Build
Google Forms guide
An Apps Script trigger rewards each response, no server of your own.
How it fits together
Google Forms runs Apps Script on each response, on Google's servers, so you need no server of your own: the script
calls POST /rewards with a restricted key kept in the script's properties. Apps Script is a server, not a
browser, so the key is not exposed to respondents.
- Make a program and a restricted key with only
rewards:write. - Add a short-answer question for the mobile number.
- In the form, open Extensions → Apps Script, paste the script below, and in
Project Settings → Script Properties set
JUSA_KEYandJUSA_PROGRAM. - Add an installable trigger: Triggers → Add trigger → onSubmit, event From form, On form submit.
The script
function onSubmit(e) { var props = PropertiesService.getScriptProperties(); var answers = {}; e.response.getItemResponses().forEach(function (r) { answers[r.getItem().getTitle()] = r.getResponse(); }); var id = e.response.getId(); // unique per response var res = UrlFetchApp.fetch('https://jusa.localhost.co.zw/dev/v1/rewards', { method: 'post', contentType: 'application/json', headers: { Authorization: 'Bearer ' + props.getProperty('JUSA_KEY'), 'Idempotency-Key': 'gform-' + id, }, payload: JSON.stringify({ program: props.getProperty('JUSA_PROGRAM'), recipient: { phone: answers['Mobile number'] }, // your question's title completion_id: id, }), muteHttpExceptions: true, }); if (res.getResponseCode() >= 500) throw new Error('Jusa unavailable; will retry'); console.log(res.getResponseCode(), res.getContentText()); }
- The response id is the
completion_id: an edited or re-run response is still one reward. - A 4xx (a cap, a bad number) is logged and final. A thrown error shows in the trigger's executions for you to rerun.
- Want no key at all in the script? Sign the body with the program's completions secret instead and post to
/programs/{id}/completions:Utilities.computeHmacSha256Signature(t + '.' + body, secret), hex-encoded, inJusa-Signature: t=…,v1=….