A small, honest REST API to read feedback, and signed webhooks to react to it in real time. No SDK required — it's just HTTP.
Every request is authenticated with a bearer token you create in your dashboard.
Head to Settings → Developers and create a key. It looks like fdb_live_ab12… and is shown in full only once — copy it right away and store it somewhere safe. If you lose it, revoke it and create a new one.
GET /api/v1/feedback returns your feedback, newest first, with cursor pagination.
Send your key as a bearer token in the Authorization header.
curl -H "Authorization: Bearer fdb_live_…" \
https://feedb.co/api/v1/feedbackQuery params: limit (1–100, default 25) and cursor (an item id to page after). Requests are rate-limited to 60 per minute.
A JSON object with a data array and a next_cursor (null when you've reached the end).
{
"data": [
{
"id": "clx…",
"rating": 5,
"category": "product",
"content": "Loved the onboarding flow.",
"type": "PRAISE",
"sentiment": "positive",
"created_at": "2026-07-16T09:12:04.000Z"
}
],
"next_cursor": "clx…"
}To page, pass the returned next_cursor as the cursor param on your next request until it comes back null.
Register an HTTPS endpoint and FeedB POSTs a signed JSON payload whenever new feedback arrives.
Add an endpoint under Settings → Developers. You'll get a signing secret that looks like whsec_…. An endpoint that fails 10 times in a row is automatically disabled — re-enable it after you've fixed it.
Every delivery is a POST with headers X-FeedB-Event and X-FeedB-Signature.
{
"event": "feedback.created",
"createdAt": "2026-07-16T09:12:04.000Z",
"data": {
"id": "clx…",
"rating": 5,
"content": "Loved the onboarding flow."
}
}The X-FeedB-Signature header is sha256= followed by the HMAC-SHA256 of the raw request body, keyed with your webhook secret. Recompute it and compare — reject the request if it doesn't match.
import { createHmac, timingSafeEqual } from 'crypto';
function verify(rawBody, header, secret) {
const expected =
'sha256=' + createHmac('sha256', secret).update(rawBody).digest('hex');
const a = Buffer.from(header || '');
const b = Buffer.from(expected);
return a.length === b.length && timingSafeEqual(a, b);
}Always hash the raw bytes of the body, before any JSON parsing — reserializing can change whitespace and break the comparison.
Create a key and your first webhook from your dashboard settings.
Go to Developer settings