formbasedocs
Go to appApp

Building Forms

Bot protection (Turnstile)

Cloudflare Turnstile checks share-link submissions for you. It is always on for free forms and yours to control on Pro and Business. Most respondents never see it.


How it works

When a respondent presses submit, formbase asks Turnstile for a token and verifies it on the server before the submission is written. The check normally runs silently; if it cannot resolve on its own, a small dialog appears and asks the respondent to confirm. There are no image puzzles. The dialog follows your form’s theme and language.

The check runs on the submit, not on page load, so it never delays the form opening. A submission that fails verification is rejected and the respondent is asked to try again.

Requests are not gated

Bot protection applies to share links only. A request link already names one recipient and authorises one completion, so it skips Turnstile — as it skips the sign-in requirement and response limits.

formbase-hosted forms

For forms shared on form.formbase.so links, bot protection is built in — no setup, no keys, nothing to configure. formbase manages Turnstile for you.

On the Free plan (and for guest forms), bot protection is always on and can’t be turned off. The Bot protection (Turnstile) switch under Form settings → Access stays locked on.

On a Pro or Business plan, the switch is yours. Turn bot protection on or off per form from Form settings → Access → Bot protection (Turnstile).

If your paid plan lapses, your own setting keeps applying for the first 30 days. From day 30 bot protection locks back on — the Free-plan default. See upgrading & downgrading.

Custom domain forms (BYOK)

Custom domains require a Pro or Business plan. If you share forms on a custom domain (for example fill.yourdomain.com), you bring your own Turnstile keys (BYOK): Cloudflare ties a Turnstile widget to specific hostnames, and formbase’s own key only covers formbase.so.

  1. 1

    Add your custom domain first

    The Bot Protection card on the Domains page stays empty until the workspace has at least one custom domain. Set the domain up first.

  2. 2

    Create a Cloudflare account

    Sign up for a free account at dash.cloudflare.com if you don't have one.

  3. 3

    Create a Turnstile widget

    In Turnstile, add your custom domain hostnames to the allowed list. One widget with hostname validation disabled covers every domain in the workspace.

  4. 4

    Copy your keys

    Copy the Site key and Secret key.

  5. 5

    Paste the keys in formbase

    Open Domains from the sidebar, find the Bot Protection card, paste both keys, and save. The keys are per workspace, not per form.

  6. 6

    Turn it on per form

    Switch bot protection on for individual forms in Form settings → Access.

Until the keys are saved, the switch on a custom-domain form is disabled and shows as off, because no challenge can run there. What happens to submissions on that branded URL depends on the plan:

OwnerCustom domain without keys
Pro or BusinessSubmissions go through unprotected — your switch is a preference, not a guard.
Free, guest, or a plan lapsed past day 30Submissions on the branded URL are rejected. The formbase.so link keeps working.

No custom domains? Skip this.

If all your forms use the default formbase share links, you do not need Turnstile keys. Bot protection works automatically.

Submission limits

Turnstile does not change your monthly allowance — 1,000 submissions a month on Free, 50,000 on Pro and Business. See limits & quotas.

Layered defense strategies

Turnstile is one layer. Combine it with the access controls in Form settings → Access:

Threat levelRecommendation
Low riskTurnstile alone — invisible, zero friction
Medium riskTurnstile + password protection or a scheduled close
High riskRequire authentication — no anonymous submissions at all
Lead-gen / incentivesTurnstile + scheduled close + a response limit on the share link

Next steps