Form endpoint and submission API for any frontend

    Every Formboost form has one public URL, POST https://formboost.app/f/{endpoint_id}. Point an HTML form's action at it and the browser is redirected to your thank-you page; call it with fetch(), curl or any HTTP client and it answers 202 with JSON. Same endpoint, same fields, no API route, server or database on your side — Formboost validates, stores, screens for spam and delivers.

    <!-- Plain HTML: the browser posts and is redirected to your thank-you page -->
    <form action="https://formboost.app/f/YOUR_ENDPOINT_ID" method="POST">
      <input type="email" name="email" required />
      <textarea name="message"></textarea>
      <button type="submit">Send</button>
    </form>
    
    # Any language: the same endpoint answers JSON with 202
    curl -X POST https://formboost.app/f/YOUR_ENDPOINT_ID \
      -H "Content-Type: application/json" \
      -d '{"email": "user@example.com", "message": "Hello"}'
    
    # 202 {"success":true,"message":"Submission accepted for processing","requestId":"…"}

    Key Benefits

    ✓

    One endpoint per form: POST /f/{endpoint_id}, created in seconds

    ✓

    Accepts application/json and application/x-www-form-urlencoded bodies

    ✓

    302 redirect for plain HTML forms, 202 JSON for fetch(), curl and any HTTP client

    ✓

    Named error codes (EMPTY_SUBMISSION, RATE_LIMITED, …) with a hint on every 4xx

    ✓

    Reserved fields for redirect, subject, reply-to and honeypot

    ✓

    Works with any frontend, site builder or language; CORS handled; per-IP rate limiting

    How the endpoint decides what to answer

    The endpoint reads the request's Content-Type. A form-encoded post — what a browser sends from a plain <form> — is answered with a 302 to your _redirect URL, or to Formboost's default thank-you page if the form did not send one. A JSON post — what fetch(), axios, curl, Python requests or any HTTP client sends — is answered with 202 Accepted and a JSON body. The submission itself is treated identically in both cases; only the response shape differs, so a plain form and a JavaScript form can share one endpoint.

    202 rather than 200 is deliberate: the endpoint hands the submission to a queue and answers immediately, and a worker then looks up the form, checks your monthly allowance, screens for spam, stores the row and delivers to every destination. Your visitor never waits on Slack or your webhook, and a destination being down never loses a submission. The requestId in the response identifies the submission end to end if you ever need to ask about it.

    // fetch() from React, Vue, Svelte, Astro or plain JavaScript
    const res = await fetch("https://formboost.app/f/YOUR_ENDPOINT_ID", {
        method: "POST",
        headers: { "Content-Type": "application/json", Accept: "application/json" },
        body: JSON.stringify({ email, message, _replyto: email }),
    });
    // res.status === 202; the visitor stays on the page and you show your own success state

    Reserved fields: the only configuration that lives in the form

    Any field name beginning with an underscore steers delivery instead of being stored as an answer. Everything else — name, email, message, whatever you call your inputs — becomes a column in the dashboard, a key in the webhook payload and a column in the CSV export. There is no schema to declare: the endpoint stores what it receives.

    _redirectWhere a plain HTML post lands afterwards. Must be https:// and on the same host as the page the form is on; anything else falls back to the default thank-you page, which is what stops a stranger's form from bouncing your visitors elsewhere. Ignored for JSON requests — those get 202 and decide for themselves.
    _subjectThe notification email's subject line (up to 200 characters).
    _replytoThe submitter's email; Reply in your mail client answers them directly.
    _honeyThe honeypot. Hide it from people; a bot that fills it is stored as spam.

    Every response, including the ones you do not want

    Each 4xx carries a machine-readable name and a one-line hint, so code can branch on the name rather than on message wording. A wrong or disabled endpoint ID is answered 202 like a right one — the submission is dropped — so the endpoint cannot be used to guess which IDs exist.

    202 (JSON request)Accepted — the submission is queued and stored in the background.
    302 (form-encoded request)Redirect — Location is your _redirect URL or the default thank-you page.
    400 EMPTY_SUBMISSIONEvery field was empty, or only _honey / _redirect were sent.
    400 MALFORMED_BODYThe body could not be parsed as JSON or form data.
    404 ROUTE_NOT_FOUNDThe URL is not /f/<id>.
    413 PAYLOAD_TOO_LARGEOver 256 KB; file uploads are not accepted on this endpoint.
    415 UNSUPPORTED_CONTENT_TYPESend application/json or application/x-www-form-urlencoded.
    429 RATE_LIMITEDMore than 10 submissions a minute from one IP; wait for the RateLimit-Reset header.

    Where it works, and what it is not

    The endpoint is public by design, the way any form's action URL is — there is no key to hide and nothing to expose. That is what lets it work from a static site on GitHub Pages, a Webflow, Framer, Squarespace or Shopify code block, a WordPress Custom HTML block, a Next.js Server Action, or a Python script, with the same URL. Spam is handled by screening every submission, not by hiding the address. CORS is answered for any origin, and each endpoint is rate-limited per IP so a runaway script cannot fill your inbox.

    This POST is the whole public API. Forms, destinations and submissions are managed in the dashboard; there is no endpoint to read submissions back, no API key, SDK, CLI or MCP server. To get data out programmatically, attach a webhook, Zapier or n8n destination — each new submission is pushed to you as JSON — or export CSV from the dashboard. If you need a read API, Formboost is not it, and the comparison pages say so.

    Set it up

    Frequently Asked Questions

    Common questions about Form Endpoint

    Is the form endpoint the same thing as the submission API?

    Yes. There is one URL per form, POST https://formboost.app/f/{endpoint_id}. Put it in an HTML form's action attribute and the browser is redirected after submitting; call it from fetch(), curl or any language with a JSON body and it answers 202 with JSON. The fields, storage, spam screening and delivery are identical either way.

    Do I need an API key or a server to use it?

    No. The endpoint ID is the only identifier and it is public by design, like any form's action URL. There is no server-side code, API route or serverless function to deploy, and no credential to keep secret. Spam is handled by screening each submission — heuristics on every plan, an AI model on borderline submissions from Starter — not by hiding the URL.

    Can I read submissions back through the API?

    No. The submission endpoint is write-only and it is the only public API — there is no account API, key, SDK or CLI. Submissions are read in the dashboard or exported as CSV, and each new one can be pushed to your own system as JSON through a webhook, Zapier or n8n destination on Starter and above.

    What happens when a visitor submits with JavaScript disabled?

    A plain <form action=… method="POST"> works with no JavaScript at all: the browser posts the fields and is redirected to your _redirect URL (https, same host as the page) or to Formboost's default thank-you page. A JavaScript form that uses fetch() gets a 202 JSON response instead and shows its own success state.

    Is the form endpoint included on the Free plan?

    Yes. Every plan, including Free, gets an endpoint per form — 10 forms and 500 submissions a month on Free, with email, Slack, Discord and Telegram delivery, one destination per form. Custom webhooks, Google Sheets, Zapier and n8n start on Starter at $9/mo.

    Start using Form Endpoint today

    It takes less than a minute to set up. No credit card required.