# Formbricks: the Qualtrics alternative that just replaced its own permission model

> An AGPL survey platform built on Next.js, Prisma and Turborepo, whose 6.0 release swaps a homegrown authorization evaluator for SpiceDB with no fallback.

**formbricks/formbricks** — Open Source Qualtrics Alternative

- Repository: https://github.com/formbricks/formbricks
- Website: https://formbricks.com
- Stars: 13,069 · Forks: 2,564
- Language: TypeScript
- License: NOASSERTION
- Published: 2026-10-06 · Updated: 2026-10-06 · Language: en
- Canonical page: https://hysenlabs.com/projects/formbricks-formbricks

## What the product claims, in its own words

The repository description is two words: Open Source Qualtrics Alternative. The README expands that into a free and open source surveying platform and, separately, a privacy-first experience management platform, with in-app, website, link and email surveys as the four surfaces.

The feature list is specific in a useful way. You build surveys in a no-code editor with several question types, start from templates described as best practice, and target surveys to specific user groups without changing application code. That last clause is the one that separates this from a generic form builder: targeting is a first class concept tied to your existing user data rather than something bolted on with query parameters.

Link surveys are the second mechanism, which is the conventional share-a-URL form. Organization members can be invited to collaborate on surveys, and there are integrations with Slack, Notion, Zapier and n8n. The closing line of that list is that everything is open source, transparent and self-hostable, and the licence is AGPLv3.

## The stack is stated plainly, and the tree confirms it

The README has a Built on Open Source section listing TypeScript, Next.js, React, TailwindCSS, Prisma, Auth.js, Zod and Vitest. That is a complete and unembellished list, and the repository tree backs it up: `apps/` for the application, `packages/` for shared code, `charts/` for Helm charts, `docker/` plus `docker-compose.dev.yml`, and `docs/`.

There is Turborepo at the top of the tree with `turbo.json`, and the root `package.json` is marked private with version 0.0.0, which is the convention for an application monorepo where versions live somewhere else. Database tooling goes through Prisma, with a `prisma.config.mjs` in the root, and there is an `openapi.yml` describing the API.

Testing is Playwright, with two configuration files, `playwright.config.ts` and `playwright.service.config.ts`, which suggests both end-to-end flows and service level checks. `sonar-project.properties` is there for static analysis, and `.husky/` with `.lintstagedrc.mjs` handles commit hooks. There is a `.coderabbit.yaml` for automated review comments.

## Version 6 swaps the authorization engine with no fallback

The 6.0.0 release, published on 2026-09-21, is the most important thing in the repository and it is not about features. The overview states that Formbricks 6.0 replaces the legacy authorization evaluator with AuthZed SpiceDB, and that SpiceDB is now the sole authorization decision engine with no runtime fallback.

That last phrase has a direct operational consequence: a self-hosted upgrade runs inside a maintenance window, and the authorization graph is prepared before traffic is served. The release also says self-hosted installations upgrade directly from a supported v5 version with no bridge release required, and it names a tested upgrade pair, 5.4.3 to 6.0.0, with an explicit warning not to upgrade from a pair that is not listed.

The maintenance policy is stated with a date: the 6.0 minor receives bug and security fixes until 21 December 2026, and after that it receives none. That is a short support window for a major version, and it is the kind of detail worth reading twice before you commit to self hosting a specific minor.

## A support cast of SpiceDB scripts in the root package.json

The scripts tell you how much of the operating story is now about SpiceDB. Seven of them carry the `authzed:` prefix: `health`, `schema`, `backfill`, `perf`, `smoke`, `validate` and `upgrade`. The TypeScript ones all run the same way, loading the environment with dotenv, forcing the react-server condition, and running a script from `apps/web/scripts/` through tsx with the app's own tsconfig.

Two of them are plain shell scripts rather than TypeScript, and those are the ones you would reach for during an upgrade:

```bash
bash authzed/validate.sh
bash docker/authzed-smoke.sh
```

There is an `authzed/` directory at the repository root to match. A `backfill` script is the giveaway about what a migration involves: replaying your existing permission data into the new graph, which is the work a maintenance window exists for. Running `validate` and `smoke` against the live SpiceDB is the closest thing in the repository to an upgrade health check.

## What the environment file demands of you

The `.env.example` is long, commented, and honest about which parts are mandatory. The header labels the first block mandatory, change according to your setup. The basics are the web app URL and an auth base URL that should match it, with a note that a custom base path means specifying the API route in full.

Then the secrets, three of them, each with a generation hint:

```bash
# You can use: `openssl rand -hex 32` to generate one
ENCRYPTION_KEY=

# Signs session cookies and every invite, verification and email-change token.
BETTER_AUTH_SECRET=

# API Secret for running cron jobs. (mandatory)
CRON_SECRET=
```

The comment on `BETTER_AUTH_SECRET` is the useful one, because it tells you exactly what that key protects: session cookies plus every invite, verification and email-change token. `LOG_LEVEL` accepts debug, info, warn, error or fatal.

Below that come the queue settings. BullMQ workers require `REDIS_URL`, worker startup is enabled by default outside tests, and there is a flag for splitting enqueueing web pods from a separate worker deployment. The database side is the last piece:

```json
"db:up": "pnpm dev:setup && docker compose -f docker-compose.dev.yml up -d",
"db:down": "docker compose -f docker-compose.dev.yml down"
```

Prerequisites for local work are Node 18 or newer, pnpm, and Docker to run PostgreSQL and MailHog. MailHog being the local mail catcher is a detail worth knowing before you wonder why invites never arrive in development.

## The 5.4 branch, and what a maintenance release looks like

Looking at 5.4.3, published on 2026-09-17, is a good way to see how the project handles a stable line. Every entry in that changelog is a backport to `release/5.4`, and each is a specific fix rather than a feature. CI now pulls MinIO images from quay.io instead of Docker Hub. Next was bumped to 16.3.3 for two critical remote code execution advisories. A response filter on the Other option is now bounded instead of permuting every subset, which is a performance fix with a clear before and after. And the Helm chart supports Gateway API v1.5 clusters.

Four patches, four different areas, no new features, in a single point release. That is the maintenance discipline you need from a project you are self hosting, and it is also the reason the 6.0 support window is short: the team is clearly running both lines in parallel.

The repository metadata shows 12,981 stars and 2,527 forks with 214 open issues, and the last push was on 2026-09-21. There is an `ACCESSIBILITY.md` at the root, which is a small sign of a product with a public-facing survey renderer that takes accessibility seriously. `docker/`, `charts/` and `.devcontainer/` alongside `.gitpod/` tell you the supported paths to a running instance are broad.

## Conclusion

Formbricks is a serious piece of infrastructure rather than a weekend survey tool, and the repository shows it. Next.js and Prisma and Postgres and Redis are the baseline, the editor is a no-code in-app surface rather than a link you paste, and version 6 puts a SpiceDB authorization graph in front of everything. The upgrade path is the thing to read first if you self host, because 6.0 has no runtime fallback and a stated support date of 21 December 2026 for the 6.0 minor. Start with the Docker self hosting docs, read the release notes for your exact version pair, and check the authzed scripts before you schedule a maintenance window.

## FAQ

### What is Formbricks and who is it for?

Formbricks is a free and open source survey and experience management platform, positioned as an alternative to Qualtrics. It supports in-app, website, link and email surveys, a no-code editor, templates, and targeting surveys at specific user groups without changing application code. The code is AGPLv3 and you can self host it with Docker.

### What does Formbricks version 6 change?

Version 6.0 replaces the legacy authorization evaluator with AuthZed SpiceDB as the sole decision engine, with no runtime fallback. Self-hosted upgrades therefore run in a maintenance window while the authorization graph is prepared. Supported v5 installations upgrade directly with no bridge release, and the 6.0 minor receives bug and security fixes until 21 December 2026.

### What stack does Formbricks use?

TypeScript, Next.js, React, TailwindCSS, Prisma and Zod, tested with Vitest and Playwright, in a Turborepo monorepo with PostgreSQL and Redis. The root package.json carries a set of AuthZed SpiceDB scripts for schema, backfill, health, performance, smoke tests and validation, and the API is described by an `openapi.yml` at the repository root.

### What environment variables does Formbricks require?

At minimum `WEBAPP_URL`, an auth base URL, and three generated secrets: `ENCRYPTION_KEY`, `BETTER_AUTH_SECRET` and `CRON_SECRET`, each produced with `openssl rand -hex 32`. `LOG_LEVEL` selects the minimum log level, and BullMQ workers need `REDIS_URL` set. There is also an optional server-side JWKS URL and a base path that can only be set at build time.

### Can I self host Formbricks without a subscription?

Yes. The project is available under the AGPLv3 licence and you can host it on your own servers using Docker without a subscription. A cloud offering also exists at formbricks.com with a free plan. For local development you need Node 18 or newer, pnpm, and Docker to run PostgreSQL and MailHog.

## Sources

- [formbricks/formbricks on GitHub](https://github.com/formbricks/formbricks)
- [Issues](https://github.com/formbricks/formbricks/issues)
- [Project website](https://formbricks.com)
- [README](https://github.com/formbricks/formbricks/blob/main/README.md)
- [Releases](https://github.com/formbricks/formbricks/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/formbricks-formbricks
