NisuformDocs

Special fields

Fields that control how Nisuform handles a submission, like the _gotcha honeypot, the _elapsed fill time and _redirect.

Fields whose names start with an underscore tell Nisuform how to handle a submission. They are never saved, never shown in the inbox and never sent to notifications or integrations.

FieldPlanWhat it does
_gotchaAllHoneypot. If it has any value, the submission is dropped as a bot.
_elapsedAllMilliseconds the visitor spent on the form. Under 2 seconds, the submission is dropped as a bot.
_redirectProWhere to send the visitor after a browser submit.
cf-turnstile-responseAllThe Cloudflare Turnstile token. Checked when Turnstile is turned on for the form.

A dropped submission still gets a normal success response, so bots can't tell they were caught. The JSON response has no submissionId in that case.

_gotcha

A hidden text input that people never see, so they leave it empty. Many bots fill in every input they find.

<input type="text" name="_gotcha" tabindex="-1" autocomplete="off" style="display:none">
  • Hide it with CSS, not with type="hidden". Bots skip hidden inputs.
  • Keep tabindex="-1" so keyboard users don't land on it, and autocomplete="off" so browsers don't fill it in.

_elapsed

The time between showing the form and submitting it, in milliseconds. A person needs a few seconds to fill in a form. A bot needs a few milliseconds.

const shownAt = Date.now()

form.addEventListener('submit', () => {
  form.elements._elapsed.value = String(Date.now() - shownAt)
})
<input type="hidden" name="_elapsed">

Submissions with a value under 2,000 are dropped. If the field is missing or is not a number, the check is skipped, so plain HTML forms without JavaScript keep working. The styled embed from the form builder sends it for you.

_redirect

On Pro, a browser submit that includes _redirect is answered with a 303 redirect to that URL instead of the thank-you page.

<input type="hidden" name="_redirect" value="https://example.com/thanks">
  • It must be an absolute http or https URL.
  • It must be on the same site as the page that sent the form, or on one of the form's allowed websites. Anything else is ignored, which keeps your form from being used to redirect people to other sites.
  • It overrides the redirect URL in the form's settings for that one submission.
  • fetch requests that ask for JSON are never redirected.

See Thank-you page and redirects for the other options.

cf-turnstile-response

Added by the Cloudflare Turnstile widget. When Turnstile is on for the form, a missing or invalid token is rejected with 403 and captcha_failed. See Cloudflare Turnstile.

The names g-recaptcha-response and h-captcha-response are reserved too. They are ignored and never saved, but Nisuform does not verify reCAPTCHA or hCaptcha tokens.

Other names that start with an underscore

Any other field that starts with an underscore, like _subject or _next from other form services, is ignored. Rename it without the underscore if you want to keep the value.