@npm_tentwenty/strapi-formidable
v1.2.4
Published
Strapi Formidable is a powerful and flexible form builder plugin for Strapi v5. It allows you to visually create, manage, and process forms, submissions, email templates, and more all from the Strapi admin panel.
Readme
Strapi Formidable
Strapi Formidable is a powerful and flexible form builder plugin for Strapi v5. It allows you to visually create, manage, and process forms, submissions, email templates, and more all from the Strapi admin panel.
Features
- Visual drag-and-drop form builder
- Multiple field types (text, email, select, multiselect, file, etc.)
- Field options, validation, dependencies, and appearance settings (help text, tooltip, trailing text)
- Email templates and notifications
- Submission management, search, and CSV/Excel export
- Rate-limited form submissions to curb spam/abuse
- Localization (i18n) support
- Dashboard with statistics
Installation
npm i @npm_tentwenty/strapi-formidableRebuild your Strapi admin panel:
npm run buildRestart Strapi:
npm run developUsage
- Open the Strapi admin panel.
- Find Strapi Formidable in the sidebar.
- Create and manage forms, fields, emails, templates, and view submissions.
Creating a Form
- Go to Forms > Create.
- Add fields, configure options, and set up email notifications.
- Save and publish your form.
Managing Submissions
- View, filter, search, and export submissions from the Submissions section.
- Search by ID, Submission ID, or document ID using the search box on the submissions list.
- Each submission is assigned a human-readable Submission ID (e.g.
SUB-M5F3K2-A1B2C3D4) that submitters can quote back to you — it's returned in the submit API response, available as the{{submission_id}}email placeholder, and shown in the submissions list/detail view and CSV/Excel exports.
Email Templates
- Create reusable email templates and assign them to form notifications.
Client API Endpoints
RESTful endpoints for all major entities:
GET /api/strapi-formidable/forms- List all formsGET /api/strapi-formidable/forms/:documentId- Get a single form's detailsGET /api/strapi-formidable/:documentId- Generate a form's full schema (fields, options, dependencies) for rendering and submissionPOST /api/strapi-formidable- Submit form values (rate-limited — see Rate Limiting)
All endpoints support localization via the locale query parameter.
Note:
GET /:documentIdandPOST /currently require an authenticated Strapi admin session (admin::isAuthenticatedAdmin), even though they're the endpoints a public-facing form would call to render and submit. If you're building a public/customer-facing form, keep this in mind — calling either from an unauthenticated frontend will currently return a 403.
Rate Limiting
POST /api/strapi-formidable (form submission) is protected by an in-memory, fixed-window rate limiter keyed by client IP.
- Default limit: 5 submissions per 60-second window per client IP, shared across every write endpoint the plugin exposes (not tracked per-route).
- Exceeding the limit returns
429 Too Many Requests. Every response also carriesX-RateLimit-Limit,X-RateLimit-Remaining, andX-RateLimit-Resetheaders; a blocked response additionally includesRetry-After. - Counts live in process memory — they reset on restart and are not shared across multiple Strapi instances/pods. For a horizontally-scaled deployment, this needs a shared store (e.g. Redis) instead.
Configuration (environment variables)
| Variable | Default | Description |
|----------------------------|---------|------------------------------------------------------------------------------|
| RATE_LIMIT_MAX_REQUESTS | 5 | Max submissions allowed per client IP per 60-second window. |
| TRUST_PROXY | false | Trust the X-Forwarded-For header (rightmost entry) to resolve the real client IP. Only enable this if Strapi sits behind a proxy you control, and set proxy: true in config/server.ts — otherwise this header is spoofable by the client. |
| TRUST_CF_HEADERS | false | Trust Cloudflare's cf-connecting-ip / true-client-ip headers instead. Only valid when Cloudflare sits directly in front of Strapi. Implies TRUST_PROXY. |
Without either trust flag set, the client IP is taken directly from the request's TCP peer (ctx.request.ip) — safe by default, but will resolve to your load balancer's IP if one sits in front of Strapi.
Email Templating
Strapi Formidable uses Handlebars to render dynamic content in emails. You can embed placeholders in your email body and email wrapper templates using {{placeholder}} syntax.
How It Works
When a form is submitted, the plugin:
- Collects the submitted field values.
- Maps each value to its field's handle.
- Injects special built-in placeholders.
- Compiles your Email Body (
contentfield on the Form Email) with all field data. - Optionally wraps the compiled body inside an Email Template (
Form Email Template).
Email Body Placeholders (Form Email → content)
These are available when writing the body HTML of a Form Email.
Dynamic Field Placeholders
For every form field, use its handle value as the placeholder key:
{{handle}}The handle is the string you define on each Form Field in the Strapi admin. For example, if a field has handle: "first_name", use {{first_name}} in your email HTML.
Example form fields and their placeholders:
| Field Name | Handle (defined by you) | Placeholder |
|----------------|--------------------------|-------------------|
| First Name | first_name | {{first_name}} |
| Email Address | email | {{email}} |
| Phone Number | phone | {{phone}} |
| Message | message | {{message}} |
Note: File fields are rendered as a list of
<a href="...">Download</a>links. Multi-value fields (multiselect, checkbox) are joined with,.
Built-in Placeholders
These are always available regardless of your form fields:
| Placeholder | Description |
|-----------------|------------------------------------------------------------------|
| {{form_name}} | The name of the form that was submitted |
| {{subject}} | The subject line defined on the Form Email |
| {{submission_id}} | The unique reference code generated for this submission (also returned in the submit API response, and shown in the Submissions admin page) — share it with submitters so they can reference it later |
| {{all_fields}}| A pre-built HTML block listing all fields as <p><strong>Field Name:</strong> value</p> |
Admin Email Placeholders
These are only populated when Admin Email is enabled on the Form Email (they're empty on client-facing emails). Set the View Submission Label field on an admin email to control the button/link text.
| Placeholder | Description |
|-------------------------------|------------------------------------------------------------------------------|
| {{view_submission_label}} | The text from the Form Email's View Submission Label field (defaults to "View Submission" if left blank) |
| {{view_submission_url}} | A direct link to this submission in the Strapi admin panel |
| {{view_submission_link}} | A pre-built <a href="...">Label</a> tag combining the two above — drop it straight into your email body |
Example Email Body
<h2>New submission from {{form_name}}</h2>
<p>You received a message from <strong>{{first_name}}</strong> ({{email}}).</p>
<p>Message: {{message}}</p>
<hr>
<h3>All submitted fields:</h3>
{{all_fields}}Email Wrapper Template Placeholders (Form Email Template → content)
When a Form Email Template is assigned to a Form Email, the compiled body is injected into the wrapper. Only two placeholders are available here:
| Placeholder | Description |
|-------------------|----------------------------------------------|
| {{content}} | The fully rendered email body HTML |
| {{email_content}} | Alias for {{content}} — same value |
Example Wrapper Template
<html>
<body style="font-family: Arial, sans-serif; padding: 24px;">
<header>
<img src="https://example.com/logo.png" alt="Logo" />
</header>
<main>
{{content}}
</main>
<footer>
<p>© 2026 My Company</p>
</footer>
</body>
</html>Summary
| Template location | Available placeholders |
|-------------------------------|---------------------------------------------------------------|
| Form Email content (body) | {{<handle>}}, {{form_name}}, {{subject}}, {{submission_id}}, {{all_fields}}, and (admin emails only) {{view_submission_label}}, {{view_submission_url}}, {{view_submission_link}} |
| Form Email Template content | {{content}}, {{email_content}} |
Author
Siddhesh Shetye [email protected] Agnelo Fernandes [email protected] Afaq Ghauri < [email protected]>
