> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.pinnacle.sh/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.pinnacle.sh/_mcp/server.

# List Form Submissions

POST https://api.pinnacle.sh/forms/{id}/submissions/list
Content-Type: application/json

Paginated list of completed submissions for a form, newest first. Each row includes the submitted `data` keyed by field `key`, the sender/recipient, IP, user-agent, and timestamps.


Reference: https://docs.pinnacle.sh/api-reference/forms/list-form-submissions

## Authentication

- `PINNACLE-API-KEY` header (required) — API Key authentication via header

## Request

### Path parameters

- `id` (string, required) — The unique identifier of the form whose submissions you want to list. &#x20;This identifier is a string that always begins with the prefix `form_`, for example: `form_Oy2n7iUoi9CJwUU6`.

### Body (application/json)

This endpoint expects a ListFormSubmissionsRequest.

- `pageIndex` (integer, optional, default: 0) — Zero-based page index.
- `pageSize` (integer, optional, default: 20) — Number of submissions to return in a single page. Max 100.

## Response

### 200

Paginated list of submissions.

- `data` (list of FormSubmission, required) — Submissions on this page, newest first.
- `hasMore` (boolean, required) — True if there are more pages after this one. Fetch the next page by incrementing `pageIndex`.
- `count` (integer, required) — Number of submissions returned in `data`.

## Errors

### 400 Bad Request Error

Validation failed. The payload has missing required fields and/or invalid types.&#x20; See [https://zod.dev/error-formatting](https://zod.dev/error-formatting) for more information.

- `description` (string, required) — Human-readable summary of validation failures.
- `errors` (ZodErrorErrors, required) — Structured dictionary of issues containing two main sections: - `errors`: Array of global validation errors not tied to specific fields - `properties`: Object mapping field names to their specific validation errors, where each field contains an `errors` array

### 401 Unauthorized Error

The request lacks valid authentication credentials or the provided credentials are invalid.&#x20; Ensure you're including a valid API key in the request headers and that your account has the necessary permissions to access this endpoint.

- `error` (string, required) — Human-readable description of the error that occurred, corresponding to the HTTP status code.

### 404 Not Found Error

The requested resource could not be found.&#x20; This may occur if the identifier is incorrect, the resource has been deleted, or you don't have permission to access it.

- `error` (string, required) — Human-readable description of the error that occurred, corresponding to the HTTP status code.

### 500 Internal Server Error

An unexpected error occurred on Pinnacle's servers while processing your request.&#x20; If this error persists, please contact support with the request details.

- `error` (string, required) — Human-readable description of the error that occurred, corresponding to the HTTP status code.

## Types

### FormSubmission

A single submission against a form.

- `id` (string, required) — Submission id (starts with `fsub_`).
- `url` (string, required) — Public submission URL (`https://forms.pinnacle.sh/{submission_id}`) — the unguessable credential used by the recipient to fill out the form.
- `form_id` (string, required) — Id of the form this submission belongs to (starts with `form_`).
- `from` (string, required, nullable) — Sender identifier — E.164 phone number or RCS agent id. Null if the sender could no longer be resolved (e.g. the phone number or agent was deleted after the submission).
- `to` (string, required, nullable) — Recipient phone number (E.164). Null for URL-only sends (`to` was omitted at send time).
- `data` (map from string to any, required, nullable) — Submitted answers keyed by field `key`. Null if the submission has not been completed yet. Each value's shape depends on the field type: - `text`, `email`, `phone`, `url`, `textarea`, `select`, `radio` → string - `number` → number - `checkbox` (single) → boolean - `checkbox` (multi), `multiselect` → array of strings - Skipped optional field → null
- `ip_address` (string, required, nullable) — IP address the submission was POSTed from. Null for pending submissions.
- `user_agent` (string, required, nullable) — User-Agent header of the browser that submitted the form. Null for pending submissions.
- `submitted_at` (string, required, nullable) — Timestamp of completion. Null for pending submissions; updated on each edit of a `can_update=true` submission.
- `created_at` (string, required) — Timestamp of when the submission URL was minted.

### ZodErrorErrors

Structured dictionary of issues containing two main sections: - `errors`: Array of global validation errors not tied to specific fields - `properties`: Object mapping field names to their specific validation errors, where each field contains an `errors` array

## Examples

**Request**

```json
{
  "pageIndex": 0,
  "pageSize": 20
}
```

**Response**

```json
{
  "data": [
    {
      "id": "fsub_T17R9JjWSCnc2MDQ",
      "url": "https://forms.pinnacle.sh/fsub_T17R9JjWSCnc2MDQ",
      "form_id": "form_Oy2n7iUoi9CJwUU6",
      "from": "agent_iM9wQcyBBjYn",
      "to": "+14155551234",
      "data": {
        "full_name": "Ada Lovelace",
        "email": "ada@example.com",
        "plan": "pro"
      },
      "ip_address": "203.0.113.45",
      "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15",
      "submitted_at": "2026-04-23T22:15:04.406Z",
      "created_at": "2026-04-23T22:10:00.000Z"
    }
  ],
  "hasMore": false,
  "count": 1
}
```

**SDK Code**

```python First page
import requests

url = "https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list"

payload = {
    "pageIndex": 0,
    "pageSize": 20
}
headers = {
    "PINNACLE-API-KEY": "<apiKey>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript First page
const url = 'https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list';
const options = {
  method: 'POST',
  headers: {'PINNACLE-API-KEY': '<apiKey>', 'Content-Type': 'application/json'},
  body: '{"pageIndex":0,"pageSize":20}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go First page
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list"

	payload := strings.NewReader("{\n  \"pageIndex\": 0,\n  \"pageSize\": 20\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("PINNACLE-API-KEY", "<apiKey>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby First page
require 'uri'
require 'net/http'

url = URI("https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["PINNACLE-API-KEY"] = '<apiKey>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"pageIndex\": 0,\n  \"pageSize\": 20\n}"

response = http.request(request)
puts response.read_body
```

```java First page
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list")
  .header("PINNACLE-API-KEY", "<apiKey>")
  .header("Content-Type", "application/json")
  .body("{\n  \"pageIndex\": 0,\n  \"pageSize\": 20\n}")
  .asString();
```

```php First page
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list', [
  'body' => '{
  "pageIndex": 0,
  "pageSize": 20
}',
  'headers' => [
    'Content-Type' => 'application/json',
    'PINNACLE-API-KEY' => '<apiKey>',
  ],
]);

echo $response->getBody();
```

```csharp First page
using RestSharp;

var client = new RestClient("https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list");
var request = new RestRequest(Method.POST);
request.AddHeader("PINNACLE-API-KEY", "<apiKey>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"pageIndex\": 0,\n  \"pageSize\": 20\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift First page
import Foundation

let headers = [
  "PINNACLE-API-KEY": "<apiKey>",
  "Content-Type": "application/json"
]
let parameters = [
  "pageIndex": 0,
  "pageSize": 20
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.pinnacle.sh/forms/form_Oy2n7iUoi9CJwUU6/submissions/list")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```