Webhooks

Formgong POSTs JSON and an HMAC-SHA256 signature of the raw body. The secret is in the form settings. Up to 5 attempts, delayed by 30s, 2m, 10m, 30m, and 2h.

{
  "event": "submission.created",
  "form": { "id": "…", "name": "…" },
  "submission": {
    "id": "…",
    "created_at": "2026-09-29T12:00:00.000Z",
    "page_url": "https://example.com/",
    "fields": { "name": "Olena", "email": "olena@example.com" },
    "is_spam": false
  }
}

Header X-Signature: sha256=…. Header X-Formgong-Event: submission.created.

import { createHmac, timingSafeEqual } from "node:crypto";

function verified(rawBody, signature, secret) {
  const digest = createHmac("sha256", secret).update(rawBody).digest();
  const got = Buffer.from(String(signature).replace(/^sha256=/, ""), "hex");
  return got.length === digest.length && timingSafeEqual(got, digest);
}

Make, n8n, Zapier

Create a webhook module (Make), a Webhook node (n8n), or a Catch Hook (Zapier) and paste that URL into the form settings. Map submission.fields from there.

Google Sheets

function doPost(e) {
  const body = JSON.parse(e.postData.contents);
  const fields = body.submission.fields;
  SpreadsheetApp.getActive().getSheetByName("Leads").appendRow([
    body.submission.created_at, fields.name, fields.email, fields.message,
  ]);
  return ContentService.createTextOutput("ok");
}

KeyCRM

There is no native connector. In n8n or Make, receive the Formgong webhook and call the KeyCRM API with your own key. Read fields from submission.fields.