Forms

Forms are first-class content. Manage them under Content → Forms (/cp/forms).

  • Definitions: content/sites/{CMS_SITE}/forms/{slug}.json

  • Submissions: host database table form_submissions

  • Optional email notification per form (or Tools → Email From). Turn off to store in Submissions only.

  • CSV export from Submissions. File fields download from the submission detail. Uploads are encrypted at rest.

On submit actions

  • Email notification — optional; can be disabled per form.

  • Webhook (optional) — enable on the form edit screen to POST JSON to an HTTPS URL after the submission is saved. Payload includes event (form.submitted), site, form metadata, labeled fields, and submitted_at. Failures are logged only (the visitor still sees success). Use for CRM/Zapier-style integrations — not a full form automation builder.

Do not enable webhooks on PHI/HIPAA forms unless the endpoint is covered under your BAA — payloads include field values.

HIPAA-aware forms

Off by default under Identity → Site Settings → Extras. Turning it on requires confirming that this install (and any mail or form vendor) uses HIPAA-compliant servers or form services. Coaptive CMS does not make your host or inbox HIPAA-compliant. When on, submissions older than 90 days (configurable) are purged daily. Mark individual forms with This form collects Personal Health Information. Notification email then omits field values and must go to an encrypted channel.

Field types

text, email, tel, textarea, select, checkbox, date, consent, file.

  • date — HTML date input

  • consent — required-style checkbox when marked required

  • file — stored under storage/app/private/form-uploads/… (not public web root)

Placement on pages

  1. Attached form — on page edit, choose Attached form (renders after the body).

  2. Embed — TipTap Form toolbar button inserts a mid-content placeholder.

  3. Page Builder → Form section — same live form inside a section block.

Public submit & CAPTCHA

POST /forms/{slug} (throttled) validates against the definition, ignores honeypot website, optionally verifies CAPTCHA when Tools → CAPTCHA has “Public forms” enabled, then stores a submission.

CAPTCHA providers: Cap (self-hosted), Cloudflare Turnstile, Google reCAPTCHA v2/v3, hCaptcha. Secrets live in storage/app/private/captcha-settings.json (encrypted) — never commit them.