Create an application
An application is one applicant’s run through one flow. Creating it is a single call, and it returns the URL you hand to the applicant.
Before you start: get an API token
Section titled “Before you start: get an API token”Every call carries a bearer token that belongs to your workspace.
-
Open the Portal and select your workspace.
-
In the left-hand menu, open API Token.
-
Generate a token. It is shown once — copy it now.
-
Store it in your secret manager, and expose it to your backend as an environment variable:
Terminal window export UPPASS_API_TOKEN='...'
Keep it server-side only — never in browser or mobile-app code. See Authentication for the 401 / 403 behaviour.
The call
Section titled “The call”curl --request POST \ 'https://app.uppass.io/en/api/forms/{form_slug}/create/' \ --header 'Authorization: Bearer '"$UPPASS_API_TOKEN" \ --header 'Content-Type: application/json' \ --data '{ "answers": {} }'const res = await fetch(`https://app.uppass.io/en/api/forms/${FORM_SLUG}/create/`, { method: 'POST', headers: { Authorization: `Bearer ${process.env.UPPASS_API_TOKEN}`, 'Content-Type': 'application/json', }, body: JSON.stringify({ answers: {} }),});
// 201 Created — not 200.const { detail, form_url } = await res.json();res = requests.post( f"https://app.uppass.io/en/api/forms/{FORM_SLUG}/create/", headers={ "Authorization": f"Bearer {os.environ['UPPASS_API_TOKEN']}", "Content-Type": "application/json", }, json={"answers": {}}, timeout=30,)res.raise_for_status() # 201 Created on successbody = res.json(){ "info": "https://app.uppass.io/en/api/forms/{form_slug}/applied-forms/{slug}/info/", "detail": { "form": "{form_slug}", "step": "personal", "section": "personal", "submitted_at": null, "slug": "{slug}" }, "form_url": "https://app.uppass.io/en/form/{form_slug}/{slug}/"}Three things to note in the response
Section titled “Three things to note in the response”-
The status is
201, not200. A client asserting200fails on every successful create. -
detail.slugis your correlation key — store it now. It comes back in the webhook asapplication.slug, and nothing else reliably ties the result to your record. -
stepandsectionare flow-specific. Read them from the response; do not hard-code them. They are whatever the first step of your flow happens to be.
Hand the applicant the link
Section titled “Hand the applicant the link”Send the applicant to form_url. The verification experience is mobile web only — a
desktop visitor is prompted to switch devices, so if your own journey starts on desktop,
present the link as a QR code rather than a redirect that dead-ends.
Then wait for the submission webhook. Polling is for progress indicators, not for driving business logic.
Language
Section titled “Language”The {lang} path segment sets the locale the form renders in. It accepts en, th,
zh-hans, zh-hant, km, my, lo, ms, vi, id, ja, hi, ar, ru, de,
es and fr.
- Authentication — the API token, and what the slug is for.
- Set up your workspace — the Portal steps to complete once.
- Reading the result — before you write decision logic.