Skip to main content
ConfigView reads your Typeform account through Typeform’s API, using a personal access token created by the person who owns your Typeform account. You will end up with 1 secret in ConfigView (TYPEFORM_API_TOKEN), plus TYPEFORM_BASE_URL if your Typeform responses are stored in the EU.
Scope of this integration today. ConfigView shows where Typeform sends your form responses: every webhook that posts answers to Zapier, Make, a CRM, a company server or anywhere else, by destination. It also lists who owns and can open each shared workspace, outside people with access, and which forms are public. ConfigView only reads. It never reads form titles, questions or answers.
What Typeform’s API cannot show. Typeform has no account-wide admin API. A token sees only the workspaces its creator can open. The account owner can open every shared workspace, but nobody, not even the owner, can see another member’s private “My workspace” through the API. Forms someone keeps in their own private workspace, and any webhooks on them, are therefore not visible to ConfigView. Typeform’s API also has no list of the account’s seats, no audit log and no list of the built-in integrations (the Google Sheets, HubSpot or Slack connections set up from a form’s Connect tab). Only webhooks are visible.

Step 1: Open the Typeform page in ConfigView

Open ConfigView in a second browser tab and leave it open: https://{companyname}.configview.com/admin/integrations/typeform Typeform shows the token once, when you create it, so paste it straight into ConfigView instead of keeping it in a notes file.

Step 2: Create a personal access token in Typeform

Sign in as the owner of the Typeform account. A token has the same view as the person who creates it, so a member’s token sees only the workspaces shared with that member.
  1. In Typeform, open the menu next to your name (top left) and click Account
  2. In the left menu, click Personal tokens
  3. Click Generate a new token and name it ConfigView
  4. Under scopes, tick only:
    • Workspaces: Read (workspaces:read)
    • Forms: Read (forms:read)
    • Webhooks: Read (webhooks:read)
    • Accounts: Read (accounts:read) is optional. It lets the health check name whose token it is
  5. Do not tick Responses: Read. ConfigView never reads answers, and that scope would let the token read all of them
  6. Click Generate token, then copy the token. It starts with tfp_
  7. Paste it into TYPEFORM_API_TOKEN in ConfigView and click the save icon
EU data center. If your account stores responses in the EU, also save TYPEFORM_BASE_URL as https://api.eu.typeform.com. Accounts on Typeform’s newer EU data center use https://api.typeform.eu instead. If you are not sure, your Typeform Customer Success Manager can tell you. Leave it empty otherwise. Who owns the token matters. The token stops working if the person who created it leaves Typeform or deletes or regenerates it. To revoke ConfigView’s access, delete the token on the same Personal tokens page. Plans. The API works on every Typeform plan. Shared workspaces and webhooks need a paid plan, so on a free plan there is little to see.

Step 3: Connect and verify

  1. Back on https://{companyname}.configview.com/admin/integrations/typeform, confirm the credential shows as saved
  2. Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
  1. Click Verify now. The health check confirms the secret, lists the workspaces the token can see (and warns if none of them is shared, which means the token does not belong to the account owner), names the token’s owner when accounts:read was ticked, and reads the forms and one form’s webhooks.
If a check fails:
  • 401. The token is wrong, was deleted or regenerated, its owner has left Typeform, or your account is in the EU data center and TYPEFORM_BASE_URL is not set.
  • 403 naming a scope. The token was created without that scope. Typeform cannot add scopes to an existing token. Generate a new one with the scopes above.
  • “none is shared”. The token belongs to someone who sees only their own private workspace. Generate it as the account owner.
  • 429. Typeform’s limit of two requests a second for your account is spent for now, usually by another API client. The next run will be fine.

Data Tables

Once the scripts run, these tables are created in your database. Each includes a run_at column and keeps only the newest run. role is the person’s role in that workspace: owner or member. Typeform’s API has no list of the account’s users, so a person appears once per workspace they can open. Someone whose only workspace is their own private one does not appear at all. destination_host is the host part of the webhook’s URL only (for example hooks.zapier.com). The rest of the URL often contains a secret key that lets anyone post to the receiving end, so ConfigView drops it. event_types lists what triggers the webhook. form_response fires when someone submits a form. form_response_partial also sends half-finished answers. url_scheme is http for older webhooks that still send answers without encryption. Typeform has refused new http webhooks since May 2026, but existing ones keep working.

Things worth knowing

Response counts are not collected. Typeform only reports how many responses a form has through its Responses API, and the scope that allows that (responses:read) also allows reading every answer. ConfigView does not ask for it. A workspace whose owner has left keeps working. Its forms keep accepting answers and its webhooks keep sending them out. The catalog question “People who have left but still have Typeform workspace access” finds these by comparing workspace members with Okta and Google Workspace. Large accounts. The webhook list is read one form at a time, within Typeform’s limit of two requests a second. An account with about 1,000 forms takes around 12 minutes. Above about 2,400 forms the Webhooks run stops before writing anything, so the previous complete list stays in place.

What isn’t collected

  • Form titles, questions, logic, themes and links
  • Responses and the files people upload
  • Response counts (they need a scope that can read the answers)
  • The full webhook URL and the webhook signing secret
  • Members’ private workspaces, which Typeform’s API does not show to anyone else