FormLynk
Sign In
REST API Reference

FormLynk API

Connect your forms. Send anywhere.

A high-performance, secure backend for forms hosted on static and frontend-only websites (Next.js, React, Vue, Svelte, static HTML, WordPress, Shopify). All form submissions are validated server-side, checked for spam, persisted in database records, and dispatched asynchronously through email queues and webhooks.

Multi-Tenant Architecture & Plan Quotas

FormLynk is a multi-tenant platform where developers, agencies, and companies manage their form backends in isolated workspaces. Every user can register a free account to immediately receive an API key and starter endpoint.

Free Tier

Included
  • 1 Workspace Project
  • 1 Form Endpoint with Field Builder
  • 1 Scoped API Key
  • Submitter Auto-Replies & Honeypot Spam Trap
  • Global SMTP Notification Dispatch

Pro & Enterprise

Unlimited
  • Unlimited Workspace Projects
  • Unlimited Form Endpoints & Custom Schemas
  • Unlimited Public & Private API Keys
  • Dedicated Project SMTP (SendGrid, Postmark, AWS SES)
  • Real-time HMAC Webhooks & CSV Exports

Authentication

All requests to the submission endpoint must authenticate using an API key generated in your project dashboard. Supply the key in the X-API-Key header or as a Bearer token.

# Header Format 1 (Recommended):

X-API-Key: pk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxx

# Header Format 2 (Authorization Bearer):

Authorization: Bearer pk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxx

Domains & CORS Origin Protection

Browser public keys (pk_live_...) enforce strict origin matching. Add your frontend domains (e.g. https://example.com, http://localhost:3000) to your project in the dashboard.

POST https://formlynk.com/api/v1/forms/submit

Submits form data. Accepts both application/json and multipart/form-data (required for file uploads).

Request Body (JSON)
{
  "form_id": "contact",
  "name": "Jane Doe",
  "email": "jane@example.com",
  "phone": "+15551234567",
  "subject": "Inquiry about enterprise plans",
  "message": "Hello, we would like to evaluate your software for our team.",
  "_gotcha": ""
}
Response 200 OK (Success)
{
  "success": true,
  "message": "Your message has been submitted successfully.",
  "submission_id": "sub_8f92ab31c4e2"
}

File Uploads

To attach resumes, documents, or photos, configure a field with type file in the Form Builder, and submit your form using multipart/form-data or standard JavaScript FormData. Uploaded files are stored securely outside public web roots and sent as attachments to your notification email.

Honeypot & Bot Shield

Include a hidden honeypot input in your frontend form (default: _gotcha). Human users will not see or fill it, but automated spam bots will fill it out and be silently trapped and blocked.

<input type="text" name="_gotcha" style="display:none !important;" tabindex="-1" autocomplete="off">

Idempotency Protection

Prevent accidental duplicate submissions caused by network retries or double-clicks by passing a unique Idempotency-Key header:

Idempotency-Key: 7b84c3e2-9d41-4c12-850f-2b1029c78d5e

Error Codes & Statuses

Code HTTP Status Description
INVALID_API_KEY 401 Unauthorized Missing, revoked, or invalid API key.
INVALID_ORIGIN 403 Forbidden Request Origin domain is not whitelisted for this project.
FORM_NOT_FOUND 404 Not Found Specified form_id was not found or is paused.
VALIDATION_ERROR 422 Unprocessable Input validation failed; includes detailed fields errors.
RATE_LIMIT_EXCEEDED 429 Too Many Requests Rate limit triggered. Returns Retry-After header.

Webhooks & HMAC-SHA256 Verification

Webhooks dispatch JSON payloads accompanied by a signature header X-Webhook-Signature. Verify it in Node.js or Python using your webhook secret:

// Node.js Webhook Signature Verification
const crypto = require("crypto");

function verifySignature(rawBody, signatureHeader, secret) {
  const hash = crypto.createHmac("sha256", secret).update(rawBody).digest("hex");
  return crypto.timingSafeEqual(Buffer.from(hash), Buffer.from(signatureHeader));
}