A valid request URL is required to generate request examples{
"surveys": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"kind": "nps",
"question": "<string>",
"active": true,
"cooldown_days": 123,
"segment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"triggers": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"kind": "days_after_created",
"event_type": "<string>",
"days": 123,
"period": "month"
}
],
"created_by": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"event_types": [
"<string>"
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}List surveys
Requires engagement:manage — reads included, like the changelog and onboarding. What you ask your users and what they answered is your own copy, and no wider permission shows any of it.
Inactive surveys are listed and marked: one still being written is exactly what this screen is opened to finish. Every survey comes back with its triggers.
event_types is the vocabulary an event trigger may wait on, derived from the facts this system actually publishes about a person. It travels on the read rather than being hard-coded in a screen, so a screen cannot go on offering a type the API stopped accepting.
A valid request URL is required to generate request examples{
"surveys": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"environment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"kind": "nps",
"question": "<string>",
"active": true,
"cooldown_days": 123,
"segment_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"triggers": [
{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"kind": "days_after_created",
"event_type": "<string>",
"days": 123,
"period": "month"
}
],
"created_by": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}
],
"event_types": [
"<string>"
]
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}{
"error": {
"code": "forbidden",
"message": "your role does not allow this action"
}
}Authorizations
A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange. Only a 401 means it is spent; not_a_member (403) is about the organization named in X-Organization-Id and leaves the token good for the others.
Headers
The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing: the answer is not_a_member (403), which does not mean the session is over. Absent, the session's default organization answers, or — if that membership was revoked while the session was open — any other one the caller still holds.
Query Parameters
Which environment to act in. A view parameter, valid only on the staff surface — a machine credential never chooses its environment, it is resolved from the key.
live, test