API and developer access
Use the QuestionPunk REST API to manage surveys and responses programmatically.
QuestionPunk provides a public REST API for survey and response workflows. Authenticate with an API key or OAuth access token, and use the documented operations and required scopes. Assistants can connect through the separate researcher MCP connection using OAuth.
Steps
- Generate an API keyGo to Settings > Developer > API Keys and click + Create API Key. Give it a name and copy the key. Store it securely: it is only shown once.
- Authenticate requestsUse
https://app.questionpunk.com/api/public/v1as the REST base URL. Send your API key or OAuth access token in theAuthorization: Bearer <token>header for authenticated operations. - Explore the APIRead the public REST OpenAPI specification for supported methods, paths, request bodies, response schemas, and required scopes. MCP tool arguments and REST request bodies use separate contracts.
- Respect rate limitsThe public REST API allows 100 requests per fixed 60-second window per client IP. Read the returned rate limit headers, and honor
Retry-Afterwhen a request returns 429.
For an assistant, follow the researcher MCP setup guide. Its canonical endpoint is https://app.questionpunk.com/api/v1; a compatible client discovers OAuth, asks you to sign in, and requests consent. This is distinct from the public REST base URL.
API keys can be created, rotated, and revoked from the Developer settings page. Select the scopes your REST integration needs, and keep credentials out of URLs and chat messages.
The public OpenAPI specification can be used to generate REST client libraries. Account permissions and operation-specific restrictions still apply.
REST responses include X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset. Keys used from the same client IP share its window; creating another key does not provide a separate IP allowance.