Build

Google Forms guide

An Apps Script trigger rewards each response, no server of your own.

How it fits together

Google Forms runs Apps Script on each response, on Google's servers, so you need no server of your own: the script calls POST /rewards with a restricted key kept in the script's properties. Apps Script is a server, not a browser, so the key is not exposed to respondents.

  1. Make a program and a restricted key with only rewards:write.
  2. Add a short-answer question for the mobile number.
  3. In the form, open Extensions → Apps Script, paste the script below, and in Project Settings → Script Properties set JUSA_KEY and JUSA_PROGRAM.
  4. Add an installable trigger: Triggers → Add trigger → onSubmit, event From form, On form submit.

The script

function onSubmit(e) {
  var props = PropertiesService.getScriptProperties();
  var answers = {};
  e.response.getItemResponses().forEach(function (r) {
    answers[r.getItem().getTitle()] = r.getResponse();
  });
  var id = e.response.getId();                        // unique per response
  var res = UrlFetchApp.fetch('https://jusa.localhost.co.zw/dev/v1/rewards', {
    method: 'post',
    contentType: 'application/json',
    headers: {
      Authorization: 'Bearer ' + props.getProperty('JUSA_KEY'),
      'Idempotency-Key': 'gform-' + id,
    },
    payload: JSON.stringify({
      program: props.getProperty('JUSA_PROGRAM'),
      recipient: { phone: answers['Mobile number'] },     // your question's title
      completion_id: id,
    }),
    muteHttpExceptions: true,
  });
  if (res.getResponseCode() >= 500) throw new Error('Jusa unavailable; will retry');
  console.log(res.getResponseCode(), res.getContentText());
}
  • The response id is the completion_id: an edited or re-run response is still one reward.
  • A 4xx (a cap, a bad number) is logged and final. A thrown error shows in the trigger's executions for you to rerun.
  • Want no key at all in the script? Sign the body with the program's completions secret instead and post to /programs/{id}/completions: Utilities.computeHmacSha256Signature(t + '.' + body, secret), hex-encoded, in Jusa-Signature: t=…,v1=….