FormLynk API
Connect your forms. Send anywhere.
A high-performance, secure backend for forms hosted on static and frontend-only websites (Next.js, React, Vue, Svelte, static HTML, WordPress, Shopify). All form submissions are validated server-side, checked for spam, persisted in database records, and dispatched asynchronously through email queues and webhooks.
Multi-Tenant Architecture & Plan Quotas
FormLynk is a multi-tenant platform where developers, agencies, and companies manage their form backends in isolated workspaces. Every user can register a free account to immediately receive an API key and starter endpoint.
Free Tier
Included- 1 Workspace Project
- 1 Form Endpoint with Field Builder
- 1 Scoped API Key
- Submitter Auto-Replies & Honeypot Spam Trap
- Global SMTP Notification Dispatch
Pro & Enterprise
Unlimited- Unlimited Workspace Projects
- Unlimited Form Endpoints & Custom Schemas
- Unlimited Public & Private API Keys
- Dedicated Project SMTP (SendGrid, Postmark, AWS SES)
- Real-time HMAC Webhooks & CSV Exports
Authentication
All requests to the submission endpoint must authenticate using an API key generated in your project dashboard. Supply the key in the X-API-Key header or as a Bearer token.
# Header Format 1 (Recommended):
X-API-Key: pk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxx
# Header Format 2 (Authorization Bearer):
Authorization: Bearer pk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxx
Domains & CORS Origin Protection
Browser public keys (pk_live_...) enforce strict origin matching. Add your frontend domains (e.g. https://example.com, http://localhost:3000) to your project in the dashboard.
Submits form data. Accepts both application/json and multipart/form-data (required for file uploads).
{
"form_id": "contact",
"name": "Jane Doe",
"email": "jane@example.com",
"phone": "+15551234567",
"subject": "Inquiry about enterprise plans",
"message": "Hello, we would like to evaluate your software for our team.",
"_gotcha": ""
}
{
"success": true,
"message": "Your message has been submitted successfully.",
"submission_id": "sub_8f92ab31c4e2"
}
File Uploads
To attach resumes, documents, or photos, configure a field with type file in the Form Builder, and submit your form using multipart/form-data or standard JavaScript FormData. Uploaded files are stored securely outside public web roots and sent as attachments to your notification email.
Honeypot & Bot Shield
Include a hidden honeypot input in your frontend form (default: _gotcha). Human users will not see or fill it, but automated spam bots will fill it out and be silently trapped and blocked.
Idempotency Protection
Prevent accidental duplicate submissions caused by network retries or double-clicks by passing a unique Idempotency-Key header:
Error Codes & Statuses
| Code | HTTP Status | Description |
|---|---|---|
| INVALID_API_KEY | 401 Unauthorized | Missing, revoked, or invalid API key. |
| INVALID_ORIGIN | 403 Forbidden | Request Origin domain is not whitelisted for this project. |
| FORM_NOT_FOUND | 404 Not Found | Specified form_id was not found or is paused. |
| VALIDATION_ERROR | 422 Unprocessable | Input validation failed; includes detailed fields errors. |
| RATE_LIMIT_EXCEEDED | 429 Too Many Requests | Rate limit triggered. Returns Retry-After header. |
Webhooks & HMAC-SHA256 Verification
Webhooks dispatch JSON payloads accompanied by a signature header X-Webhook-Signature. Verify it in Node.js or Python using your webhook secret:
// Node.js Webhook Signature Verification
const crypto = require("crypto");
function verifySignature(rawBody, signatureHeader, secret) {
const hash = crypto.createHmac("sha256", secret).update(rawBody).digest("hex");
return crypto.timingSafeEqual(Buffer.from(hash), Buffer.from(signatureHeader));
}