Wozu eine Regeldatei
Ein Prompt repariert das Formular einmal. Ein Agent, der das Projekt Wochen später bearbeitet, erinnert sich nicht an diesen Prompt. Er „verbessert“ das Formular vielleicht mit einer API-Route, entfernt den Honeypot oder setzt einen erfundenen Schlüssel ein. Die Regeldatei liegt im Repository, und der Agent liest sie vor der Arbeit, sodass die Formularregeln mit dem Code mitwandern.
Alle vier Dateien unten enthalten dieselben Regeln. Nur die Hülle unterscheidet sich, weil jedes Tool seine eigene Datei liest. Die Regeln passen zur Referenz agents.md und zu den fertigen Prompts. Die Regeln selbst sind auf Englisch: So verstehen Agenten Anweisungen am zuverlässigsten.
AGENTS.md
Für die meisten Agenten. Speichern Sie die Datei als AGENTS.md im Projektstamm oder fügen Sie den Abschnitt einer bestehenden AGENTS.md hinzu.
# AGENTS.md
<!-- Formgong form rules. Source: https://formgong.com/agent-rules/AGENTS.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
CLAUDE.md
Für Claude Code. Speichern Sie die Datei als CLAUDE.md im Projektstamm oder fügen Sie den Abschnitt einer bestehenden CLAUDE.md hinzu.
# CLAUDE.md
<!-- Formgong form rules for Claude Code. Source: https://formgong.com/agent-rules/CLAUDE.md -->
<!-- If this repository already has these rules in AGENTS.md, this file can be one line instead: @AGENTS.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
.cursor/rules/formgong.mdc
Für Cursor. Speichern Sie die Datei als .cursor/rules/formgong.mdc. Cursor wendet sie an, wenn es bei einer Aufgabe um ein Formular geht.
Herunterladen .cursor/rules/formgong.mdc
---
description: Formgong form rules. Use when adding, editing, or debugging a website form, contact page, or form submission.
alwaysApply: false
---
<!-- Save as .cursor/rules/formgong.mdc. Source: https://formgong.com/agent-rules/formgong.mdc -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
.windsurfrules
Für Windsurf. Hängen Sie den Inhalt an .windsurfrules im Projektstamm an.
<!-- Formgong form rules for Windsurf. Append to .windsurfrules in the project root. Source: https://formgong.com/agent-rules/windsurfrules.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
Wohin jede Datei gehört
- AGENTS.md im Projektstamm. Viele Agenten lesen sie, darunter Cursor und Windsurf.
- CLAUDE.md im Projektstamm für Claude Code. Stehen die Regeln schon in AGENTS.md, kann CLAUDE.md aus einer Zeile bestehen: @AGENTS.md.
- .cursor/rules/formgong.mdc für Projektregeln in Cursor. Seine Beschreibung sagt Cursor, die Regel anzuwenden, wenn Sie an einem Formular arbeiten.
- .windsurfrules im Projektstamm für Windsurf. Neuere Versionen lesen auch Regeldateien in .windsurf/rules oder .devin/rules.
Keine Datei enthält Geheimnisse. Der Zugriffsschlüssel in Ihrem Code ist öffentlich, und das API-Token für den MCP-Server bleibt in den Einstellungen des Tools oder in einer Umgebungsvariable.
Noch kein Zugangsschlüssel? Der Link zum Anlegen eines Formulars
Die Regeln decken auch den Fall ab, dass der Agent Ihren Zugangsschlüssel nicht kennt. Statt einen zu erfinden, kann er Ihnen einen Link wie diesen geben:
https://formgong.com/new?name=Contact%20form&site=https%3A%2F%2Fexample.com&redirect=https%3A%2F%2Fexample.com%2FthanksAlle drei Parameter sind optional. name ist der Formularname, site dient als Standardname, und redirect wird die Dankeseite des Formulars (eine vollständige https-Adresse). Formgong zeigt diese Einstellungen zuerst. Sie melden sich an oder geben Ihre E-Mail-Adresse ein, können Namen und Dankeseite ändern und bestätigen. Das Öffnen des Links legt allein kein Formular an, und Formgong leitet Sie von dieser Seite nie zur redirect-Adresse weiter.
Nach der Bestätigung sehen Sie den Zugangsschlüssel und eine kurze Nachricht, die Sie in Ihr KI-Tool zurückkopieren. Ist das Tool mit dem MCP-Server verbunden, legt es das Formular selbst an und braucht den Link nicht.
Fragen und Antworten
Welche Datei brauche ich?
Die Datei, die Ihr Tool liest. Nutzen Sie mehrere Tools, pflegen Sie AGENTS.md und verweisen Sie aus den anderen darauf, etwa mit der Zeile @AGENTS.md in CLAUDE.md.
Darf ich die Regeln ändern?
Ja. Ändern Sie den Sprachcode, ergänzen Sie eine eigene Dankeseite für _redirect oder entfernen Sie den MCP-Teil, wenn Sie MCP nicht nutzen. Die Regeln zu Adresse, access_key und botcheck lassen Sie unverändert.
Ist es sicher, diese Dateien zu committen?
Ja. Sie enthalten keine Geheimnisse. Ihr Zugriffsschlüssel ist absichtlich öffentlich, und die Dateien weisen den Agenten an, nie ein API-Token oder andere Geheimnisse ins Projekt zu schreiben.
Ersetzen die Regeln die Prompts?
Nein, sie arbeiten zusammen. Fügen Sie das Formular mit einem Prompt hinzu und halten Sie es mit der Regeldatei korrekt, während der Agent das Projekt weiter ändert.
Quellen
Geprüft am 04.10.2026 anhand offizieller Hilfeseiten und öffentlicher Seiten: AGENTS.md, Claude Code: CLAUDE.md, Cursor: Rules, Windsurf (Devin Desktop): rules.