FormLynk — Connect your forms. Send anywhere.
FORM INFRASTRUCTURE FOR DEVELOPERS

Build powerful forms without a backend.

Connect any frontend form to secure validation, asynchronous email delivery, submission persistence, and outbound webhooks with FormLynk. Zero server setup required.

Browser Public Keys
CORS Origin Shielded
Async Retry Queues
TRUSTED BY DEVELOPERS
⚛React
NNext.js
▲Vue
5HTML
●Svelte
FormLynk visual form builder, instant submission, and webhook integration pipeline
01THE ARCHITECTURAL SHIFT

A contact form shouldn't require an entire backend.

Building and maintaining a dedicated backend infrastructure just to capture leads and deliver emails introduces unnecessary fragility, security vulnerabilities, and maintenance debt.

THE TRADITIONAL APPROACH

Custom Backend Sprawl

✕
Spin up backend serverProvision Express, Django, Laravel, or lambda function
✕
Configure SMTP credentialsManage TLS, ports, connection timeouts, and mailer errors
✕
Write custom validationManual regex for emails, phone numbers, and required fields
✕
Handle spam & bot attacksBuild custom honeypots, integrate CAPTCHA, block malicious IPs
✕
Database migrations & schemasCreate tables, manage UUIDs, file storage, and data exports
✕
Build background retry queuesRedis / Bull / SQS queues to prevent dropped submissions
✕
Ongoing server maintenancePatch vulnerabilities, maintain SSL, and monitor uptime
Result: 14+ hours of boilerplate setup, fragile email connections, and security debt.
RECOMMENDED
FORMLYNK

1 Headless Request. Handled.

✓
Add 1 API endpoint to your formPoint your form action or fetch request to /api/v1/forms/submit
✓
Instant multi-tenant securityOrigin whitelisting, Honeypot (_gotcha), Turnstile & rate limiting
✓
Visual Dynamic Field BuilderDefine schema rules, required fields & file constraints visually
✓
Asynchronous retry queueSubmissions saved immediately; emails delivered with exponential backoff
✓
Auto-reply confirmationsSend branded confirmation emails to submitters automatically
✓
Real-time HMAC webhooksDispatch JSON payloads directly to Zapier, Make, Slack, or CRMs
✓
Admin Portal & CSV exportInspect delivery logs, audit trails, and manage submissions
Result: 2 minutes to integrate. Accepted in <24ms. Zero servers to patch.
02PIPELINE WALKTHROUGH

How your submission travels through the engine.

From the moment your user clicks submit to the final email delivery and CRM sync, every step is guarded, validated, and asynchronous.

STEP 01 OF 07STAGE: CONNECT

Connect — Frontend submits POST payload

Your Next.js, React, or static HTML form sends an HTTPS POST directly to /api/v1/forms/submit.

Compatible with JSON and multipart/form-data. No server libraries or SDK installation required.

ENGINE TELEMETRYNODE: STAGE_01
POST /api/v1/forms/submit
Headers:
  Content-Type: application/json
  X-API-Key: pk_live_8f92ab31c4e2
  Origin: https://mywebsite.com
03UNIVERSAL COMPATIBILITY

One API. Any frontend or framework.

Whatever technology you use to render your user interface, submitting a form is as simple as making a single HTTPS POST request to FormLynk.

Next.js

App Router / Pages

Native Client Component fetch with TypeScript typings & zero bundle bloat.

POST /api/v1/forms/submit→

React

Vite / CRA / SPAs

Standard async event handlers and hook integration in any React frontend.

POST /api/v1/forms/submit→

Vue.js / Nuxt

Vue 3 Composition API

Reactive v-model bindings sending direct REST JSON payloads.

POST /api/v1/forms/submit→

Svelte / SvelteKit

Reactive Web Apps

Lightweight fetch dispatch with Svelte stores or standard forms.

POST /api/v1/forms/submit→

Static HTML

Vanilla Web

Works with pure <form> tags or micro JS snippets with file attachments.

POST /api/v1/forms/submit→

WordPress

Custom Blocks & Themes

Bypass bloated form plugins and heavy database bloat on WP hosting.

POST /api/v1/forms/submit→

Shopify

Liquid & Hydrogen

Custom wholesale, return, and lead capture forms without monthly app fees.

POST /api/v1/forms/submit→

PHP

Server-to-Server

Send server-side form payloads securely using Private API Keys (sk_live_).

POST /api/v1/forms/submit→

Mobile Apps

iOS / Android / Flutter

Submit in-app feedback, bug reports, and KYC documents via standard HTTPS.

POST /api/v1/forms/submit→
Supports both JSON payloads and multipart/form-data for file attachments.
Explore all integration guides →
04NEXT.JS & VERCEL OPTIMIZED

Deploy your frontend anywhere.

Build pure static or serverless Next.js applications on Vercel, Cloudflare, Netlify, or AWS without provisioning server databases or custom API route workers.

Zero Serverless Function Cold Starts:

Avoid burning serverless execution limits on form submission processing.

Safe Browser Public Key Architecture:

Store NEXT_PUBLIC_FORM_API_KEY safely in client bundles. Protected via strict domain CORS whitelisting.

Built-in Bot Honeypot (_gotcha):

Included in the payload without loading heavy third-party client scripts.

ENVIRONMENT CONFIGURATION:
.env.local
NEXT_PUBLIC_FORM_API_KEY=pk_live_xxxxxxxxx
components/ContactForm.tsx
typescript
1"use client";
2import { useState } from "react";
3
4export default function ContactForm() {
5 const [status, setStatus] = useState<{
6 loading: boolean;
7 success: boolean;
8 error: string | null;
9 }>({ loading: false, success: false, error: null });
10
11 async function handleSubmit(e: React.FormEvent<HTMLFormElement>) {
12 e.preventDefault();
13 setStatus({ loading: true, success: false, error: null });
14
15 const form = e.currentTarget;
16 const formData = new FormData(form);
17 const data = Object.fromEntries(formData.entries());
18
19 try {
20 const response = await fetch("https://api.formlynk.io/api/v1/forms/submit", {
21 method: "POST",
22 headers: {
23 "Content-Type": "application/json",
24 "X-API-Key": process.env.NEXT_PUBLIC_FORM_API_KEY!,
25 },
26 body: JSON.stringify({
27 form_id: "contact",
28 ...data,
29 }),
30 });
31
32 const result = await response.json();
33 if (response.ok && result.success) {
34 setStatus({ loading: false, success: true, error: null });
35 form.reset();
36 } else {
37 setStatus({
38 loading: false,
39 success: false,
40 error: result.error?.message || "Submission failed. Please try again.",
41 });
42 }
43 } catch (err) {
44 setStatus({ loading: false, success: false, error: "Network connection error." });
45 }
46 }
47
48 return (
49 <form onSubmit={handleSubmit} className="space-y-4">
50 {/* Honeypot field (hidden from real users, traps automated bots) */}
51 <input
52 type="text"
53 name="_gotcha"
54 style={{ display: "none" }}
55 tabIndex={-1}
56 autoComplete="off"
57 />
58
59 <div>
60 <label htmlFor="name" className="block text-sm font-medium text-slate-700">Name</label>
61 <input id="name" type="text" name="name" required className="w-full border px-3 py-2 rounded" />
62 </div>
63
64 <div>
65 <label htmlFor="email" className="block text-sm font-medium text-slate-700">Email</label>
66 <input id="email" type="email" name="email" required className="w-full border px-3 py-2 rounded" />
67 </div>
68
69 <div>
70 <label htmlFor="message" className="block text-sm font-medium text-slate-700">Message</label>
71 <textarea id="message" name="message" required rows={4} className="w-full border px-3 py-2 rounded" />
72 </div>
73
74 {status.error && <p className="text-sm text-red-600">{status.error}</p>}
75 {status.success && <p className="text-sm text-green-600">Thank you! Your message was received.</p>}
76
77 <button
78 type="submit"
79 disabled={status.loading}
80 className="px-5 py-2.5 bg-ink text-white font-medium rounded hover:bg-black transition"
81 >
82 {status.loading ? "Sending..." : "Send Message"}
83 </button>
84 </form>
85 );
86}
05INTEGRATION SAMPLES

From form to API in minutes.

Copy and paste production-ready snippets into your codebase. No proprietary SDKs, bloated dependencies, or complex setup steps.

Production Next.js 14/15 Client Component with FormLynk endpoint, state handling, and honeypot.Full API Docs
components/ContactForm.tsx
typescript
1"use client";
2import { useState } from "react";
3
4export default function ContactForm() {
5 const [status, setStatus] = useState<{
6 loading: boolean;
7 success: boolean;
8 error: string | null;
9 }>({ loading: false, success: false, error: null });
10
11 async function handleSubmit(e: React.FormEvent<HTMLFormElement>) {
12 e.preventDefault();
13 setStatus({ loading: true, success: false, error: null });
14
15 const form = e.currentTarget;
16 const formData = new FormData(form);
17 const data = Object.fromEntries(formData.entries());
18
19 try {
20 const response = await fetch("https://api.formlynk.io/api/v1/forms/submit", {
21 method: "POST",
22 headers: {
23 "Content-Type": "application/json",
24 "X-API-Key": process.env.NEXT_PUBLIC_FORM_API_KEY!,
25 },
26 body: JSON.stringify({
27 form_id: "contact",
28 ...data,
29 }),
30 });
31
32 const result = await response.json();
33 if (response.ok && result.success) {
34 setStatus({ loading: false, success: true, error: null });
35 form.reset();
36 } else {
37 setStatus({
38 loading: false,
39 success: false,
40 error: result.error?.message || "Submission failed. Please try again.",
41 });
42 }
43 } catch (err) {
44 setStatus({ loading: false, success: false, error: "Network connection error." });
45 }
46 }
47
48 return (
49 <form onSubmit={handleSubmit} className="space-y-4">
50 {/* Honeypot field (hidden from real users, traps automated bots) */}
51 <input
52 type="text"
53 name="_gotcha"
54 style={{ display: "none" }}
55 tabIndex={-1}
56 autoComplete="off"
57 />
58
59 <div>
60 <label htmlFor="name" className="block text-sm font-medium text-slate-700">Name</label>
61 <input id="name" type="text" name="name" required className="w-full border px-3 py-2 rounded" />
62 </div>
63
64 <div>
65 <label htmlFor="email" className="block text-sm font-medium text-slate-700">Email</label>
66 <input id="email" type="email" name="email" required className="w-full border px-3 py-2 rounded" />
67 </div>
68
69 <div>
70 <label htmlFor="message" className="block text-sm font-medium text-slate-700">Message</label>
71 <textarea id="message" name="message" required rows={4} className="w-full border px-3 py-2 rounded" />
72 </div>
73
74 {status.error && <p className="text-sm text-red-600">{status.error}</p>}
75 {status.success && <p className="text-sm text-green-600">Thank you! Your message was received.</p>}
76
77 <button
78 type="submit"
79 disabled={status.loading}
80 className="px-5 py-2.5 bg-ink text-white font-medium rounded hover:bg-black transition"
81 >
82 {status.loading ? "Sending..." : "Send Message"}
83 </button>
84 </form>
85 );
86}
06PLATFORM CAPABILITIES

Architected for developer workflows.

Everything you need to capture, validate, protect, deliver, and automate form submissions at scale.

SCHEMA ENGINE

Dynamic Form Field Builder

Define custom validation rules, required fields, regex patterns, numeric bounds, and file attachment limits visually without altering your frontend code.

10+ Built-in Field Types
Regex and Range Validation
Live Interactive Preview
KEY ISOLATION

Browser Public vs Server Private Keys

Browser Public keys (pk_live_) are scoped strictly to frontend form ingestion and secured via Origin whitelisting. Server Private keys (sk_live_) handle backend server-to-server operations.

Environment Segregation (Live & Test)
Granular Project Scoping
One-Click Instant Revocation
CORS SECURITY

Domain & Origin Protection

Prevent unauthorized third-party websites from spamming your API key. Any browser submission from an unapproved hostname is immediately blocked with 403 INVALID_ORIGIN.

Multiple Domains per Project
Localhost Staging Support
Zero Config CORS Handling
ANTI-SPAM SHIELD

Honeypots & Cloudflare Turnstile

Silent _gotcha honeypot traps automated bots without frustrating human visitors. Optional Turnstile or reCAPTCHA verification adds cryptographic bot resistance.

Silent Honeypot Trap (_gotcha)
Cloudflare Turnstile & reCAPTCHA
IP Blacklist & Rate Limits
RELIABILITY

Asynchronous Email Delivery

Submissions are committed to storage first in under 24ms. Notification emails and auto-replies are queued and retried automatically with exponential backoff (10s, 60s, 300s).

Sub-24ms API Response
Exponential Retry Backoff
Dedicated SMTP Configuration
AUTOMATION

Outbound HMAC Webhooks

Push leads directly into Zapier, Make, Slack, HubSpot, or custom web services with verifiable HMAC-SHA256 signature headers on creation, processing, or failure.

HMAC-SHA256 Signature Header
Event Filtering
Delivery Audit Logs & Retries
MANAGEMENT

Submission Vault & CSV Export

Search, filter, and inspect captured form submissions with public-safe UUIDs. Export clean CSV spreadsheets with a single click.

Public-safe UUIDs (sub_...)
Status Filtering
One-Click Instant CSV Export
STORAGE SAFETY

Secure File Uploads

Safely receive resumes and documents. Executable file extensions (.exe, .php, .sh) are blocked, MIME types verified, and files assigned private UUID names.

Executable Blacklist Enforcement
MIME Type Sanitization
Private Storage Outside Webroot
CUSTOMIZATION

HTML Templates & Dynamic Tags

Design branded notification emails and auto-replies using dynamic template variables like {{name}}, {{email}}, {{message}}, and custom fields.

XSS-Sanitized HTML Rendering
Submitter Auto-Reply Confirmations
Custom Dynamic Field Tags
07DEFENSE-IN-DEPTH

Security between your form and the inbox.

Every incoming HTTP request passes through an 8-stage automated defense checkpoint before reaching the database or email dispatcher.

01

API Key Authentication

Distinguishes Browser Public (pk_) vs Server Private (sk_) keys with live/test environments.

PassedAUTHENTICATED
02

CORS Origin Whitelist

Strictly enforces domain boundaries. Unapproved domains are rejected with 403 INVALID_ORIGIN.

PassedORIGIN_VERIFIED
03

Rate Limiting per IP

Default 20 req/min per IP and per form limits prevent brute-force and DDoS flooding.

PassedUNDER_LIMIT
04

Silent Honeypot Trap

Hidden _gotcha field catches automated scrapers without annoying human users with puzzles.

PassedCLEAN
05

Turnstile / reCAPTCHA

Cryptographic bot challenge verification for high-risk lead generation endpoints.

PassedCHALLENGE_PASSED
06

Dynamic Validation

Evaluates input bounds, RFC 5322 email syntax, and disallows dangerous script injection.

PassedSCHEMA_VALID
07

Idempotency Key Deduplication

Pass Idempotency-Key to prevent double submissions from double clicks or network reconnects.

PassedUNIQUE_TRANSACTION
08

Stack Concealment

Strips X-Powered-By & framework headers. Stores file uploads privately outside webroot.

PassedCONCEALED
Responsible Disclosure: Browser Public keys (pk_live_...) are safe in frontend code because they are restricted by CORS origins and rate limits.
Read Security Architecture →
08ASYNCHRONOUS ENGINE

Your submission is accepted before the email leaves.

Traditional form scripts block user browsers waiting on synchronous SMTP connections. Universal Form API commits the submission immediately and handles delivery asynchronously.

STAGE 1: SYNCHRONOUS (< 24ms)

Instant Persistence

As soon as the payload passes validation, the engine writes the record to database storage and returns a 200 OK response. The user never waits on slow mail servers.

Database Write:14ms [COMMITTED]
Client Response:200 OK
Queue Job:DISPATCHED
STAGE 2: ASYNCHRONOUS (BACKGROUND WORKER)

Exponential Backoff Retries

If an external SMTP provider experiences transient network errors, DNS timeouts, or rate limits, the queue worker automatically retries delivery with exponential backoff.

Attempt 1ImmediateSMTP Connect
Attempt 2+10s DelayRetry 1
Attempt 3+60s DelayDelivered ✓
Delivery logs & manual retry available in Admin Portal99.98% Delivery SLA
09AUTOMATION & INTEGRATION

Outbound HMAC webhooks in real time.

Sync submissions directly to Zapier, Make, HubSpot, Slack, or internal REST APIs with cryptographically verifiable HMAC-SHA256 signatures.

WEBHOOK EVENT DISPATCHER
OUTBOUND HTTP HEADERS:
X-Webhook-Signature: sha256=d87f98e72c0192e4483a992bc8310f823485ab921c
Content-Type: application/json
{
  "event": "submission.created",
  "timestamp": "2026-09-26T15:20:00Z",
  "project_id": "prj_01h9x4b9e28k",
  "submission_id": "sub_8f92ab31c4e2",
  "form": {
    "id": "contact",
    "name": "Main Contact Form"
  },
  "data": {
    "name": "Sarah Chen",
    "email": "sarah@techcorp.com",
    "phone": "+1 415-555-0199",
    "message": "We need a custom enterprise SLA for high-volume lead capture."
  },
  "client": {
    "ip_address": "198.51.100.42",
    "origin": "https://techcorp.com"
  }
}
Cryptographic Verification:Calculate HMAC-SHA256 using your secret token and compare against the X-Webhook-Signature header with timing-safe equality to verify authenticity.
10HTML TEMPLATE ENGINE

Branded notification & auto-reply emails.

Craft responsive HTML email notifications for your team and automated confirmations for your submitters with dynamic template tags and automated XSS sanitization.

TEMPLATE: Admin Notification (Contact Us)
NEW SUBMISSION RECEIVED

Contact Us Form

sub_8f92ab31c4e2
From Name:Jane Developer
Email Address:jane@example.com
Submitted At:Sep 26, 2026, 15:20 UTC
Message:
Hello! We are looking to replace our legacy backend contact forms with FormLynk across our Next.js client deployments.
Reply-To header set to jane@example.com. Direct replies will reach the submitter.
11SMTP INFRASTRUCTURE

Bring your own SMTP or use our shared mailer.

Every project workspace can connect its own dedicated transactional SMTP credentials. Passwords and API tokens are encrypted at rest with AES-256.

SendGrid

Supported

Connect your SendGrid API key or SMTP user with TLS authentication.

smtp.sendgrid.netPort 587 / 465

Postmark

Supported

Ultra-fast transactional deliverability with Postmark server tokens.

smtp.postmarkapp.comPort 587 / 2525

Amazon SES

Supported

Low-cost high-volume deliverability via your dedicated AWS SES credentials.

email-smtp.*.amazonaws.comPort 587 / 465

Mailgun

Supported

Custom domain routing with Mailgun SMTP credentials per project.

smtp.mailgun.orgPort 587

Brevo (Sendinblue)

Supported

European data-residency compliant transactional relay integration.

smtp-relay.brevo.comPort 587

Default Shared Mailer

Included Free

Zero configuration needed. Included out-of-the-box on all plans.

System Managed RelayPort Encrypted Queue
SMTP passwords and authorization secrets are strictly encrypted at rest inside the database using AES-256-CBC.
12FORMLYNK PORTAL PREVIEW

Full visibility over your submissions and mail logs.

Manage projects, generate scoped API keys, whitelist origins, configure webhooks, inspect field payloads, and monitor asynchronous email delivery in real time.

app.formlynk.io / portal / projects / prj_acme_production
HEALTHY
ACTIVE PROJECTAcme Marketing & SaaSpk_live_98ab42...
Submissions
48,290
Emails Sent
48,102 (99.9%)
Active Queue
18 Jobs
Spam Blocked
3,412 (Silent)
UUIDSubmitterForm SlugStatusLatencyActions
sub_8f92ab31c4e2
Jane Developer
jane@acmeweb.dev
Contact FormDelivered18ms
sub_4c71ef82a901
David Sterling
david@saasgroup.io
Enterprise QuoteDelivered22ms
sub_1a29ff08cb54
BotScraper_98
spambot@darkweb.xyz
Contact FormSpam Blocked12ms
sub_99dd302ba188
Elena Rostova
elena@startup.co
Beta RequestDelivered24ms
13VISUAL SCHEMA DESIGNER

Build validation schemas without backend code.

Create field types, regular expressions, required constraints, and attachment limits visually. The API validates all submissions against your schema before saving.

FIELD BUILDER: Form Slug [contact-us]
CONFIGURED FIELD RULES (5)DRAG TO REORDER
⋮⋮
Full Namekey: full_name | type: text
REQUIRED
⋮⋮
Work Emailkey: email | type: email
REQUIRED
⋮⋮
Phone Numberkey: phone | type: phone
OPTIONAL
⋮⋮
Project Detailskey: message | type: textarea
REQUIRED
⋮⋮
Resume (PDF/DOC)key: resume | type: file
OPTIONAL
LIVE CLIENT PREVIEWAUTO-SYNCED
Upload Resume (PDF/DOC) (PDF, DOCX up to 10MB)
14DEVELOPER WORKFLOW

Built for developers. Simple enough for everyone else.

From signing up to receiving your first live form submission in production takes less than three minutes.

STEP 01

Create Project

Group forms and domains by client or application in isolated workspaces.

STEP 02

Add Allowed Domains

Whitelist development and production hostnames for strict CORS defense.

STEP 03

Configure Form & Email

Set notification recipients, reply-to routing, and optional submitter auto-replies.

STEP 04

Generate API Key

Get your Browser Public key (pk_live_) with one-click token generation.

STEP 05

Copy Integration Code

Paste the clean fetch request or static HTML form into your frontend repo.

STEP 06

Deploy Anywhere

Ship to Vercel, Netlify, Cloudflare Pages, or static S3 hosting. Ready instantly.

15SANDBOX PLAYGROUND

Interactive API Explorer

Test endpoints, inspect request headers, simulate validation errors, test honeypot behavior, and observe live API responses in a safe sandbox.

REQUEST BUILDER
POST /api/v1/forms/submit
Simulate Condition:
OUTGOING HTTP REQUEST
{
  "form_id": "contact",
  "name": "Taylor Morgan",
  "email": "taylor@startup.io",
  "message": "Can we schedule an architecture review for our team?"
}
SERVER RESPONSE PAYLOAD
{
  "status": "Ready. Click Execute Request to test endpoint."
}
16FREQUENTLY ASKED QUESTIONS

Everything you need to know.

Straight answers on architecture, compatibility, security, deliverability, and developer workflows.

No. FormLynk was designed specifically to power frontend-only forms. Your form submits directly to our endpoint with your public API key. We handle origin verification, schema validation, spam blocking, asynchronous email queueing, and webhook dispatching.
READY FOR PRODUCTION

Your frontend is ready. Give it an API.

Connect your forms, capture submissions, deliver email, and automate your workflow without building, debugging, or maintaining another backend.

Free tier available 3-minute setup No credit card required