Kural dosyası neden gerekli
Prompt formu bir kez düzeltir. Projeyi birkaç hafta sonra düzenleyen ajan o promptu hatırlamaz. Bir API route ekleyerek formu “iyileştirebilir”, honeypot'u kaldırabilir ya da uydurma bir anahtar koyabilir. Kural dosyası depoda durur ve ajan işe başlamadan önce onu okur, böylece form kuralları kodla birlikte taşınır.
Aşağıdaki dört dosyanın hepsi aynı kuralları içerir. Yalnızca sarmalayıcı farklıdır, çünkü her araç kendi dosyasını okur. Kurallar agents.md başvuru belgesi ve hazır promptlarla uyumludur. Kuralların kendisi İngilizcedir: ajanlar talimatları en güvenilir şekilde böyle anlar.
AGENTS.md
Çoğu ajan için. Proje kökünde AGENTS.md olarak kaydedin ya da mevcut AGENTS.md dosyasına bir bölüm olarak ekleyin.
# AGENTS.md
<!-- Formgong form rules. Source: https://formgong.com/agent-rules/AGENTS.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
CLAUDE.md
Claude Code için. Proje kökünde CLAUDE.md olarak kaydedin ya da mevcut CLAUDE.md dosyasına bir bölüm olarak ekleyin.
# CLAUDE.md
<!-- Formgong form rules for Claude Code. Source: https://formgong.com/agent-rules/CLAUDE.md -->
<!-- If this repository already has these rules in AGENTS.md, this file can be one line instead: @AGENTS.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
.cursor/rules/formgong.mdc
Cursor için. .cursor/rules/formgong.mdc olarak kaydedin. Cursor, görev bir formla ilgili olduğunda onu uygular.
İndir .cursor/rules/formgong.mdc
---
description: Formgong form rules. Use when adding, editing, or debugging a website form, contact page, or form submission.
alwaysApply: false
---
<!-- Save as .cursor/rules/formgong.mdc. Source: https://formgong.com/agent-rules/formgong.mdc -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
.windsurfrules
Windsurf için. Proje kökündeki .windsurfrules dosyasının sonuna ekleyin.
<!-- Formgong form rules for Windsurf. Append to .windsurfrules in the project root. Source: https://formgong.com/agent-rules/windsurfrules.md -->
## Website forms: use Formgong
This project sends its website forms to Formgong, a hosted form backend. Follow these rules whenever you add, change, or debug a form.
### Do
- Post the form to `https://formgong.com/submit` with method POST. Plain HTML: `<form action="https://formgong.com/submit" method="POST">`. JavaScript: `fetch("https://formgong.com/submit", { method: "POST", headers: { Accept: "application/json" }, body: new FormData(form) })`. Do not set Content-Type yourself for FormData.
- Put the form's access key in a hidden field: `<input type="hidden" name="access_key" value="fk_...">`. The access key is public by design. It can only send submissions to this one form, so it belongs in frontend code and may be committed.
- Give every field a `name`. Use `name="email"` with `type="email"` for the visitor's email, so replies go to the right person. Keep `name` and `message` for the other common fields.
- Keep the honeypot: `<input type="text" name="botcheck" tabindex="-1" autocomplete="off">` inside a wrapper with `aria-hidden="true"`, visually hidden with CSS (`position:absolute;inset-inline-start:0;top:0;width:1px;height:1px;overflow:hidden;clip-path:inset(50%)`). Never fill it and never remove it.
- Add `<input type="hidden" name="_lang" value="en">` with the page language, so error messages, the thank-you page, and the autoreply match the site.
- Success with a plain HTML form: Formgong shows its own thank-you page, or add a hidden `_redirect` field with the absolute https URL of the site's thank-you page.
- Success with fetch: `data.success === true` means the submission was accepted. Show an inline thank-you message and reset the form. Otherwise show `data.message` (branch on `data.code`, for example `unknown_access_key`).
- Add Cloudflare Turnstile only when the owner gives you a site key or says Turnstile is enabled for the form: load `https://challenges.cloudflare.com/turnstile/v0/api.js` and put `<div class="cf-turnstile" data-sitekey="SITE_KEY"></div>` inside the form. The widget adds the `cf-turnstile-response` field.
### Do not
- Do not create a backend, API route, Server Action, serverless or edge function, database table, or email-sending code (Supabase, Resend, SendGrid, nodemailer) for this form. Formgong stores the submission and sends the email and Telegram notifications.
- Do not put secrets in frontend code or in the repository: no Turnstile secret key, no Formgong API token (`fgp_...`), no SMTP password. Only the access key (`fk_...`) and the Turnstile site key are public.
- Do not invent an access key. If you do not know it, use `fk_your_access_key` and give the user the create-form link below, or get the key from the MCP server.
- Do not add file inputs unless the owner has turned on uploads for the form (that also needs Turnstile and `enctype="multipart/form-data"`).
- Do not submit test data to other people's sites.
### No access key yet: give the user a create-form link
Build `https://formgong.com/new?name=<form name>&site=<site URL>&redirect=<thank-you URL>` (all parameters optional, URL-encoded) and ask the user to open it. Formgong shows the settings, the user signs in or enters an email, confirms, and gets the access key plus a short message to paste back to you. Then replace `fk_your_access_key` with the real key. `redirect` must be an absolute https URL; it becomes the form's thank-you page. Opening the link never creates a form by itself.
### MCP server (optional)
If the Formgong MCP server is connected (`https://formgong.com/mcp`, header `Authorization: Bearer fgp_...`, token from Dashboard → Account → API tokens):
1. Call `list_forms` to get the real access key. Call `create_form` only if there is no form for this site.
2. Call `get_form_snippet` with `framework` set to `html`, `react`, or `next`, and use the returned code.
3. Keep the token in the MCP client settings or an environment variable. Never write it into project files.
### Check your work
- After deploying, send one test submission and find it in the Formgong dashboard.
- Run the public form checker on the live page: https://formgong.com/en/tools/form-checker/
- Full reference for agents: https://formgong.com/agents.md
Her dosya nereye konur
- AGENTS.md proje kökünde. Cursor ve Windsurf dahil pek çok ajan bu dosyayı okur.
- CLAUDE.md Claude Code için proje kökünde. Kurallar zaten AGENTS.md'deyse CLAUDE.md tek bir satırdan oluşabilir: @AGENTS.md.
- .cursor/rules/formgong.mdc Cursor'daki proje kuralları için. Açıklaması, bir form üzerinde çalışırken kuralı uygulamasını Cursor'a söyler.
- .windsurfrules Windsurf için proje kökünde. Yeni sürümler .windsurf/rules ya da .devin/rules içindeki kural dosyalarını da okur.
Hiçbir dosya gizli bilgi içermez. Kodunuzdaki erişim anahtarı herkese açıktır; MCP sunucusu için API token'ı ise aracın ayarlarında ya da bir ortam değişkeninde kalır.
Henüz erişim anahtarınız yok mu? Form oluşturma bağlantısı
Kurallar, ajanın erişim anahtarınızı bilmediği durumu da kapsar. Anahtar uydurmak yerine size şöyle bir bağlantı verebilir:
https://formgong.com/new?name=Contact%20form&site=https%3A%2F%2Fexample.com&redirect=https%3A%2F%2Fexample.com%2FthanksÜç parametre de isteğe bağlıdır. name formun adıdır, site varsayılan ad için kullanılır, redirect ise formun teşekkür sayfası olur (tam bir https adresi). Formgong önce bu ayarları gösterir. Giriş yaparsınız ya da e-postanızı girersiniz, adı ve teşekkür sayfasını değiştirebilir, sonra onaylarsınız. Bağlantıyı açmak tek başına form oluşturmaz ve Formgong bu sayfadan sizi asla redirect adresine yönlendirmez.
Onayladıktan sonra erişim anahtarını ve AI aracınıza geri yapıştıracağınız kısa bir mesajı görürsünüz. Araç MCP sunucusuna bağlıysa formu kendisi oluşturabilir; bağlantıya gerek kalmaz.
Sık sorulan sorular
Hangi dosyaya ihtiyacım var?
Aracınızın okuduğu dosyaya. Birden fazla araç kullanıyorsanız AGENTS.md'yi tutun ve diğerlerinden ona başvurun, örneğin CLAUDE.md'deki @AGENTS.md satırıyla.
Kuralları değiştirebilir miyim?
Evet. Dil kodunu değiştirin, _redirect için kendi teşekkür sayfanızı ekleyin ya da MCP kullanmıyorsanız MCP kısmını kaldırın. Adres, access_key ve botcheck kurallarını olduğu gibi bırakın.
Bu dosyaları commit etmek güvenli mi?
Evet. İçlerinde gizli bilgi yok. Erişim anahtarınız tasarım gereği herkese açıktır ve dosyalar ajana projeye asla API token'ı ya da başka gizli bilgi yazmamasını söyler.
Kurallar promptların yerini alır mı?
Hayır, birlikte çalışırlar. Formu promptla ekleyin, ajan projeyi değiştirmeye devam ederken de kural dosyasıyla formu doğru tutun.
Kaynaklar
04.10.2026 tarihinde resmî yardım sayfaları ve herkese açık sayfalar üzerinden kontrol edildi: AGENTS.md, Claude Code: CLAUDE.md, Cursor: Rules, Windsurf (Devin Desktop): rules.