Build powerful forms
without a backend.
Connect any frontend form to secure validation, asynchronous email delivery, submission persistence, and outbound webhooks with FormLynk. Zero server setup required.

A contact form shouldn't require an entire backend.
Building and maintaining a dedicated backend infrastructure just to capture leads and deliver emails introduces unnecessary fragility, security vulnerabilities, and maintenance debt.
Custom Backend Sprawl
1 Headless Request. Handled.
How your submission travels through the engine.
From the moment your user clicks submit to the final email delivery and CRM sync, every step is guarded, validated, and asynchronous.
Connect — Frontend submits POST payload
Your Next.js, React, or static HTML form sends an HTTPS POST directly to /api/v1/forms/submit.
Compatible with JSON and multipart/form-data. No server libraries or SDK installation required.
POST /api/v1/forms/submit Headers: Content-Type: application/json X-API-Key: pk_live_8f92ab31c4e2 Origin: https://mywebsite.com
One API. Any frontend or framework.
Whatever technology you use to render your user interface, submitting a form is as simple as making a single HTTPS POST request to FormLynk.
Next.js
App Router / PagesNative Client Component fetch with TypeScript typings & zero bundle bloat.
React
Vite / CRA / SPAsStandard async event handlers and hook integration in any React frontend.
Vue.js / Nuxt
Vue 3 Composition APIReactive v-model bindings sending direct REST JSON payloads.
Svelte / SvelteKit
Reactive Web AppsLightweight fetch dispatch with Svelte stores or standard forms.
Static HTML
Vanilla WebWorks with pure <form> tags or micro JS snippets with file attachments.
WordPress
Custom Blocks & ThemesBypass bloated form plugins and heavy database bloat on WP hosting.
Shopify
Liquid & HydrogenCustom wholesale, return, and lead capture forms without monthly app fees.
PHP
Server-to-ServerSend server-side form payloads securely using Private API Keys (sk_live_).
Mobile Apps
iOS / Android / FlutterSubmit in-app feedback, bug reports, and KYC documents via standard HTTPS.
Deploy your frontend anywhere.
Build pure static or serverless Next.js applications on Vercel, Cloudflare, Netlify, or AWS without provisioning server databases or custom API route workers.
Avoid burning serverless execution limits on form submission processing.
Store NEXT_PUBLIC_FORM_API_KEY safely in client bundles. Protected via strict domain CORS whitelisting.
Included in the payload without loading heavy third-party client scripts.
1"use client";2import { useState } from "react";34export default function ContactForm() {5 const [status, setStatus] = useState<{6 loading: boolean;7 success: boolean;8 error: string | null;9 }>({ loading: false, success: false, error: null });1011 async function handleSubmit(e: React.FormEvent<HTMLFormElement>) {12 e.preventDefault();13 setStatus({ loading: true, success: false, error: null });1415 const form = e.currentTarget;16 const formData = new FormData(form);17 const data = Object.fromEntries(formData.entries());1819 try {20 const response = await fetch("https://api.formlynk.io/api/v1/forms/submit", {21 method: "POST",22 headers: {23 "Content-Type": "application/json",24 "X-API-Key": process.env.NEXT_PUBLIC_FORM_API_KEY!,25 },26 body: JSON.stringify({27 form_id: "contact",28 ...data,29 }),30 });3132 const result = await response.json();33 if (response.ok && result.success) {34 setStatus({ loading: false, success: true, error: null });35 form.reset();36 } else {37 setStatus({38 loading: false,39 success: false,40 error: result.error?.message || "Submission failed. Please try again.",41 });42 }43 } catch (err) {44 setStatus({ loading: false, success: false, error: "Network connection error." });45 }46 }4748 return (49 <form onSubmit={handleSubmit} className="space-y-4">50 {/* Honeypot field (hidden from real users, traps automated bots) */}51 <input52 type="text"53 name="_gotcha"54 style={{ display: "none" }}55 tabIndex={-1}56 autoComplete="off"57 />5859 <div>60 <label htmlFor="name" className="block text-sm font-medium text-slate-700">Name</label>61 <input id="name" type="text" name="name" required className="w-full border px-3 py-2 rounded" />62 </div>6364 <div>65 <label htmlFor="email" className="block text-sm font-medium text-slate-700">Email</label>66 <input id="email" type="email" name="email" required className="w-full border px-3 py-2 rounded" />67 </div>6869 <div>70 <label htmlFor="message" className="block text-sm font-medium text-slate-700">Message</label>71 <textarea id="message" name="message" required rows={4} className="w-full border px-3 py-2 rounded" />72 </div>7374 {status.error && <p className="text-sm text-red-600">{status.error}</p>}75 {status.success && <p className="text-sm text-green-600">Thank you! Your message was received.</p>}7677 <button78 type="submit"79 disabled={status.loading}80 className="px-5 py-2.5 bg-ink text-white font-medium rounded hover:bg-black transition"81 >82 {status.loading ? "Sending..." : "Send Message"}83 </button>84 </form>85 );86}
From form to API in minutes.
Copy and paste production-ready snippets into your codebase. No proprietary SDKs, bloated dependencies, or complex setup steps.
1"use client";2import { useState } from "react";34export default function ContactForm() {5 const [status, setStatus] = useState<{6 loading: boolean;7 success: boolean;8 error: string | null;9 }>({ loading: false, success: false, error: null });1011 async function handleSubmit(e: React.FormEvent<HTMLFormElement>) {12 e.preventDefault();13 setStatus({ loading: true, success: false, error: null });1415 const form = e.currentTarget;16 const formData = new FormData(form);17 const data = Object.fromEntries(formData.entries());1819 try {20 const response = await fetch("https://api.formlynk.io/api/v1/forms/submit", {21 method: "POST",22 headers: {23 "Content-Type": "application/json",24 "X-API-Key": process.env.NEXT_PUBLIC_FORM_API_KEY!,25 },26 body: JSON.stringify({27 form_id: "contact",28 ...data,29 }),30 });3132 const result = await response.json();33 if (response.ok && result.success) {34 setStatus({ loading: false, success: true, error: null });35 form.reset();36 } else {37 setStatus({38 loading: false,39 success: false,40 error: result.error?.message || "Submission failed. Please try again.",41 });42 }43 } catch (err) {44 setStatus({ loading: false, success: false, error: "Network connection error." });45 }46 }4748 return (49 <form onSubmit={handleSubmit} className="space-y-4">50 {/* Honeypot field (hidden from real users, traps automated bots) */}51 <input52 type="text"53 name="_gotcha"54 style={{ display: "none" }}55 tabIndex={-1}56 autoComplete="off"57 />5859 <div>60 <label htmlFor="name" className="block text-sm font-medium text-slate-700">Name</label>61 <input id="name" type="text" name="name" required className="w-full border px-3 py-2 rounded" />62 </div>6364 <div>65 <label htmlFor="email" className="block text-sm font-medium text-slate-700">Email</label>66 <input id="email" type="email" name="email" required className="w-full border px-3 py-2 rounded" />67 </div>6869 <div>70 <label htmlFor="message" className="block text-sm font-medium text-slate-700">Message</label>71 <textarea id="message" name="message" required rows={4} className="w-full border px-3 py-2 rounded" />72 </div>7374 {status.error && <p className="text-sm text-red-600">{status.error}</p>}75 {status.success && <p className="text-sm text-green-600">Thank you! Your message was received.</p>}7677 <button78 type="submit"79 disabled={status.loading}80 className="px-5 py-2.5 bg-ink text-white font-medium rounded hover:bg-black transition"81 >82 {status.loading ? "Sending..." : "Send Message"}83 </button>84 </form>85 );86}
Architected for developer workflows.
Everything you need to capture, validate, protect, deliver, and automate form submissions at scale.
Dynamic Form Field Builder
Define custom validation rules, required fields, regex patterns, numeric bounds, and file attachment limits visually without altering your frontend code.
Browser Public vs Server Private Keys
Browser Public keys (pk_live_) are scoped strictly to frontend form ingestion and secured via Origin whitelisting. Server Private keys (sk_live_) handle backend server-to-server operations.
Domain & Origin Protection
Prevent unauthorized third-party websites from spamming your API key. Any browser submission from an unapproved hostname is immediately blocked with 403 INVALID_ORIGIN.
Honeypots & Cloudflare Turnstile
Silent _gotcha honeypot traps automated bots without frustrating human visitors. Optional Turnstile or reCAPTCHA verification adds cryptographic bot resistance.
Asynchronous Email Delivery
Submissions are committed to storage first in under 24ms. Notification emails and auto-replies are queued and retried automatically with exponential backoff (10s, 60s, 300s).
Outbound HMAC Webhooks
Push leads directly into Zapier, Make, Slack, HubSpot, or custom web services with verifiable HMAC-SHA256 signature headers on creation, processing, or failure.
Submission Vault & CSV Export
Search, filter, and inspect captured form submissions with public-safe UUIDs. Export clean CSV spreadsheets with a single click.
Secure File Uploads
Safely receive resumes and documents. Executable file extensions (.exe, .php, .sh) are blocked, MIME types verified, and files assigned private UUID names.
HTML Templates & Dynamic Tags
Design branded notification emails and auto-replies using dynamic template variables like {{name}}, {{email}}, {{message}}, and custom fields.
Security between your form and the inbox.
Every incoming HTTP request passes through an 8-stage automated defense checkpoint before reaching the database or email dispatcher.
API Key Authentication
Distinguishes Browser Public (pk_) vs Server Private (sk_) keys with live/test environments.
CORS Origin Whitelist
Strictly enforces domain boundaries. Unapproved domains are rejected with 403 INVALID_ORIGIN.
Rate Limiting per IP
Default 20 req/min per IP and per form limits prevent brute-force and DDoS flooding.
Silent Honeypot Trap
Hidden _gotcha field catches automated scrapers without annoying human users with puzzles.
Turnstile / reCAPTCHA
Cryptographic bot challenge verification for high-risk lead generation endpoints.
Dynamic Validation
Evaluates input bounds, RFC 5322 email syntax, and disallows dangerous script injection.
Idempotency Key Deduplication
Pass Idempotency-Key to prevent double submissions from double clicks or network reconnects.
Stack Concealment
Strips X-Powered-By & framework headers. Stores file uploads privately outside webroot.
pk_live_...) are safe in frontend code because they are restricted by CORS origins and rate limits.Your submission is accepted before the email leaves.
Traditional form scripts block user browsers waiting on synchronous SMTP connections. Universal Form API commits the submission immediately and handles delivery asynchronously.
Instant Persistence
As soon as the payload passes validation, the engine writes the record to database storage and returns a 200 OK response. The user never waits on slow mail servers.
Exponential Backoff Retries
If an external SMTP provider experiences transient network errors, DNS timeouts, or rate limits, the queue worker automatically retries delivery with exponential backoff.
Outbound HMAC webhooks in real time.
Sync submissions directly to Zapier, Make, HubSpot, Slack, or internal REST APIs with cryptographically verifiable HMAC-SHA256 signatures.
{
"event": "submission.created",
"timestamp": "2026-09-26T15:20:00Z",
"project_id": "prj_01h9x4b9e28k",
"submission_id": "sub_8f92ab31c4e2",
"form": {
"id": "contact",
"name": "Main Contact Form"
},
"data": {
"name": "Sarah Chen",
"email": "sarah@techcorp.com",
"phone": "+1 415-555-0199",
"message": "We need a custom enterprise SLA for high-volume lead capture."
},
"client": {
"ip_address": "198.51.100.42",
"origin": "https://techcorp.com"
}
}X-Webhook-Signature header with timing-safe equality to verify authenticity.Branded notification & auto-reply emails.
Craft responsive HTML email notifications for your team and automated confirmations for your submitters with dynamic template tags and automated XSS sanitization.
Contact Us Form
Bring your own SMTP or use our shared mailer.
Every project workspace can connect its own dedicated transactional SMTP credentials. Passwords and API tokens are encrypted at rest with AES-256.
SendGrid
Connect your SendGrid API key or SMTP user with TLS authentication.
Postmark
Ultra-fast transactional deliverability with Postmark server tokens.
Amazon SES
Low-cost high-volume deliverability via your dedicated AWS SES credentials.
Mailgun
Custom domain routing with Mailgun SMTP credentials per project.
Brevo (Sendinblue)
European data-residency compliant transactional relay integration.
Default Shared Mailer
Zero configuration needed. Included out-of-the-box on all plans.
Full visibility over your submissions and mail logs.
Manage projects, generate scoped API keys, whitelist origins, configure webhooks, inspect field payloads, and monitor asynchronous email delivery in real time.
| UUID | Submitter | Form Slug | Status | Latency | Actions |
|---|---|---|---|---|---|
| sub_8f92ab31c4e2 | Jane Developer jane@acmeweb.dev | Contact Form | Delivered | 18ms | |
| sub_4c71ef82a901 | David Sterling david@saasgroup.io | Enterprise Quote | Delivered | 22ms | |
| sub_1a29ff08cb54 | BotScraper_98 spambot@darkweb.xyz | Contact Form | Spam Blocked | 12ms | |
| sub_99dd302ba188 | Elena Rostova elena@startup.co | Beta Request | Delivered | 24ms |
Build validation schemas without backend code.
Create field types, regular expressions, required constraints, and attachment limits visually. The API validates all submissions against your schema before saving.
full_name | type: textemail | type: emailphone | type: phonemessage | type: textarearesume | type: fileBuilt for developers. Simple enough for everyone else.
From signing up to receiving your first live form submission in production takes less than three minutes.
Create Project
Group forms and domains by client or application in isolated workspaces.
Add Allowed Domains
Whitelist development and production hostnames for strict CORS defense.
Configure Form & Email
Set notification recipients, reply-to routing, and optional submitter auto-replies.
Generate API Key
Get your Browser Public key (pk_live_) with one-click token generation.
Copy Integration Code
Paste the clean fetch request or static HTML form into your frontend repo.
Deploy Anywhere
Ship to Vercel, Netlify, Cloudflare Pages, or static S3 hosting. Ready instantly.
Interactive API Explorer
Test endpoints, inspect request headers, simulate validation errors, test honeypot behavior, and observe live API responses in a safe sandbox.
{
"form_id": "contact",
"name": "Taylor Morgan",
"email": "taylor@startup.io",
"message": "Can we schedule an architecture review for our team?"
}{
"status": "Ready. Click Execute Request to test endpoint."
}Everything you need to know.
Straight answers on architecture, compatibility, security, deliverability, and developer workflows.
Your frontend is ready.
Give it an API.
Connect your forms, capture submissions, deliver email, and automate your workflow without building, debugging, or maintaining another backend.