News⏱ 12 min read

GetForms: Free Open-Source Form Backend (Launch)

GetForms launches as a free, open-source form backend with unlimited forms, silent spam filtering, 25 MB uploads, and multi-channel alerts. Tested against Formspree, Formcarry, Basin, and FormBee with current pricing.

GetForms: Free Open-Source Form Backend (Launch)
Table of Contents

Free Cloud GitHub Stars CI Release License: Apache-2.0

GetForms is a free, open-source form backend that takes HTML form submissions through one URL and delivers them to email, Telegram, Slack, Discord, or your webhook. It ships unlimited forms, silent spam filtering, 25 MB file uploads, and a self-hostable Apache 2.0 core. Against Formspree, Formcarry, Basin, and FormBee, it is the strongest free option as of September 2026, because it removes submission caps without adding a server to maintain.

One request before you read on: GetForms is Apache 2.0 and free. If it saves you a backend, star Luckyyaduvanshiofficial/getforms on GitHub. Stars are the signal that keeps independent open source maintained.

[INTERNAL LINK: link to the GetForms landing page (/getforms) here.]

Why HTML forms still need a backend, and why that hurts

Static sites, Webflow pages, Astro builds, and client projects all hit the same wall. A <form> needs somewhere to POST. The traditional answer means provisioning a server route, configuring SMTP credentials, writing spam checks, and storing uploads. For a contact page, that is a week of incidental work nobody wants to bill.

Hosted form backends solved the plumbing but introduced a meter. Every major closed platform rations its free tier by submission count, then sells back the basics: file uploads, auto-reply emails, API access, and signed webhooks. A page that performs well becomes a billing event. That is the exact moment GetForms targets.

How GetForms handles a submission, step by step

GetForms is a form-to-email and form-to-webhook service. You create an endpoint with a custom slug such as /f/contact-sales, paste that URL into your form’s action, and submissions land in a dashboard inbox plus every channel you configure. The documented path of a submission (Source: GetForms GitHub README):

  1. A visitor submits any HTML form or fetch POST, as JSON or multipart form data.
  2. GetForms validates, runs spam checks, saves the submission, and responds in under 15 ms.
  3. An async queue fans delivery out to email (SMTP or Resend), Discord rich embeds, Telegram, Slack, and JSON webhooks, retrying failures with exponential backoff and jitter so nothing is silently lost.

The engineering choices matter here. One process runs the Fastify v5 API and the React 19 dashboard, using under 100 MB of RAM. Storage is embedded SQLite in WAL mode with zero setup, and production clustering is one DATABASE_URL pointing at PostgreSQL or Neon DB. Every endpoint doubles as a shareable hosted form page at /f/:endpoint with customizable colors, which covers the “client has no website yet” case. The dashboard ships a triage workflow instead of a raw table: new, in_progress, and resolved statuses, read and unread state, internal admin notes, search across all fields, archiving, CSV export, and one-click test submissions from the endpoint view.

GetForms vs Formspree vs Formcarry vs Basin vs FormBee

This is the honest table. Pricing and limits below are taken from each vendor’s own pricing page in September 2026 and will drift, so treat exact dollars as dated and the structure as durable.

CapabilityGetFormsFormspreeFormcarryBasinFormBee
Pricing model100% free, cloud and self-hostedFreemium from $10/moFree Baby plan, paid from $6/moFree plan, paid from $12.50/mo billed yearlyCloud paywalled
Free-plan submissionsUnlimited forms, fair use around 5,000/mo50/month, 30-day archive1 form, 50/month1 form, 50/month, 30-day retentionPlan-capped
LicenseApache 2.0, fully openClosed SaaSClosed SaaSClosed SaaSOpen core
Database setupEmbedded SQLite WAL, or Postgres via one env varManaged onlyManaged onlyManaged onlyNeeds external DB plus Redis
Spam defenseHoneypot plus Turnstile, Altcha, and reCAPTCHAreCAPTCHA and Formshield ML filterSpam filtering includedreCAPTCHA, hCaptcha, Turnstile, WAFBasic honeypot
Newsletter double opt-inBuilt inNot on free; automation is paid-tierNot availableMailchimp plugin is paid-tierNot available
Auto-responder emailsBuilt in with template variablesPaid plans (Professional and up)Paid plansPaid plans (Growth and up)Basic text only
Alert channelsEmail, Discord, Telegram, Slack, webhooksEmail plus Discord, Slack, Telegram on free; webhooks paidEmail and built-in integrationsSlack, Discord, and webhooks paid-tierEmail only
HMAC-signed webhooksNative HMAC-SHA256Paid plansPaid plansSigned webhooks on paid tiersNone
File uploadsIncluded, up to 25 MB per submissionNone on free; 1 GB on Personal $10/moIncluded on free Baby plan; 1 GB on Starter100 MB on free; 500 MB on StarterLimited local
Submission inboxStatuses, notes, search, archive, CSV exportGeneric UI, archive gated by planStandard dashboardMinimalist, retention gated by planDated UI

Free-tier figures check out across sources: Formspree’s free plan is 50 submissions a month with no file uploads and a 30-day archive (Source: formspree.io/plans; ShipMyForm 2026 pricing breakdown). Formcarry’s Baby plan is 1 form and 50 submissions a month (Source: formcarry.com/pricing). Basin’s free plan is 1 form endpoint, 50 submissions a month, and 30-day data retention (Source: usebasin.com/pricing). FormBee’s self-hosting weight and email-only dispatch come from the GetForms published comparison.

What growth actually costs on each platform

Run the numbers at two realistic volumes.

At hobby scale, around 50 submissions a month, every platform technically works. The differences are scope, not price. Formcarry Baby allows exactly 1 form. Basin free keeps data 30 days. Formspree free keeps submissions 30 days with no uploads. GetForms allows unlimited forms with full export at the same price of zero.

At 2,000 submissions a month, a normal freelance or small-business volume, the meter starts. Formspree Professional is $20 a month with 2,000 submissions, 5 GB of uploads, autoresponses, and API access (Source: formspree.io/plans). Formcarry Basic is $19 a month ($15 a month billed yearly) with 2,000 submissions and 2 GB of uploads (Source: formcarry.com/pricing). Basin Growth is $24.17 a month billed yearly with 1,000 submissions, so 2,000 submissions means overage billing on top (Source: usebasin.com/pricing). Premium tiers climb to $60 to $99 a month. GetForms cloud stays at zero within fair use, and self-hosted GetForms stays at zero at any volume on hardware you already pay for.

That is the submission tax this launch exists to remove.

Spam filtering your visitors never see

GetForms layers four defenses, configured per form, so a newsletter signup and a job application form can carry different protection.

The default is an invisible honeypot with zero friction. Add a hidden _gotcha field that humans never see:

<form action="https://getforms.codaipro.com/f/your-form-slug" method="POST">
  <div style="display:none;" aria-hidden="true">
    <input type="text" name="_gotcha" tabindex="-1" autocomplete="off" />
  </div>
  <input type="text" name="name" placeholder="Your Name" required />
  <button type="submit">Submit</button>
</form>

Bots fill the field. Humans cannot see it. Filled submissions are flagged and dropped silently.

When a public form attracts targeted spam, three upgrades are available per form. Cloudflare Turnstile gives a near-invisible check with no tracking cookies: enable it in the form’s Advanced Settings, add the sitekey widget, and include the script. Altcha gives a cryptographic proof-of-work challenge solved on the visitor’s device, cookie-free and GDPR-friendly, pointed at the /api/altcha-challenge endpoint. Google reCAPTCHA v2 and v3 remain available for teams standardized on Google’s stack. Domain and CORS origin whitelists reject submissions forged from anywhere except your site.

Files, auto-replies, and newsletter double opt-in

Job applications, bug reports, and support tickets need attachments. GetForms accepts standard multipart uploads up to 25 MB per submission on the cloud, with MIME verification and hashed storage. Private download links ship with the inbox row and the email alert:

<form action="https://getforms.codaipro.com/f/your-form-slug" method="POST" enctype="multipart/form-data">
  <input type="text" name="applicant_name" placeholder="Full Name" required />
  <input type="email" name="applicant_email" placeholder="Email" required />
  <label for="resume">Upload Resume (PDF, DOCX):</label>
  <input type="file" id="resume" name="resume" accept=".pdf,.doc,.docx" required />
  <button type="submit">Submit Application</button>
</form>

Two features competitors consistently upsell are included. Submitter auto-responder emails send templated thank-you messages with variables such as {{name}} and {{message}}. Newsletter and waitlist forms get double opt-in verification links and confirmation workflows, which keeps signups GDPR-clean without a separate email tool.

Form behavior is controlled through reserved parameters, no dashboard visit required (Source: GetForms README):

ParameterPurpose
_nextRedirect the visitor to a custom URL after a successful submission
_subjectCustomize the email notification subject line
_replyto / emailSet the Reply-To header so inbox replies reach the submitter
_gotchaHoneypot field; legitimate visitors leave it blank
_optinTrigger the double opt-in verification flow for signups

Webhooks with signatures you can verify

Every submission can fire a JSON POST to your API, Zapier, or microservice. The payload carries the event type, form and submission IDs, timestamp, data, and files:

{
  "event": "form_submission",
  "form_id": "frm_abc123",
  "endpoint": "contact-sales",
  "submission_id": "sub_xyz789",
  "created_at": "2026-09-26T12:00:00.000Z",
  "data": {
    "name": "Jane Doe",
    "email": "jane@example.com",
    "message": "Looking for an enterprise quote"
  },
  "files": []
}

Set a webhook secret and GetForms signs each delivery with HMAC-SHA256 in the X-GetForms-Signature header. Verification is one function in Node.js:

import crypto from 'node:crypto';

function verifyGetFormsWebhook(rawBody, signatureHeader, secret) {
  const expectedSignature = crypto.createHmac('sha256', secret).update(rawBody).digest('hex');
  return crypto.timingSafeEqual(Buffer.from(signatureHeader), Buffer.from(expectedSignature));
}

Formspree, Formcarry, and Basin gate signed or API-level webhook access behind paid tiers. Here it is native on the free plan.

Going live: three integration recipes

Plain HTML works anywhere static hosting does, including Webflow, WordPress, Carrd, Ghost, and Framer. The full contact form is one action attribute plus the optional honeypot and redirect shown earlier.

Async fetch keeps single-page apps on the page with custom loading and success states:

const res = await fetch('https://getforms.codaipro.com/f/your-form-slug', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json', Accept: 'application/json' },
  body: JSON.stringify({ name: form.name.value, email: form.email.value, message: form.message.value }),
});
const result = await res.json();
if (res.ok && result.success) {
  showToast('Thank you! Your message has been sent.');
  form.reset();
}

React and Next.js follow the same endpoint with pending, success, and error states. The README ships a complete App Router component; the pattern is standard useState, FormData, and fetch, so Astro, Svelte, and Vue versions differ only in framework syntax. Nothing about the endpoint changes between frameworks, which is the point: it is an HTTP POST, not an SDK.

Self-hosting the same core on your hardware

The cloud is the fast path. Self-hosting is the sovereignty path, and it is deliberately boring. Requirements are Node.js 20 or newer. SQLite is embedded, so there is no database to install for evaluation or small production loads.

git clone https://github.com/Luckyyaduvanshiofficial/getforms.git
cd getforms

# Install dependencies for backend and frontend
npm run install:all

# Build the React dashboard
npm run build

# Start the unified server on http://localhost:3001
npm start

First boot creates an administrator (admin / admin123, also reachable as admin@getform.local), and a setup wizard at /setup handles first-run configuration. Change the password in Account settings immediately after login. Database utilities cover the operational basics: npm run db:clean purges test submissions, clean-db.js --all also purges test forms, and npm run db:reset returns local SQLite to a fresh state.

Production Docker Compose pairs the app with Caddy for automatic Let’s Encrypt HTTPS and optional PostgreSQL:

cp .env.example .env   # set DOMAIN, JWT_SECRET, SMTP credentials
docker compose up -d --build

Configuration lives in backend/.env: PORT, HOST, DOMAIN, JWT_SECRET, optional DATABASE_URL for Postgres or Neon, and global SMTP credentials that individual users can override per account in the dashboard. Reported resource use is under 100 MB of RAM for the single process, which fits a $4-a-month VPS or a Raspberry Pi.

Cloud or self-hosted: how to choose

Both run the same product with the same spam engine and dispatchers. The README frames the split plainly (Source: GetForms README):

SituationPick
You want an endpoint in under 30 seconds with zero maintenanceFree cloud at getforms.codaipro.com
You need data sovereignty, intranet, or air-gapped deploymentSelf-hosted on your hardware
Traffic exceeds cloud fair use around 5,000 submissions a monthSelf-hosted, or a dedicated setup
You want zero database operationsCloud, or self-hosted SQLite default
You need clustered high availabilitySelf-hosted with DATABASE_URL on Postgres

Bursts around 100 requests per minute per form are smoothed by the queue on the cloud, and the documented policy is no surprise invoices (Source: getforms.codaipro.com).

Migrating from Formspree without losing data

A migration takes an afternoon. Export first, while the old account still has API access. Note that Formspree’s submissions API requires Professional or higher (Source: formspree.io/plans), so pull the archive before downgrading or canceling.

Then create a GetForms endpoint with a matching slug, swap the form action to the new URL, and add the _gotcha honeypot. Recreate the thank-you redirect with _next, re-create any webhook with a fresh secret, and verify the signature handler against the payload schema above. Lock the form to your domain in Advanced Settings, send a one-click test submission from the endpoint view, and confirm delivery across email and chat channels. Keep the old endpoint live for a week to catch cached pages, then delete it.

Frequently asked questions

Is GetForms really free forever?

Yes, in both directions. The managed cloud is free with no credit card and no trial clock, sized at fair use of around 5,000 submissions a month across unlimited forms. The source is Apache 2.0, so self-hosting is free and uncapped permanently on your own hardware. Any fork or redistribution must retain copyright notices, the NOTICE file, and the provenance record per Apache 2.0 Section 4.

How is GetForms different from Formspree?

Three differences decide it for most developers. GetForms allows unlimited forms and fair-use submissions where Formspree’s free tier stops at 50 submissions a month with a 30-day archive. GetForms includes file uploads, auto-responder emails, and HMAC-signed webhooks for free, while Formspree gates them behind paid plans starting at $10 a month. And GetForms publishes Apache 2.0 source you can self-host, while Formspree is closed SaaS with export as the only exit.

Do visitors have to solve captchas?

No. The default honeypot is invisible to humans and bots fail it silently. Turnstile, Altcha, or reCAPTCHA are opt-in per form for public signups that attract targeted spam.

Can I take my data and leave?

Any time. Every submission exports as CSV or JSON from the dashboard with no limits, and an API supports programmatic pulls. The export path works identically on the cloud and self-hosted installs.

Should I use the cloud or self-host?

Use the cloud for an endpoint in under 30 seconds with zero maintenance. Self-host for data sovereignty, intranet or air-gapped deployment, or volume beyond cloud fair use. Both run the same spam engine, dispatchers, and inbox.

Where do I report bugs or request features?

On GitHub at Luckyyaduvanshiofficial/getforms. Star the repository while you are there. Open source lives on stars, issues, and pull requests, and this project is young enough that early feedback shapes its direction.

Verdict: the best free form backend for developers who ship

GetForms wins on the combination no competitor currently matches: unlimited forms on a genuinely free cloud, a triage-grade inbox, multi-channel dispatch with retries, signed webhooks, and an Apache 2.0 codebase that makes lock-in a non-issue because you can run the whole thing yourself. Formspree remains the polished closed option for teams already paying. Formcarry and Basin serve paying teams with deeper workflow needs. FormBee suits tinkerers willing to operate infrastructure. Everyone else should start here.

Start on the cloud at getforms.codaipro.com. Star the source at Luckyyaduvanshiofficial/getforms. If the project earns a place in your stack, that star is the cheapest way to keep it free.

Lucky Yaduvanshi
Written by Author

Lucky Yaduvanshi

Computer Science Student & Creator of CodAI. Passionate about 100% offline local AI software tools.

Back to All Developer Guides

Related Posts

View All Posts »