Recommended order
- Use the form platform's built-in webhook feature.
- Use a server-side form handler.
- Use a same-origin proxy for custom browser JavaScript.
- Configure receiving-server CORS only when direct browser posting is intentionally supported.
Forms
PINGSLAP is not a contact form builder. You generally keep your current website form and connect its webhook action, form handler, or server route to your PINGSLAP Space.
Your visitor submits your website form. Your website receives the form, then your server sends a webhook to PINGSLAP.
Your visitor's browser sends a request directly to PINGSLAP. This exposes your webhook URL in client-side code and network inspection, and may encounter CORS blocks.
WordPress form plugins, backend APIs, and automation tools send webhooks from a server. Server requests do not use the same CORS checks that browsers use, and your private PINGSLAP webhook URL remains protected on the server rather than exposed to website visitors.
For custom website forms, do not expose your PINGSLAP webhook URL in frontend JavaScript or HTML forms. Anyone who inspects the page or browser network traffic can copy the URL and send unwanted notifications into that Space.
Instead, submit the form to your own server-side handler. Your server reads the secret webhook URL from its environment configuration and forwards the alert server-to-server:
Keep the webhook URL in server-side environment or secret configuration rather than client-side code. A .env file or hosting platform environment variable is a familiar pattern:
PINGSLAP_WEBHOOK_URL=https://app.pingslap.com/v1/receive/spc_sample_token_keep_secret
A minimal server-side handler (such as a PHP script or serverless function) reads the configuration value, prepares safe fields, and POSTs server-to-server to PINGSLAP:
<?php
// submit.php - handles the form submission on your server
$webhookUrl = getenv('PINGSLAP_WEBHOOK_URL');
if (!$webhookUrl) {
http_response_code(500);
exit('Server configuration error');
}
$payload = json_encode([
'title' => 'New website form submission',
'message' => $_POST['message'] ?? 'New submission received',
'name' => $_POST['name'] ?? '',
'email' => $_POST['email'] ?? '',
]);
$ch = curl_init($webhookUrl);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, $payload);
curl_setopt($ch, CURLOPT_HTTPHEADER, ['Content-Type: application/json']);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_exec($ch);
curl_close($ch);
echo 'Thank you for your message!';
Direct server integrations: Backend applications, automation platforms (n8n, Zapier, Make), and server-side WordPress plugins already run in private server environments where visitors cannot see the webhook URL. They do not need this extra proxy handler and can send directly to PINGSLAP.
Use browser JavaScript only for low-risk experiments or when you understand how to protect the webhook URL. For production lead forms, prefer a server, WordPress webhook, automation platform, or reverse proxy.
Related: JavaScript and CORS, Webhook security, and Verify Integration.