Special fields
Fields that control how Nisuform handles a submission, like the _gotcha honeypot, the _elapsed fill time and _redirect.
Fields whose names start with an underscore tell Nisuform how to handle a submission. They are never saved, never shown in the inbox and never sent to notifications or integrations.
| Field | Plan | What it does |
|---|---|---|
_gotcha | All | Honeypot. If it has any value, the submission is dropped as a bot. |
_elapsed | All | Milliseconds the visitor spent on the form. Under 2 seconds, the submission is dropped as a bot. |
_redirect | Pro | Where to send the visitor after a browser submit. |
cf-turnstile-response | All | The Cloudflare Turnstile token. Checked when Turnstile is turned on for the form. |
A dropped submission still gets a normal success response, so bots can't tell they were caught. The JSON response has no submissionId in that case.
_gotcha
A hidden text input that people never see, so they leave it empty. Many bots fill in every input they find.
<input type="text" name="_gotcha" tabindex="-1" autocomplete="off" style="display:none">- Hide it with CSS, not with
type="hidden". Bots skip hidden inputs. - Keep
tabindex="-1"so keyboard users don't land on it, andautocomplete="off"so browsers don't fill it in.
_elapsed
The time between showing the form and submitting it, in milliseconds. A person needs a few seconds to fill in a form. A bot needs a few milliseconds.
const shownAt = Date.now()
form.addEventListener('submit', () => {
form.elements._elapsed.value = String(Date.now() - shownAt)
})<input type="hidden" name="_elapsed">Submissions with a value under 2,000 are dropped. If the field is missing or is not a number, the check is skipped, so plain HTML forms without JavaScript keep working. The styled embed from the form builder sends it for you.
_redirect
On Pro, a browser submit that includes _redirect is answered with a 303 redirect to that URL instead of the thank-you page.
<input type="hidden" name="_redirect" value="https://example.com/thanks">- It must be an absolute
httporhttpsURL. - It must be on the same site as the page that sent the form, or on one of the form's allowed websites. Anything else is ignored, which keeps your form from being used to redirect people to other sites.
- It overrides the redirect URL in the form's settings for that one submission.
fetchrequests that ask for JSON are never redirected.
See Thank-you page and redirects for the other options.
cf-turnstile-response
Added by the Cloudflare Turnstile widget. When Turnstile is on for the form, a missing or invalid token is rejected with 403 and captcha_failed. See Cloudflare Turnstile.
The names g-recaptcha-response and h-captcha-response are reserved too. They are ignored and never saved, but Nisuform does not verify reCAPTCHA or hCaptcha tokens.
Other names that start with an underscore
Any other field that starts with an underscore, like _subject or _next from other form services, is ignored. Rename it without the underscore if you want to keep the value.