htmlhost.co
how-toformswebhooksdeveloperspro

How to send form submissions to your own server or tools with webhooks

htmlhost.co·September 25, 2026·2 min read

This post is part of our How to series on getting more from your htmlhost site. Every feature it mentions is documented in the docs.

A webhook sends each new form message to a URL you choose, the moment it arrives. It's how you connect your site's forms to everything else: a CRM through Zapier, a Slack channel through Make or n8n, or your own backend.

Set it up

  1. Get a URL to receive messages: a Zapier Catch Hook, a Make or n8n webhook trigger, or an endpoint on your own server. It must start with https://.
  2. In your site's Forms tab → Integrations → Webhook, paste the URL and click Save.
  3. Click Send test. htmlhost sends a sample message and shows what your endpoint answered.

What you receive

Each message arrives as a JSON POST:

{
  "event": "form.submission",
  "id": "5f0c…",
  "site": { "slug": "bakery", "address": "bakery.htmlhost.co" },
  "form": "Contact",
  "page": "/contact",
  "submittedAt": "2026-09-23T10:00:00.000Z",
  "email": "ada@example.com",
  "fields": [
    { "name": "name", "value": "Ada" },
    { "name": "message", "value": "Hi!" }
  ],
  "files": [{ "name": "brief.pdf", "size": 48213, "type": "application/pdf" }]
}

Fields arrive in the same order as your form. Attachments are listed by name only; they stay private and you download them from the dashboard.

Check it really came from htmlhost

If your endpoint is public, anyone could post to it. Every delivery carries an X-Htmlhost-Signature header: an HMAC-SHA256 of the raw body using your site's signing secret (shown in the Forms tab). In Node:

const expected = "sha256=" +
  crypto.createHmac("sha256", SECRET).update(rawBody).digest("hex");
const valid = crypto.timingSafeEqual(
  Buffer.from(expected),
  Buffer.from(req.headers["x-htmlhost-signature"])
);

Compare against the raw body before parsing it as JSON; re-serialising can change the bytes. If the secret ever leaks, click New secret, and the old one stops working immediately.

Good to know

  • Deliveries happen just after the visitor's message is saved, so a slow endpoint never slows your form down.
  • Your endpoint should reply within 5 seconds. Redirects aren't followed.
  • For your security, only public addresses can be used. Internal and private network addresses are refused.
  • The Forms tab shows the result of the latest delivery, so you can spot a broken endpoint.
  • Messages flagged as spam are never sent to your webhook.

See the webhook docs for the full reference.

Ready to try it yourself?

Paste HTML, get a link. Deploy your site in under 3 seconds — no config, no build step.

Start hosting