Get a form
/forms/{form_id}Returns one form with its JSON Schema. version goes up each time an admin publishes a change in the
form builder.
Scope: forms:read · Plan: Pro and Enterprise in live mode; every plan in test mode.
Send Authorization: Bearer <token> on every request. The token is one of:
| Prefix | What it is | Where it may be used |
|---|---|---|
agoo_sk_live_ | Secret key, live mode | Your servers only |
agoo_sk_test_ | Secret key, test mode | Your servers only |
agoo_pk_live_ | Publishable key, live mode | Browsers and apps: create pre-registrations and bookings, read public booking types (with their intake questions) and their free slots, read the visit types open for pre-registration with their public forms. Never lists people. |
agoo_pk_test_ | Publishable key, test mode | As above, in test mode |
Admins create keys in Console → Developers → API keys and choose each key's scopes. A key is shown once. Never put a secret key in a URL, a browser or a mobile app.
In: header
Scope: forms:read
Path Parameters
The form's ID.
^form_[0-7][0-9a-hjkmnp-tv-z]{25}$"form_01kk1602m0errvasw8gkt8f90b"Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X GET "https://example.com/forms/form_01kk1602m0errvasw8gkt8f90b"{ "id": "form_01kk1602m0errvasw8gkt8f90b", "name": "Contractor", "entity": "visit", "visit_type": "contractor", "version": 3, "schema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "type": "object", "properties": { "contractor_company": { "type": "string", "title": "Contracting company", "maxLength": 120 }, "work_order": { "type": "string", "title": "Work order number", "pattern": "^WO-[0-9]{5}$" }, "areas": { "type": "array", "title": "Areas needed", "items": { "enum": [ "server_room", "generator_house", "roof", "banking_hall" ] }, "uniqueItems": true }, "safety_induction_done": { "type": "boolean", "title": "Safety induction completed" } }, "required": [ "contractor_company", "work_order", "safety_induction_done" ], "additionalProperties": false }, "created_at": "2026-03-06T09:00:00Z", "updated_at": "2026-09-02T10:15:00Z"}List forms GET
Returns your organisation's active forms, each with the JSON Schema for its custom fields. There is one visit form per visit type, including the types your organisation adds, and one person form. Read them to know which `custom_fields` keys and values a visit or person accepts. `GET /visit-types` lists the types. Forms include the fields your staff fill in, so publishable keys can't read them. A pre-registration form gets the visitor's questions from the type's `public_form` in `GET /visit-types` instead. **Scope:** `forms:read` · **Plan:** Pro and Enterprise in live mode; every plan in test mode.
Register a file upload POST
Registers a file and returns a presigned URL to upload it to. Files never pass through the API: send the bytes with `PUT` to `upload.url`, with exactly the headers in `upload.headers`, within five minutes. Then use the file's ID where a record takes one, for example `selfie_file_id` on a clock-in. | `kind` | Content types | Up to | | ---------------- | ----------------------------------------- | ------ | | `visitor_photo` | `image/jpeg`, `image/png`, `image/webp` | 5 MB | | `id_image` | `image/jpeg`, `image/png`, `image/webp` | 10 MB | | `signature` | `image/png` | 1 MB | | `selfie` | `image/jpeg`, `image/webp` | 5 MB | | `delivery_photo` | `image/jpeg`, `image/png`, `image/webp` | 10 MB | | `document` | `application/pdf` | 20 MB | | `badge` | `application/pdf`, `image/png` | 5 MB | - The storage refuses an upload of another type or size, or after the link expires. Register the file again to get a new link. - After the upload, Agoo removes the photo's metadata (EXIF, including any GPS location), checks that the content matches its type and makes a thumbnail for photos. The file's `status` then changes from `pending` to `ready`, usually within seconds. A file whose content doesn't match its type is deleted. - A file that is never uploaded is deleted after a day. ID images, visitor photos and selfies are deleted on your organisation's retention schedule. - `selfie` needs selfie evidence switched on in your attendance settings; otherwise you get `validation_failed` at `body.kind`. **Scope:** `files:write` · **Plan:** Pro and Enterprise in live mode; every plan in test mode.