Skip to guide
form koi.Start free ↗

Connect your
website.

You supply the fields and the design. Form Koi receives the message, keeps a copy and queues a notification for the people you choose.

1. Create a form

  1. Sign in and create a form. Give it a recognizable name, such as “Website contact.”
  2. Choose at least one verified notification recipient. Add other addresses under Recipients and complete their verification before selecting them.
  3. Open the form’s connection guide and copy its endpoint and generated example. That example reflects your current honeypot, Turnstile and upload settings.
Use the endpoint shown in your workspace.

The examples below use staging and a placeholder key. Replace the complete URL. A form’s public key belongs in website code; your management API token and Turnstile secret do not.

2. Add the code to your page

Every input you want to receive needs a name. You can change labels, styling and fields. Keep the configured honeypot hidden and empty.

Paste this into your existing page. Replace the whole action URL with your form’s endpoint. Plain HTML uses the configured thank-you destination after submission.

contact.html
<form action="https://api-staging.formkoi.com/f/YOUR_PUBLIC_FORM_KEY" method="POST">
  <label for="name">Your name</label>
  <input id="name" name="name" autocomplete="name" required>

  <label for="email">Email address</label>
  <input id="email" name="email" type="email" autocomplete="email" required>

  <label for="message">Your message</label>
  <textarea id="message" name="message" required></textarea>

  <!-- Leave this hidden anti-spam field empty. -->
  <input type="text" name="botcheck"
    tabindex="-1" autocomplete="off" style="display:none" hidden>

  <button type="submit">Send message</button>
</form>

Using WordPress? Follow the WordPress setup guide for Custom HTML block instructions and hosting requirements.

These starter examples have no Turnstile widget or files. When you enable either feature, copy the updated example from your form’s connection guide. The protection guide explains how to install the widget before enforcing it.

The request goes directly from the visitor’s browser to your public submission endpoint. You do not need a Next.js route handler, Astro server endpoint or Form Koi management token for this flow.

3. Send a test

  1. Run the receiver test in the connection guide to check the form’s destination. This creates a real test message, uses your allowance and queues an owner notification.
  2. Open your actual website and submit a distinct message. If you configured allowed origins, this page must use one of those exact origins.
  3. Find it in the Inbox. Check its fields, chosen recipients and delivery history. If it is missing, also check Spam.
  4. If Turnstile is enabled, confirm that the form’s protection status reflects a successful website submission. The receiver test alone cannot verify a website installation.

Staging notifications stay in the internal test inbox. Receiving a 201 response confirms that the message was stored; it does not confirm that a live email reached a recipient.

4. Before you publish

  • Connect Turnstile and set allowed origins for your intended website. Include the exact scheme and host, such as https://www.example.com.
  • Choose a notification subject and, for plain HTML, an HTTPS thank-you URL in form settings. A visitor-supplied field cannot override those choices.
  • Test empty fields, invalid email, a slow connection and retry behavior. Keep someone’s message intact when a request fails.
  • Check keyboard navigation and your smallest supported screen. Keep labels visible and success/error messages understandable.

Adding files, visitor replies or routing later? Each has its own guide and settings. Recopy your generated integration when changing settings that affect the website.

Understand the submission contract ↗