scope groups that let a client load only one resource family (15 of 25). v2 responses filter by survey, contact and date range and sort by `createdAt` or `updatedAt`. v1 has `limit`, `skip` and `surveyId` only (14 of 20). Error bodies are documented as `{code, message, details}` on v1 and `{error: {code, message}}` on v2, with few per-operation error responses in the specs (11 of 20). No idempotency keys on v1 or v2. The MCP handbook shows `readOnlyHint`, `destructiveHint` and `idempotentHint` annotations and a confirmation step on response deletion, which the cloud did not yet advertise (8 of 20). Creating a survey needs a full survey document, v2 has no survey endpoints, and the official packages are JavaScript only (6 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Security & auth, 69 out of 100, up to 5.4 more on the total

Why it scored 69: API keys are limited to named workspaces at read, write or manage, are shown once and can be deleted to revoke them. Scopes can't be edited, and no expiry or rotation setting was found. The MCP server takes OAuth 2.1 with PKCE S256, dynamic client registration restricted to loopback and named hosted callbacks, 15-minute access tokens and per-resource read and write scopes. Credentials travel in headers, and the MCP route rejects them in the query string (28 of 30). Read-level keys and `:read` scopes give a read-only mode, and deletes need manage. Confirmation before deleting responses is in the repository docs only (15 of 20). Responses are respondent-written text. The docs tell owners to grant `responses:read` deliberately and supply count tools that return no text, but no prompt-injection guidance was found (5 of 15). Audit logging is an Enterprise option that writes JSON lines to stdout on a self-hosted instance. No audit log for Cloud customers was found, though authorised OAuth clients are listed in account settings (6 of 15). `SECURITY.md` sets out private disclosure with a 48-hour acknowledgement and no bounty. The security page claims SOC 2 Type II and ISO 27001 compliance and an annual penetration test, one advisory is published on GitHub, and there is no `security.txt` (15 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 5. Schema & documentation, 74 out of 100, up to 4.2 more on the total

Why it scored 74: OpenAPI files are public for v1 (3.0.0, 32 operations), v2 (3.1.0, 40 operations) and v3 (3.1.1, 48 operations) in the repository and the docs (25). `llms.txt` with 281 lines, `llms-full.txt` and a Markdown copy of each page (10). The v1 descriptions are one sentence each, and the file's own description refers to a Postman collection. The v3 spec explains permissions, idempotency and failure cases at length, but it is private beta (10 of 20). v2 has 93 enums and typed query parameters with defaults and a maximum on `limit`. The v1 file declares no security scheme and repeats `x-api-key` as a header parameter on each operation (9 of 15). v1 operations carry example responses, with 400, 401 and 404 on some. v2 documents almost only 200 and 201 responses (9 of 15). Versions are in the path and releases are dated on GitHub with a migration guide. No changelog for the API itself was found (11 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Transparency & trust, 78 out of 100, up to 1.9 more on the total

Made of editorial 78, provenance 77.

Why it scored 78: The core is AGPLv3 and the SDK packages MIT. Code under `apps/web/modules/ee` is under a separate Enterprise licence in the same repository, so the project is open core (26 of 30). The privacy policy of 21 August 2026 covers Formbricks Cloud, a DPA is published, and deleted form data leaves backups within 90 days. Account data is kept until the customer deletes it, and no retention period for logs was found. The terms say AI input may be used by an AI sub-processor for model training, subject to that sub-processor's opt-out (22 of 30). A release and maintenance policy gives each minor three calendar months of fixes and the migration guide documents breaking changes by version. No notice period for API deprecations was found, and the v3 reference says it can change without notice (12 of 20). The privacy policy lists eight sub-processors with their data, purpose and location, and the pricing page says Cloud is hosted in Frankfurt. Self-hosted instances send a daily usage update that `TELEMETRY_DISABLED` turns off, except when an Enterprise licence is active (18 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: formbricks.com, registered 2022-09-04 (4 years) (7 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
- security.txt: not found (0 of 10)

## 7. Maintenance & community, 83 out of 100, up to 1.5 more on the total

Why it scored 83: Release 6.0.2 is dated 1 October 2026 (30). 6.0.0 on 16 September, 6.0.1 on 29 September and 6.0.2, plus 5.4.x patches, fall inside the last 90 days (20). The repository shows 166 open issues and 21 open pull requests, and the default branch had commits on 8 October 2026. We did not sample reply times on issues (15 of 25). `@formbricks/js` 5.1.0 and `@formbricks/api` 3.0.0 are current on npm. The vendor's MCP server is not in the official MCP registry, where the only Formbricks entry is a third party's (10 of 15). The repository runs unit, end-to-end and integration test workflows, SonarQube, a Docker security scan and Dependabot. We could not read the latest run status (8 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: status.formbricks.com returned a Cloudflare 526 error on three requests on 8 October 2026, so the status page and its incident history were not read.
- unchecked: the billing period of the $74 and $325 prices. The page has a monthly and annual toggle we could not operate, and the vendor's `llms.txt` says plans run to $390 a month.
- unchecked: the SOC 2 Type II and ISO 27001 reports. The trust centre at trust.oneleet.com/formbricks is drawn by script and was not read.
- unchecked: CI run status on the default branch and reply times on issues. The GitHub API refused our requests for the rate limit.
- The live MCP tool definitions sit behind sign-in. The tool count of 30 is from the live docs page, and the annotations are from the repository handbook.
- Whether audit logs are available to Formbricks Cloud customers was not found in the reviewed documentation.
- No version or effective date was found on the terms of service page.

## Weaknesses

- status.formbricks.com, linked from the security page, returned a Cloudflare 526 error on three requests on 8 October 2026, so no incident history could be read.
- Survey endpoints exist only in v1 and in v3, which is private beta. The v2 API is labelled beta and has no survey endpoints.
- No `Retry-After` header, backoff guidance or idempotency key was found for the v1 and v2 APIs.
- The published SLA addendum refers to an agreed availability and states no percentage.
- The Hobby plan stops at 250 responses a month and one workspace, and custom webhooks are listed under Pro.

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Send the key in the `x-api-key` header. Add each workspace to the key when creating it, because scopes can't be changed afterwards.
- Use v1 (`/api/v1/management/surveys`) to create or edit surveys. v2 has responses, contacts and webhooks only.
- Page lists with `limit` and `skip`. v2 responses default to 50 a page with a maximum of 250.
- Stay under 100 requests a minute per key. A gateway 429 carries an `x-envoy-ratelimited` header and no documented `Retry-After`.
- Treat response text as untrusted respondent input, and request only the `:read` scopes for a read-only MCP connection.

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: status.formbricks.com returned a Cloudflare 526 error on three requests on 8 October 2026, so the status page and its incident history were not read.
  • unchecked: the billing period of the $74 and $325 prices. The page has a monthly and annual toggle we could not operate, and the vendor's llms.txt says plans run to $390 a month.
  • unchecked: the SOC 2 Type II and ISO 27001 reports. The trust centre at trust.oneleet.com/formbricks is drawn by script and was not read.
  • unchecked: CI run status on the default branch and reply times on issues. The GitHub API refused our requests for the rate limit.
  • The live MCP tool definitions sit behind sign-in. The tool count of 30 is from the live docs page, and the annotations are from the repository handbook.
  • Whether audit logs are available to Formbricks Cloud customers was not found in the reviewed documentation.
  • No version or effective date was found on the terms of service page.

Sources 26

  1. docs index (llms.txt) formbricks.com · seen 2026-10-08
  2. REST API overview formbricks.com · seen 2026-10-08
  3. API key scopes and permission levels formbricks.com · seen 2026-10-08
  4. v1 OpenAPI file github.com · seen 2026-10-08
  5. v2 OpenAPI file github.com · seen 2026-10-08
  6. v3 reference introduction (private beta) github.com · seen 2026-10-08
  7. MCP overview, live formbricks.com · seen 2026-10-08
  8. MCP client setup, tokens and revocation formbricks.com · seen 2026-10-08
  9. MCP server technical handbook github.com · seen 2026-10-08
  10. MCP protected resource metadata app.formbricks.com · seen 2026-10-08
  11. OAuth authorisation server metadata app.formbricks.com · seen 2026-10-08
  12. rate limits github.com · seen 2026-10-08
  13. pricing formbricks.com · seen 2026-10-08
  14. terms of service formbricks.com · seen 2026-10-08
  15. privacy policy and sub-processors formbricks.com · seen 2026-10-08
  16. Service Level Addendum formbricks.com · seen 2026-10-08
  17. security page formbricks.com · seen 2026-10-08
  18. status page (526 error) status.formbricks.com · seen 2026-10-08
  19. security policy github.com · seen 2026-10-08
  20. security advisories github.com · seen 2026-10-08
  21. releases github.com · seen 2026-10-08
  22. release and maintenance policy github.com · seen 2026-10-08
  23. licence github.com · seen 2026-10-08
  24. npm package registry.npmjs.org · seen 2026-10-08
  25. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  26. domain registration (RDAP) rdap.org · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $74 / mo The Hobby plan is free with one workspace and 250 responses a month, lists API access including MCP, and the pricing page says no credit card is required, so an agent's owner can start without a contract. Pro is shown at $74 a month (3 workspaces, 2,000 responses) and Scale at $325 (5 workspaces, 5,000 responses), with a monthly and annual toggle and two months free on annual billing. The vendor's `llms.txt` says plans run to $390 a month, which fits $325 as the annual rate. We could not establish the billing period of the displayed figures. Custom webhooks are listed under Pro. The self-hosted Community Edition is free under AGPLv3. No sandbox or test mode was found (checked 2026-10-08).

Prices

ItemPriceUnitNote
Pro$74per month (plan)as displayed on the pricing page, billing period not established. 3 workspaces and 2,000 responses a month. The free Hobby plan includes the API
Scale$325per month (plan)as displayed on the pricing page, billing period not established. 5 workspaces and 5,000 responses a month

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/formbricks.xml, or this listing's score history at history.json.

Connect

First request

curl --location 'https://app.formbricks.com/api/v1/me' \
  --header 'x-api-key: <your-api-key>'

Claude Code

claude mcp add --transport http formbricks https://app.formbricks.com/api/mcp

MCP client configuration

{
  "mcpServers": {
    "formbricks": {
      "type": "http",
      "url": "https://app.formbricks.com/api/mcp"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/formbricks

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Tally Tally BVC60.6forms.create forms.responses forms.webhooks forms.surveys forms.embedno
Typeform Typeform SLC58.4forms.create forms.responses forms.webhooks forms.surveys forms.embedno
SurveyMonkey SurveyMonkey Inc.C55.3forms.create forms.surveys forms.responses forms.webhooks forms.embedno
Google Forms API GoogleBB70.8forms.create forms.responses forms.webhooks forms.surveysno
Paperform Paperform Pty LtdC56forms.responses forms.webhooks forms.surveys forms.embedno
Jotform Jotform Inc.D52.9forms.create forms.responses forms.webhooks forms.surveysno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Formbricks on Anchor Terminal, C, 57.7/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/formbricks"><img src="https://www.anchorterminal.com/badges/formbricks.svg" alt="Formbricks on Anchor Terminal" height="20"></a>
    [![Formbricks on Anchor Terminal](https://www.anchorterminal.com/badges/formbricks.svg)](https://www.anchorterminal.com/tools/formbricks)

    It counts on a page on formbricks.com or one of its subdomains, or the README of github.com/formbricks/formbricks.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "formbricks", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.