Documentation

    Submission API Reference & Form Configuration

    Reference for POST /f/{endpoint_id}: JSON and form-encoded bodies, the 202 and 302 responses, every error name, reserved fields, and per-form settings.

    Submit a Form

    Send data to a form endpoint. This is identical to a standard HTML form POST.

    POST https://formboost.app/f/:endpoint_id

    JSON submission

    const response = await fetch("https://formboost.app/f/YOUR_ENDPOINT_ID", {
      method: "POST",
      headers: { "Content-Type": "application/json" },
      body: JSON.stringify({
        email: "user@example.com",
        message: "Hello from the API"
      })
    });
    
    if (!response.ok) {
      const error = await response.json(); // { success, message, name, hint }
    }

    cURL example

    curl -X POST https://formboost.app/f/YOUR_ENDPOINT_ID \
      -H "Content-Type: application/json" \
      -d '{"email": "user@example.com", "message": "Hello"}'

    Response

    The endpoint accepts the submission and processes it in the background, so the answer is immediate. What you get depends on how you sent it:

    • JSON or fetch() clients (Accept: application/json, or a JSON body) receive 202 Accepted:
    {
      "success": true,
      "message": "Submission accepted for processing",
      "requestId": "3f1c…"
    }
    • Plain HTML form posts receive a 302 redirect — to your _redirect URL when it is an https URL on the same host as the submitting page, otherwise to the default thank-you page.

    requestId is the identifier of this request, useful when reporting a problem. It is not a lookup key: submissions are read in the dashboard, not through this endpoint. Check response.ok rather than parsing the body for success.

    Error Codes

    Errors are JSON with success: false, a human message, and a machine-readable name to branch on, plus a hint saying what to change:

    CodenameMeaning
    400EMPTY_SUBMISSIONNo field other than _honey / _redirect was sent
    400MALFORMED_BODYThe body is not valid JSON
    413PAYLOAD_TOO_LARGEOver the size limit; file uploads are not accepted
    415UNSUPPORTED_CONTENT_TYPESend application/json or application/x-www-form-urlencoded
    429RATE_LIMITEDWait for the window in the RateLimit-Reset header
    5xx—Server error; safe to retry

    Required fields are not validated at the endpoint — every non-empty submission is accepted. An unknown endpoint id is also accepted and discarded during processing, so check the id in the dashboard rather than relying on a 404. A plain HTML form post never sees JSON: on an error it is redirected to the default page instead.

    Special Fields

    These hidden fields control Formboost behavior without being stored as submission data:

    FieldDescription
    _redirectURL to redirect to after submission
    _subjectCustom email subject line
    _replytoSet reply-to address on notification emails
    _honeyHoneypot field name for spam detection
    _emailThe address Auto Reply writes to when your form has no email field

    Email Notifications

    By default, Formboost sends an email notification to your account email for every submission. You can customize this under Endpoint → Notifications.

    SettingDescription
    To addressWhere notification emails are sent
    SubjectCustomize with _subject field
    Reply-toAuto-populated from the _replyto field

    These emails go to you. To email the person who filled in the form instead, see Auto Reply. It is available on Starter and above, with HTML templates and {{fieldName}} variables on Pro.

    Spam Protection

    Formboost uses AI-powered spam filtering. Configure sensitivity under Endpoint → Spam Protection.

    Honeypot Fields

    Add a hidden input that humans never fill in. Bots usually do.

    <form action="https://formboost.app/f/YOUR_ENDPOINT_ID" method="POST">
      <!-- Honeypot: hidden from real users -->
      <input type="text" name="_honey" style="display:none" tabindex="-1" autocomplete="off" />
    
      <input type="email" name="email" required />
      <button type="submit">Submit</button>
    </form>

    Set _honey as the honeypot field name in your endpoint settings to activate detection.

    Written by · Last updated