Webhook

FormgongはJSONをPOSTし、生の本文にHMAC-SHA256の署名を付けます。シークレットはフォーム設定にあります。再送は最大5回で、間隔は30秒、2分、10分、30分、2時間です。

{
  "event": "submission.created",
  "form": { "id": "…", "name": "…" },
  "submission": {
    "id": "…",
    "created_at": "2026-09-29T12:00:00.000Z",
    "page_url": "https://example.com/",
    "fields": { "name": "Olena", "email": "olena@example.com" },
    "is_spam": false
  }
}

Header X-Signature: sha256=…. Header X-Formgong-Event: submission.created.

import { createHmac, timingSafeEqual } from "node:crypto";

function verified(rawBody, signature, secret) {
  const digest = createHmac("sha256", secret).update(rawBody).digest();
  const got = Buffer.from(String(signature).replace(/^sha256=/, ""), "hex");
  return got.length === digest.length && timingSafeEqual(got, digest);
}

Make, n8n, Zapier

Webhookモジュール(Make)、Webhook node(n8n)、またはCatch Hook(Zapier)を作り、そのURLをフォーム設定に貼ってください。そこから submission.fields を割り当てます。

Google Sheets

function doPost(e) {
  const body = JSON.parse(e.postData.contents);
  const fields = body.submission.fields;
  SpreadsheetApp.getActive().getSheetByName("Leads").appendRow([
    body.submission.created_at, fields.name, fields.email, fields.message,
  ]);
  return ContentService.createTextOutput("ok");
}

KeyCRM

専用コネクタはありません。n8nかMakeでFormgongのWebhookを受け、自分のキーでKeyCRM APIを呼びます。値は submission.fields から読んでください。