Forms
Forms are first-class content. Manage them under Content → Forms (/cp/forms).
Definitions:
content/sites/{CMS_SITE}/forms/{slug}.jsonSubmissions: host database table
form_submissionsOptional email notification per form (or Tools → Email From). Turn off to store in Submissions only.
CSV export from Submissions. File fields download from the submission detail. Uploads are encrypted at rest.
On submit actions
Email notification — optional; can be disabled per form.
Webhook (optional) — enable on the form edit screen to POST JSON to an HTTPS URL after the submission is saved. Payload includes
event(form.submitted),site,formmetadata, labeledfields, andsubmitted_at. Failures are logged only (the visitor still sees success). Use for CRM/Zapier-style integrations — not a full form automation builder.
Do not enable webhooks on PHI/HIPAA forms unless the endpoint is covered under your BAA — payloads include field values.
HIPAA-aware forms
Off by default under Identity → Site Settings → Extras. Turning it on requires confirming that this install (and any mail or form vendor) uses HIPAA-compliant servers or form services. Coaptive CMS does not make your host or inbox HIPAA-compliant. When on, submissions older than 90 days (configurable) are purged daily. Mark individual forms with This form collects Personal Health Information. Notification email then omits field values and must go to an encrypted channel.
Field types
text, email, tel, textarea, select, checkbox, date, consent, file.
date — HTML date input
consent — required-style checkbox when marked required
file — stored under
storage/app/private/form-uploads/…(not public web root)
Placement on pages
Attached form — on page edit, choose Attached form (renders after the body).
Embed — TipTap Form toolbar button inserts a mid-content placeholder.
Page Builder → Form section — same live form inside a section block.
Public submit & CAPTCHA
POST /forms/{slug} (throttled) validates against the definition, ignores honeypot website, optionally verifies CAPTCHA when Tools → CAPTCHA has “Public forms” enabled, then stores a submission.
CAPTCHA providers: Cap (self-hosted), Cloudflare Turnstile, Google reCAPTCHA v2/v3, hCaptcha. Secrets live in storage/app/private/captcha-settings.json (encrypted) — never commit them.