Formbricks logo

Formbricks

The Open Source Qualtrics Alternative

Alternative to: typeform, surveymonkey, qualtrics, google forms


About Versions (145)

6.0.0

2026-09-21

Overview

Formbricks 6.0 replaces the legacy authorization evaluator with AuthZed SpiceDB and ships Embedded Data V1. SpiceDB is now the sole authorization decision engine, with no runtime fallback, so a self-hosted upgrade runs inside a maintenance window and prepares its authorization graph before serving traffic.

Self-hosted installations upgrade directly from a supported v5 version — no bridge release is required. Follow Upgrade to Formbricks v6 for the procedure and Migration → v6 for the configuration changes. Tested upgrade pair for this release: — do not upgrade from a pair that is not listed here.

Under the release and maintenance policy, the 6.0 minor receives bug fixes and security fixes until 21 December 2026. After that date it receives no further fixes; move to a newer minor before then.

⚠️ Breaking changes

The upgrade procedure, prerequisites and rollback all live in Upgrade to Formbricks v6 and Migration → v6. Read those before you pull a 6.0 image. This list is the index of what changes, not the procedure.

Self-hosted deployment

  • AuthZed SpiceDB is a required dependency and the sole authorization engine; protected operations fail closed when it is unavailable (#9089).
  • Upgrades require explicit maintenance preparation; missing, disabled or weaker-consistency AuthZed settings now block server startup (#9280).
  • Production Compose requires its own POSTGRES_PASSWORD instead of the shared postgres password (#8900).
  • Bundled PostgreSQL overrides are respected: app and SpiceDB follow the effective endpoint, role and database, so PVC-backed installs with a custom postgresql.auth.username / .database must provision and migrate first (#9279).
  • Bundled Envoy CRDs move to Gateway API v1.5.1 (apply v1.8.4 CRDs first), and Envoy pod overrides move from envoy.deployment.envoyGateway.pod to envoy.deployment.pod (#9292).
  • Taxonomy deployments must declare taxonomy.llm.contextWindowTokens, select a bundled model when several are enabled, complete their provider wiring, and move reliability settings from raw taxonomy.env / hub.env keys to the named fields; the selected-record cap default drops from 50,000 to 10,000 (#8954).
  • DEFAULT_ORGANIZATION_ID and DEFAULT_ORGANIZATION_ROLE are renamed to AUTH_SSO_DEFAULT_ORGANIZATION_ID and AUTH_SSO_DEFAULT_ORGANIZATION_ROLE. Values are unchanged, and both are Enterprise SSO just-in-time provisioning only (#9157).

API and SDK contract

  • GET /api/v3/surveys: meta.hasArchived is replaced by meta.workspaceSurveyCount. On an unfiltered request, hasArchived === true becomes workspaceSurveyCount > totalCount (#8964).
  • isSingleResponsePerEmailEnabled is removed from the Survey resource on Management API v1 and v2. It never enforced anything server-side, so only the field references need removing (#8975).
  • POST /api/v3/surveys returns 422 with invalid_params instead of 500 when a body passes the request schema but fails the write schema (#8991).
  • Contact-attribute-key management endpoints on v1 and v2 now return 403 for organizations without the contacts entitlement. Entitled organizations see no change (#8955).
  • New declared embedded-data fields must match ^[a-z][a-z0-9_]*$, avoid reserved names (country, lang, …) and not collide across variables and hidden fields; existing names re-save unchanged. Response exports now use Title Case metadata headers, the full reserved catalog and numeric values (#9219).

Changed defaults and limits

  • Workspaces per organization drop from 3 to 1 without an Enterprise license, and while a Cloud license cannot be confirmed. Existing workspaces stay accessible; only creating another is blocked (#9008).
  • The organization invite quota becomes 50 recipients per organization per day, replacing 20 single invites plus 20 bulk operations (#9182).
  • When Redis rejects a session read, the request falls back to PostgreSQL and succeeds instead of returning 500 FAILED_TO_GET_SESSION. Update alerts that expect the 500 (#9125).

Coming from 5.3 or earlier

  • The bundled Valkey image moved from the Debian Valkey 8.1.1 amd64 child digest to the Alpine Valkey 8.1.9 multi-architecture index. This already shipped in 5.4.0, so it is only new to you if you are upgrading from 5.3 or earlier (#8986).

What’s Changed

🚀 Features

🐛 Fixes

🔧 Refactors

📚 Docs

⚙️ CI

🧹 Chores

🔒 Security credits

Thanks to the following researchers, who reported issues fixed in this release through responsible disclosure:

  • frandle331-yh — account pre-hijacking through autoSignInAfterVerification, where the post-verification session was handed to a browser other than the one that signed up (#8971)
  • Arthur Chan (Ada Logics), with credit owed to Google and Ada Logics — the response filter on “Other” built every permutation of every subset and aborted the Node process (#9255)

Full Changelog: https://github.com/formbricks/formbricks/compare/5.4.3…6.0.0