Webhooks

Formgong envía un POST JSON y una firma HMAC-SHA256 del cuerpo en bruto. El secreto está en los ajustes del formulario. Hasta 5 intentos, con pausas de 30 s, 2 min, 10 min, 30 min y 2 h.

{
  "event": "submission.created",
  "form": { "id": "…", "name": "…" },
  "submission": {
    "id": "…",
    "created_at": "2026-09-29T12:00:00.000Z",
    "page_url": "https://example.com/",
    "fields": { "name": "Olena", "email": "olena@example.com" },
    "is_spam": false
  }
}

Header X-Signature: sha256=…. Header X-Formgong-Event: submission.created.

import { createHmac, timingSafeEqual } from "node:crypto";

function verified(rawBody, signature, secret) {
  const digest = createHmac("sha256", secret).update(rawBody).digest();
  const got = Buffer.from(String(signature).replace(/^sha256=/, ""), "hex");
  return got.length === digest.length && timingSafeEqual(got, digest);
}

Make, n8n, Zapier

Crea un módulo de webhook (Make), un Webhook node (n8n) o un Catch Hook (Zapier) y pega esa URL en los ajustes del formulario. Desde ahí asigna submission.fields.

Google Sheets

function doPost(e) {
  const body = JSON.parse(e.postData.contents);
  const fields = body.submission.fields;
  SpreadsheetApp.getActive().getSheetByName("Leads").appendRow([
    body.submission.created_at, fields.name, fields.email, fields.message,
  ]);
  return ContentService.createTextOutput("ok");
}

KeyCRM

No hay conector nativo. En n8n o Make, recibe el webhook de Formgong y llama a la API de KeyCRM con tu propia clave. Los campos están en submission.fields.