Values you need
Every example in these docs uses a placeholder rather than a real value. This page is the lookup table: what each one means, where to get it, and what shape to expect.
Looking for the steps instead?Quick Start walks through getting a token, creating an application and receiving the webhook.
Placeholder conventions
Section titled “Placeholder conventions”Two styles appear, for two different reasons.
| Style | Where it appears | Example |
|---|---|---|
{braces} |
URL paths and prose, matching the OpenAPI path template | /{lang}/api/forms/{form_slug}/create/ |
YOUR_UPPER_CASE |
inside example payloads and example URLs | "slug": "YOUR_APPLICATION_SLUG" |
$ENV_VAR |
runnable code samples | Bearer $UPPASS_API_TOKEN |
The split exists because { and } are not legal URI characters, so a brace
placeholder cannot sit inside a URL that is also validated as one. Substitute the
same real value for either style.
Where each value comes from
Section titled “Where each value comes from”| Placeholder | What it is | Where to find it |
|---|---|---|
{api_token}$UPPASS_API_TOKEN |
Bearer token authenticating every API call | Portal → your workspace → API Token (left-hand menu). Step by step: Create an application → Before you start |
{form_slug}YOUR_FORM_SLUG |
Programmatic name of one flow | Portal → Flows → your flow → Settings |
{workspace}YOUR_WORKSPACE |
Workspace slug, used in dashboard URLs only | Workspace selector in the Portal, or the workspace= query parameter in any dashboard URL |
{lang} |
UI locale for the generated form | You choose it. See supported locales |
{slug}YOUR_APPLICATION_SLUG |
Identifier of one applicant’s application | Returned as detail.slug by Create application. Store it against your own record. |
{webhook_secret} |
Bearer secret UpPass sends on every webhook | You choose it, in Portal → Connect → Add Webhook |
https://your-server.example/... |
Your own HTTPS webhook receiver, shown with an illustrative host in the API reference | You provide it, in Portal → Connect → Add Webhook |
Shapes, so you can tell them apart
Section titled “Shapes, so you can tell them apart”Useful when reading logs. None of these are real values.
| Value | Shape |
|---|---|
| Form slug | You name it when you create the flow. Any slug that is unique in your workspace. |
Application slug (slug) |
An 8–32 character alphanumeric string, minted by the create call |
| Webhook nonce | An alphanumeric string, unique per delivery — not per application |
Sample data in the examples
Section titled “Sample data in the examples”Example payloads carry synthetic values so you can run them without touching real records.
| Field | Example value | Note |
|---|---|---|
nid |
1111111111119 |
Checksum-valid Thai national ID, synthetic. Use it in fixtures. |
nid (invalid) |
1234567890123 |
Fails the check digit — used to demonstrate the 422. |
document_number |
AB0000001 |
Passport number, synthetic. |
| Applicant name | Somchai Jaidee |
Placeholder, equivalent to “Jane Doe”. |
transaction_id |
TXN-0001 |
Your own reference. Only kept if declared under Form → Builder → Input Parameter; otherwise silently dropped. |
company_id |
CMP-0001 |
Same rule — declare it as an input parameter or it is dropped. |
Environment file
Section titled “Environment file”Keep the values in environment variables rather than in code. A template:
UPPASS_API_TOKEN=UPPASS_FORM_SLUG=UPPASS_WORKSPACE=
UPPASS_HOST=https://app.uppass.ioUPPASS_LANG=en