Contact forms without the backend.
Point your existing HTML form at GetForms and submissions land in your inbox — with 25 MB file uploads, silent spam filtering, and instant alerts to email, Telegram, Slack, Discord, or your own webhook. The free, open-source Formspree alternative with no submission tax.
No credit card. Unlimited forms. Fair use ≈ 5,000 submissions a month. Prefer your own server? Self-host the same Apache 2.0 core in one command — SQLite out of the box, Postgres when you grow.
Three steps to your first submission.
No server code, no npm package, no SMTP setup. If your page can render a<form>, it can use GetForms.
- 01
1. Point your form at us
Copy your endpoint URL into the form’s action attribute — or POST JSON with fetch. Plain HTML, React, Astro, Svelte, Vue, Webflow, WordPress: anything that can submit a form works. No SDK, no framework lock-in.
- 02
2. Submissions arrive, spam doesn’t
Every message is saved to your triage inbox, bots are dropped silently by the honeypot (no captchas for visitors), and files up to 25 MB come along with MIME verification and private download links.
- 03
3. Alerts go everywhere, at once
Email you, ping Telegram, Slack, or Discord, and call your webhook with an HMAC-SHA256 signature — all on every submission, with exponential-backoff retries. Export CSV or JSON whenever you want.
GetForms vs Formspree, Formcarry, Basin, and FormBee.
Most form backends are either expensive closed SaaS that taxes your growth with submission caps and monthly fees, or half-finished scripts with no UI, no spam story, and no retry queue. Here is the honest comparison:
| Capability | GetForms | Formspree | Formcarry | Basin | FormBee |
|---|---|---|---|---|---|
| Pricing | 100% free — cloud + self-host | $10–100+/mo | $15–99+/mo | $8–36+/mo | Cloud paywalled |
| Free-plan submissions | Unlimited (fair use ≈5,000/mo) | 50/month | 100/month | 250/month | Plan-capped |
| Open-source license | Apache 2.0 | Closed SaaS | Closed SaaS | Closed SaaS | Open core |
| Zero-config database | Embedded SQLite WAL (or Postgres) | Managed only | Managed only | Managed only | Needs external DB + Redis |
| Memory footprint | <100 MB RAM, one process | Unknown | Unknown | Unknown | Heavy (multi-container) |
| Modern anti-spam | Honeypot + Turnstile + Altcha + reCAPTCHA | reCAPTCHA only | reCAPTCHA | reCAPTCHA / hCaptcha | Basic honeypot |
| Newsletter double opt-in | Built in | Paid add-on | Not available | Not available | Not available |
| Auto-responder emails | Built in | Paid plans only | Paid plans only | Paid plans only | Basic text only |
| Multi-channel dispatch | Email, Discord, Telegram, Slack, webhooks | Email + basic webhook | Email, Slack, Zapier | Email, Slack, webhooks | Email only |
| Async queue with retries | Exponential backoff + jitter | Standard | Basic | Basic | No retry queue |
| HMAC-signed webhooks | Native HMAC-SHA256 | Paid plans only | Paid plans only | Paid plans only | None |
| File uploads | Included (25 MB) | Paid ($25+/mo) | Paid ($15+/mo) | Paid ($12+/mo) | Limited local |
| Triage inbox (statuses, notes, search) | Built in | Generic UI | Standard | Minimal | Dated UI |
| One-click test submissions | Built into endpoint view | Manual | Manual | Manual | Manual |
Free-tier caps as listed by each vendor in 2026: Formspree 50/mo, Formcarry 100/mo, Basin 250/mo. Paid ranges reflect public pricing pages and may change — the point stands: only GetForms is free without a cap clock.
Why GetForms wins, in detail.
No submission tax on growth
Closed SaaS form backends charge the moment your site gets traffic — a viral campaign means truncated submissions or a $100/month paywall. GetForms gives you unlimited submissions forever, on the free cloud or your own server.
Zero setup friction (SQLite WAL)
Self-hosting alternatives often means orchestrating Postgres, Redis, workers, and Nginx. GetForms boots in one command on embedded SQLite WAL — hundreds of submissions per second on a $4/month VPS or Raspberry Pi. Need clustering? Set DATABASE_URL to Postgres.
Privacy-respecting anti-spam
Competitors lean on Google reCAPTCHA alone: tracking cookies plus crosswalk puzzles for your visitors. GetForms filters silently with a honeypot, and adds Cloudflare Turnstile (frictionless) plus Altcha proof-of-work (cookie-free, GDPR-friendly) when you want more.
Multi-channel dispatch, no Zapier needed
Elsewhere, a Discord or Telegram alert means wiring up Zapier or Make on another subscription. GetForms natively formats Discord rich embeds, Telegram Markdown, Slack payloads, and signed JSON webhooks — with retries built in.
A real triage inbox, not a JSON dump
Most open-source form backends dump rows in a table. GetForms ships an agency-tier workflow: new / in_progress / resolved statuses, read state, internal notes, full-field search, archiving, and one-click CSV export.
Newsletters and auto-replies included
Double opt-in verification flows for waitlists and newsletters, plus customizable submitter auto-responder emails ({{name}}, {{message}}) — features competitors sell as $25+/month add-ons — are built into the free plan.
Drop it into your form. One URL.
No install, no build step, no client library. Replaceyour-form-slug with your endpoint and ship:
Works with static HTML, Webflow, WordPress, Carrd, Ghost, or Framer. The hidden_gotcha field traps bots; humans never see it.
<form action="https://getforms.codaipro.com/f/your-form-slug" method="POST">
<div style="display:none" aria-hidden="true">
<input type="text" name="_gotcha" tabindex="-1" autocomplete="off" />
</div>
<label for="name">Your Name</label>
<input type="text" id="name" name="name" required />
<label for="email">Email Address</label>
<input type="email" id="email" name="email" required />
<label for="message">Message</label>
<textarea id="message" name="message" rows="4" required></textarea>
<input type="hidden" name="_next" value="https://yourwebsite.com/thank-you" />
<button type="submit">Send Message</button>
</form>Submit asynchronously with your own loading and success states. File uploads useFormData + multipart instead of JSON.
const res = await fetch(
"https://getforms.codaipro.com/f/your-form-slug",
{
method: "POST",
headers: {
"Content-Type": "application/json",
Accept: "application/json",
},
body: JSON.stringify({
name: form.name.value,
email: form.email.value,
message: form.message.value,
}),
}
);
const result = await res.json();
if (res.ok && result.success) {
showToast("Thank you! Your message has been sent.");
form.reset();
}Production-ready pattern with pending, success, and error states. Same endpoint works from Astro, Svelte, or Vue — it is just an HTTP POST.
"use client";
import { useState } from "react";
export default function ContactForm() {
const [status, setStatus] = useState("idle");
async function handleSubmit(e) {
e.preventDefault();
setStatus("loading");
const data = Object.fromEntries(new FormData(e.currentTarget));
const res = await fetch("https://getforms.codaipro.com/f/your-form-slug", {
method: "POST",
headers: { "Content-Type": "application/json", Accept: "application/json" },
body: JSON.stringify(data),
});
setStatus(res.ok ? "success" : "error");
}
if (status === "success") return <p>Message received — we'll reply soon.</p>;
return (
<form onSubmit={handleSubmit}>
<input name="name" required placeholder="Your name" />
<input name="email" type="email" required placeholder="Email" />
<textarea name="message" required placeholder="Message" />
<button disabled={status === "loading"}>
{status === "loading" ? "Sending…" : "Send message"}
</button>
</form>
);
}Everything included. Free.
Unlimited forms on the free plan — fair use is about 5,000 submissions a month. No credit card, no trial clock, no per-feature upsell.
Your form, as-is
Any HTML form or fetch call works against one URL. Custom redirect after submit via _next, custom email subjects via _subject, and Reply-To picked up from the email field automatically.
Spam stays out, silently
Invisible honeypot traps bots with zero visitor friction. Layer on Cloudflare Turnstile, Altcha proof-of-work, or Google reCAPTCHA v2/v3, plus domain and CORS origin whitelists per form.
Files up to 25 MB
Resumes, screenshots, documents — standard multipart uploads, hashed and stored securely with MIME checks. Private download links land in your inbox row and your email alert.
Alerts everywhere, with retries
SMTP or Resend email, Discord rich embeds, Telegram bot messages, Slack notifications, and JSON webhooks. Failed deliveries retry with exponential backoff and jitter — submissions answer in under 15 ms.
Auto-responder + double opt-in
Thank submitters instantly with templated auto-reply emails, and run GDPR-clean newsletter or waitlist signups with built-in verification links and confirmation workflows.
Triage inbox, not a log file
Statuses (new, in_progress, resolved), read/unread, internal admin notes, search across every field, archive, and one-click CSV export. Test any endpoint with one click from its own view.
Hosted form pages
No website yet? Every endpoint doubles as a shareable standalone form page at /f/:endpoint with customizable colors — send the link, collect replies.
Leave whenever, export everything
Full CSV/JSON export with no limits, plus an API for programmatic pull. Your submissions are yours — no lock-in, no ransom pricing.
One binary, <100 MB RAM
A single process runs the Fastify v5 API and the React 19 dashboard. SQLite WAL out of the box; point DATABASE_URL at Postgres or Neon for production clustering.
Open source, Apache 2.0
The full core is on GitHub: self-host on Node.js, Docker Compose (Caddy + automatic HTTPS), or Cloudflare. Free cloud at getforms.codaipro.com if you’d rather write zero YAML.
Spam defense in layers.
Bots get stopped. Humans never notice. Every layer is per-form, so a newsletter signup and a job application form can carry different protection.
Honeypot (always on, zero friction)
A hidden _gotcha field only bots fill in. Filled submissions are flagged and dropped silently — your visitors never see a challenge, puzzle, or checkbox.
Cloudflare Turnstile
Invisible, frictionless verification with no tracking cookies. Enable it in the form’s Advanced Settings, drop in the widget with your sitekey, and forget captchas exist.
Altcha proof-of-work (GDPR-friendly)
A cryptographic challenge solved on the visitor’s device — cookie-free and fully GDPR-compliant. Ideal for privacy-first sites that refuse Google tracking.
reCAPTCHA v2/v3 + origin locks
Prefer Google’s stack? reCAPTCHA v2 and v3 are supported per form, alongside domain and CORS origin whitelists that reject submissions forged from anywhere except your site.
Verify webhooks with HMAC-SHA256
Set a webhook secret and every delivery carries anX-GetForms-Signature header. Verify it in one function — competitors charge extra for this:
import crypto from "node:crypto";
function verifyGetFormsWebhook(rawBody, signatureHeader, secret) {
const expected = crypto.createHmac("sha256", secret).update(rawBody).digest("hex");
return crypto.timingSafeEqual(Buffer.from(signatureHeader), Buffer.from(expected));
}Free cloud or your own server. Same product.
Don’t want to host? The managed cloud atgetforms.codaipro.com is 100% free with zero maintenance. Need data sovereignty? The identical Apache 2.0 core runs on your hardware:
| You want… | Free Cloud | Self-Hosted |
|---|---|---|
| Instant setup, zero maintenance | ● Sign up, copy your endpoint — under 30 seconds, backups handled | git clone + npm start in under 2 minutes, one lightweight process |
| Pricing | ● 100% free — no card, no trial clock, no hidden limits | 100% free — unlimited forever on your own hardware |
| Custom endpoint slugs | ● /f/contact-sales, /f/newsletter — supported | Same — /f/contact-sales, /f/newsletter supported |
| Spam protection | ● Honeypot, Turnstile, Altcha, reCAPTCHA | Identical — same engine, your keys |
| Alerts | ● Email, Discord, Telegram, Slack, webhooks | Identical — same dispatchers, your credentials |
| Data control | ● Managed dashboard with CSV/JSON export anytime | 100% data sovereignty — SQLite file or your Postgres, air-gap capable |
Self-host in under 2 minutes
Node.js 20+ is the only requirement. SQLite WAL means no database to install:
git clone https://github.com/Luckyyaduvanshiofficial/getforms.git
cd getforms
npm run install:all
npm run build
npm start
# open http://localhost:3001 (login: admin / admin123, then change it)Production with Docker + HTTPS
Caddy provisions Let’s Encrypt certificates automatically; Postgres is one env var away:
cp .env.example .env # set DOMAIN, JWT_SECRET, SMTP creds
docker compose up -d --build
# DATABASE_URL=postgresql://user:pass@localhost:5432/getformsQuestions, answered.
- Do I need a backend to use GetForms?
- No. Point your form’s action attribute (or a fetch call) at your GetForms endpoint URL and you are done — submissions are saved, spam is filtered silently, and alerts go out to email, Telegram, Slack, Discord, or your webhook. There is no server code to write and no npm package to install.
- How does spam filtering work without a captcha?
- Every form gets a hidden honeypot field (_gotcha) that humans never see but bots fill in — filled submissions are dropped silently. If you want stronger protection, Cloudflare Turnstile, Altcha proof-of-work, or Google reCAPTCHA v2/v3 can be switched on per form, plus domain and CORS origin whitelists.
- Are email, Telegram, Slack, and webhook alerts really free?
- Yes. Email forwarding, Telegram and Slack alerts, Discord rich embeds, and JSON webhooks with automatic retries and exponential backoff are all included on the free plan. HMAC-SHA256 webhook signatures are included too — competitors charge for them.
- Can I accept file uploads through my forms?
- Yes. Attach resumes, screenshots, PDFs, or receipts via standard multipart uploads (up to 25 MB per submission on the cloud). Files are stored securely with MIME verification, and a private download link ships with every alert and inbox row.
- Can I export my submissions and leave whenever I want?
- Any time. Download everything as CSV or JSON from the dashboard in one click, or pull submissions through the API. There are no export limits and no lock-in.
- Can I self-host GetForms instead of using the cloud?
- Yes. GetForms is Apache 2.0 licensed with the full source on GitHub. It boots in one command using embedded SQLite in WAL mode (under 100 MB RAM, no Docker or Postgres required), runs as a single Fastify + React process, and scales to PostgreSQL or Neon DB by setting DATABASE_URL. Docker Compose with Caddy and automatic HTTPS is provided for production.
- What happens if my form goes viral and traffic spikes?
- Submissions return in under 15 ms because delivery runs on an async queue with retries — bursts around 100 requests per minute per form are smoothed, and nothing is dropped. The cloud will never surprise you with an invoice; if you outgrow fair use (≈5,000 submissions/month), you can move to a dedicated setup or self-host with zero limits.
- How is GetForms different from Formspree, Formcarry, or Basin?
- Formspree caps its free plan at 50 submissions/month and charges $10–100+/month for uploads, auto-responders, and signed webhooks. Formcarry ($15–99+/month) and Basin ($8–36+/month) are closed-source with strict free caps. GetForms is 100% free with unlimited forms, built-in double opt-in newsletters, auto-responder emails, Discord/Telegram/Slack dispatch, HMAC-signed webhooks, and a triage inbox — plus Apache 2.0 source you can self-host.
Get your first submission today.
Create a free endpoint and point your form at it. No card, no trial — and the source is yours to keep under Apache 2.0.
$0 · unlimited forms · fair use ≈ 5,000 submissions/month · Apache 2.0