Why add a rules file
A prompt fixes the form once. A coding agent that edits the project weeks later doesn't remember that prompt. It may "improve" the form with an API route, drop the honeypot, or swap in a made-up key. A rules file sits in the repository, and the agent reads it before it works, so the form rules travel with the code.
All four files below contain the same rules. Only the wrapper differs, because each tool reads its own file. The rules match the agents.md reference and the copy-paste prompts.
AGENTS.md
For most coding agents. Save it as AGENTS.md in the project root, or add the section to the AGENTS.md you already have.
# AGENTS.md
<!-- Formgong form rules. Source: https://formgong.com/agent-rules/AGENTS.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and tell the user to replace it, or get it from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
CLAUDE.md
For Claude Code. Save it as CLAUDE.md in the project root, or add the section to your existing CLAUDE.md.
# CLAUDE.md
<!-- Formgong form rules for Claude Code. Source: https://formgong.com/agent-rules/CLAUDE.md -->
<!-- If this repository already has these rules in AGENTS.md, this file can be one line instead: @AGENTS.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and tell the user to replace it, or get it from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
.cursor/rules/formgong.mdc
For Cursor. Save it as .cursor/rules/formgong.mdc. Cursor applies it when a task involves a form.
Download .cursor/rules/formgong.mdc
---
description: Formgong form rules. Use when adding, editing, or debugging a website form, contact page, or form submission.
alwaysApply: false
---
<!-- Save as .cursor/rules/formgong.mdc. Source: https://formgong.com/agent-rules/formgong.mdc -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and tell the user to replace it, or get it from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
.windsurfrules
For Windsurf. Append it to .windsurfrules in the project root.
<!-- Formgong form rules for Windsurf. Append to .windsurfrules in the project root. Source: https://formgong.com/agent-rules/windsurfrules.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and tell the user to replace it, or get it from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
Where each file goes
- AGENTS.md in the project root. Many coding agents read it, including Cursor and Windsurf.
- CLAUDE.md in the project root for Claude Code. If you already keep the rules in AGENTS.md, CLAUDE.md can be one line: @AGENTS.md.
- .cursor/rules/formgong.mdc for Cursor project rules. Its description tells Cursor to use the rule when you work on a form.
- .windsurfrules in the project root for Windsurf. Newer versions also read rule files in .windsurf/rules or .devin/rules.
None of the files contain a secret. The access key in your code is public, and the API token for the MCP server stays in your tool's settings or an environment variable.
Questions
Which file do I need?
The one your tool reads. If you use several tools, keep AGENTS.md and point the others to it, for example with @AGENTS.md in CLAUDE.md.
Can I edit the rules?
Yes. Change the language code, add your own thank-you page for _redirect, or remove the MCP part if you don't use it. Keep the endpoint, access_key and botcheck rules as they are.
Is it safe to commit these files?
Yes. They contain no secrets. Your access key is public by design, and the files tell the agent never to write an API token or other secret into the project.
Do the rules replace the prompts?
No, they work together. Use a prompt to add the form, and the rules file to keep it correct while the agent keeps changing the project.
Sources
Checked on 04.10.2026 against these public pages: AGENTS.md, Claude Code: CLAUDE.md, Cursor: Rules, Windsurf (Devin Desktop): rules.