Before you start
- Formgong: any plan. A Free form can have one webhook; Pro and Business forms can have five.
- Make: the Free plan works. It has 1,000 credits a month and two active scenarios. Reading a webhook bundle uses credits, like any module.
- Time: about ten minutes, plus one real test submission.
Step by step
- In Make, create a scenario. Search for Webhooks and pick Custom webhook.
- Next to Webhook, click Add. Name it, for example Formgong – Contact. Leave API Key authentication empty: Formgong cannot send the
x-make-apikeyheader. Click Save and copy the URL. - In Formgong, open My forms → your form → Form settings → Webhook. Paste the URL and click Add webhook.
- Back in Make, click Run once. The module now waits for data.
- Send one real submission from your site. A real one is better than Send test, because the test only has a
messagefield. - Make shows the data structure it found. Add the next module, for example Google Sheets → Add a row, and map the fields.
- Save the scenario and switch it on. Webhook scenarios run as soon as data arrives.
What Make receives
Every real submission arrives as one JSON bundle. Your form fields sit under submission.fields, with the names from your HTML. All values are text.
{
"event": "submission.created",
"form": {
"id": "6f1c2a9e-4b7d-4e0a-9c3f-2d8b5e7a1f40",
"name": "Contact"
},
"submission": {
"id": "b3e04c51-8a2f-4d6e-9f17-0c5a3b8d2e96",
"created_at": "2026-10-03T09:15:00.000Z",
"page_url": "https://example.com/contact",
"fields": {
"name": "Sam Carter",
"email": "sam@example.com",
"phone": "+447700900123",
"message": "Can you send a quote for 20 units?",
"utm_source": "google"
},
"is_spam": false
}
}Control fields such as access_key, _redirect and botcheck are removed. If the form takes files, an attachments list adds names, sizes and links. Those links need a signed-in Formgong owner, so Make cannot download the files.
Request headers
POST <your webhook URL>
Content-Type: application/json
User-Agent: Formgong-Webhook
X-Formgong-Event: submission.created
X-Signature: sha256=<64 hex characters>Field mapping
In Make, module 1 is the Custom webhook. Click a field in the mapping panel, or type the path.
| You want | Map this in Make |
|---|---|
| Name, email, phone | {{1.submission.fields.name}}, …email, …phone |
| Message | {{1.submission.fields.message}} |
| Page the form was on | {{1.submission.page_url}} |
| Time (UTC) | {{1.submission.created_at}} |
| Unique ID for de-duplication | {{1.submission.id}} |
If you add a field to the form later, open the webhook module, click Detect new values and send one more submission.
Optional: check the signature
Anyone who learns the webhook URL could post fake data to it. The signature stops that. Formgong signs the raw body with HMAC-SHA256, using the form's Signing secret from the Webhook tab.
- Edit the webhook in Make. Set Get request headers to Yes and turn on JSON pass-through.
- Add a filter after the webhook with the condition below. Make's
sha256function returns an HMAC when you give it a key. - Add JSON → Parse JSON after the filter, so you can map the fields again.
Make filter
Filter condition (Text operators: Equal to)
sha256(<raw JSON text from module 1>; "hex"; "<your signing secret>")
equals
replace(first(map(1.headers; "value"; "name"; "x-signature")); "sha256="; "")Check the names in your first bundle: header names usually arrive in lower case. Test with one real submission before you rely on it. The secret is visible to anyone who can edit the scenario. If you click Rotate secret in Formgong, update the filter too.
Testing and retries
- Make answers
200 Acceptedas soon as the bundle is in its queue. Formgong marks that delivery as sent. - Formgong's Recent deliveries list shows every attempt with its status code. Start there when data is missing.
- If Make answers with an error or takes over 10 seconds, Formgong retries after 30 seconds, 2 minutes, 10 minutes and 30 minutes.
- A retry after a slow answer can bring the same submission twice. Use
submission.idto skip rows you already have.
Troubleshooting
- 410 Gone: Make turns off a webhook that has not been linked to a scenario for 5 days. Link it again or create a new one and update the URL in Formgong.
- 400 Queue is full: the scenario is off or out of credits, and the queue reached its limit. Switch it on or add credits; Formgong retries for about 42 minutes.
- 429: Make allows 300 requests per 10 seconds per webhook. A form will rarely hit this.
- Fields missing: click Detect new values and send a new submission.
- Checkbox group in one field: ticked boxes with the same name arrive as one string, for example
Email, Phone. To get an array, use{{split(1.submission.fields.contact; ", ")}}. - Nothing in Recent deliveries: the submission was marked as spam or held. Check the form inbox.
Questions
Does every submission cost Make credits?
Yes. Make counts credits for module actions, and reading webhook data is one of them. A short scenario uses a few credits per submission. Make's Free plan has 1,000 a month.
Can I use one webhook for several forms?
Yes. Paste the same Make URL into each form. Use form.id or form.name in a router or filter to tell them apart.
Why does Make not get the uploaded files?
Formgong sends file links, not file bytes. The links need a signed-in form owner, so open files from the Formgong dashboard instead.
Can Make reply to the visitor?
Not through the webhook. The visitor sees Formgong's thank-you page or your redirect. Use Formgong's autoreply, or send an email from the scenario.
Sources
Checked on 03.10.2026 against these public pages: Make: Webhooks app (Custom webhook), Make Help: Webhooks, Make: text functions (sha256), Make pricing, Formgong webhook reference.