Formboost API Guide — Submit Forms from Any Language
Submit form data via JSON POST and configure endpoints. Reserved fields, status codes and error names, with JavaScript, Python and cURL examples.
Formboost works with plain HTML forms, and the same endpoint accepts a JSON POST from any language. This guide covers programmatic submission, the reserved fields, the response shapes and the error codes — plus what the endpoint deliberately does not do.
Key takeaways
POST /f/{alias}is the only public endpoint, and it accepts JSON or form-encoded bodies.- A JSON client gets
202; an HTML form post gets a302to your_redirecttarget.- Errors carry a stable
UPPER_SNAKE_CASEnameplus ahint, so branch on the code, not the message.- There is no API for reading submissions back — push them out with a webhook instead.
Submitting a Form
Send a POST request to your endpoint URL:
POST https://formboost.app/f/YOUR_ENDPOINT_ID
JSON Submission
1const res = await fetch("https://formboost.app/f/YOUR_ENDPOINT_ID", {
2 method: "POST",
3 headers: { "Content-Type": "application/json" },
4 body: JSON.stringify({
5 name: "Jane Smith",
6 email: "jane@example.com",
7 message: "Hello, I'd like to learn more.",
8 }),
9});
10
11if (res.ok) {
12 console.log("Submitted");
13} else {
14 console.error("Failed:", res.status);
15}FormData Submission (HTML-style)
1const formData = new FormData();
2formData.append("name", "Jane Smith");
3formData.append("email", "jane@example.com");
4formData.append("message", "Hello!");
5
6await fetch("https://formboost.app/f/YOUR_ENDPOINT_ID", {
7 method: "POST",
8 body: formData,
9});cURL
1curl -X POST https://formboost.app/f/YOUR_ENDPOINT_ID \
2 -H "Content-Type: application/json" \
3 -d '{"name": "Jane Smith", "email": "jane@example.com", "message": "Hello"}'Python (requests)
1import requests
2
3response = requests.post(
4 "https://formboost.app/f/YOUR_ENDPOINT_ID",
5 json={
6 "name": "Jane Smith",
7 "email": "jane@example.com",
8 "message": "Hello",
9 }
10)
11
12print(response.status_code) # 200 if successfulResponse Codes
| Status | Meaning |
|---|---|
| 202 Accepted | Submission accepted; it is processed in the background |
| 400 | Empty submission, or a body that is not valid JSON |
| 413 | Payload too large (file uploads are not accepted) |
| 415 | Content-Type is not JSON or form-encoded |
| 429 | Rate limit exceeded — wait for RateLimit-Reset |
| 5xx | Server error |
Error bodies carry success: false, a message, and a machine-readable name
(EMPTY_SUBMISSION, RATE_LIMITED, …) to branch on. Required fields are not validated at the
endpoint, so validate them in your own form before posting.
Always check the status code before reporting success to the user.
Reserved Field Names
These field names have special behavior:
| Name | Effect |
|---|---|
_redirect | Redirect URL after HTML form submission |
_honey | Honeypot — submissions with this field filled in are discarded silently |
_subject | Custom subject line for email notifications |
Example — custom email subject:
1await fetch("https://formboost.app/f/YOUR_ENDPOINT_ID", {
2 method: "POST",
3 headers: { "Content-Type": "application/json" },
4 body: JSON.stringify({
5 name: "Jane",
6 email: "jane@example.com",
7 message: "Question about pricing",
8 _subject: "New pricing inquiry from Jane",
9 }),
10});Allowed Origins (CORS)
By default, Formboost accepts submissions from any origin. To restrict submissions to your domain only, configure the Allowed Origins setting in your endpoint's settings.
https://yoursite.com
Multiple origins can be added, one per line. Requests from unlisted origins will be rejected with a 403.
Reading Submissions
There is no API for reading submissions back, and this is worth being explicit about because it shapes what you can build.
POST /f/{alias} is the only endpoint Formboost exposes publicly. It receives form posts. It does not return them. Forms, submissions and integrations are managed in the dashboard, and there is no account API, no CLI, no SDK and no MCP server.
If you need submission data inside another system, push it there as it arrives rather than polling for it:
- A webhook to your own endpoint, from the Starter plan up, delivering the full submission as JSON the moment it clears screening.
- Google Sheets, from Starter, which creates the spreadsheet and appends a row per submission.
- Zapier or n8n, from Starter, for anything either of those can reach.
- CSV export from the dashboard for one-off analysis.
Spam Filtering
Every submission is screened, and how deeply depends on your plan: the free plan runs heuristics — disposable email domains, link floods, honeypot hits, per-endpoint rate limits — while Starter adds an AI model that judges the submissions heuristics cannot resolve, and Pro runs that model on every submission. Each one carries a score and a readable reason in the dashboard.
In strict mode, submissions above the spam threshold are discarded before they reach your dashboard or trigger notifications.
To configure:
- Open your endpoint in the dashboard
- Go to Settings → Spam Filtering
- Toggle strict mode on or off
You can also use the _honey field as a first layer of defense — add it as a hidden field in your form:
1<input type="text" name="_honey" style="display:none" tabindex="-1" autocomplete="off" />A submission with _honey filled in is tagged as spam rather than rejected outright, so it still lands in the dashboard where you can see what was caught.
Rate Limiting
Formboost enforces per-endpoint rate limits to protect your inbox. On the free plan, endpoints accept up to 500 submissions per month across 10 forms. When the limit is reached, subsequent submissions return a 429 status code.