Skip to content

Guide

Send form submissions to n8n

You run your own automations. Run them on a form backend with the same convictions.

Last updated

Or skip the reading entirely.

Everything below is agent-work. Paste this to yours, then come back to a working form — you show up at the end to say "keep it."

Paste to your agent
Install the Postbag skill with `npx skills add faahim/postbag --skill postbag`, then use it to connect my Postbag form to an n8n webhook and prove a test delivery arrived.

Add a Webhook node

In a new n8n workflow, add a Webhook node set to POST. It offers two URLs: a test URL that only listens while you're watching, and a production URL that works once the workflow is active. Copy the production one — the test URL's habits are the classic first-day surprise.

Give it to Postbag, with a secret

Create a webhook Destination with the production URL and a secret of your choosing. The secret makes each post verifiable: Postbag signs the body, and your workflow can check the signature before trusting a byte of it. Self-hosters tend to appreciate that sentence.

Create the Destination
form_id="fm_YOUR_FORM_ID" # Copy yours from: npx postbag forms list
destination_json="$(curl --fail --silent --show-error -X POST https://postbag.dev/v1/destinations \
  -H "Authorization: Bearer pb_live_…" \
  -H "content-type: application/json" \
  -d '{
    "type": "webhook",
    "name": "n8n",
    "config": { "url": "https://n8n.your-domain.com/webhook/…", "secret": "a-long-random-string" }
  }')"
destination_id="$(printf '%s\n' "$destination_json" | jq -er '.id')"

printf 'Destination ID: %s\n' "$destination_id"

Prove it before it matters

Activate the workflow, then send a test through the Destination. The execution list shows the delivery: your visitor's answers inside data, the envelope around it saying which Form and when, and a Postbag-Signature header for the sceptical.

Send a test delivery
curl --fail --silent --show-error -X POST https://postbag.dev/v1/destinations/"$destination_id"/test \
  -H "Authorization: Bearer pb_live_…"
What Postbag posts (your message rides in data)
{
  "id": "dl_a91x02",
  "type": "submission.received",
  "schema_version": 1,
  "form": { "id": "fm_8f3kq2", "name": "Contact" },
  "data": { "email": "[email protected]", "message": "hello" },
  "extras": {},
  "meta": { "received_at": "2026-09-09T12:00:00Z" }
}

Route your Form to it

Tie the Form to the Destination and build the rest of the workflow — enrich, file, notify, reply. Every submission is stored before it's posted; if your instance is down for an upgrade, Postbag retries up to ten times and the messages simply wait, unbothered.

Route Form → n8n
route_body="$(jq -n --arg form_id "$form_id" --arg destination_id "$destination_id" \
  '{ form_id: $form_id, destination_id: $destination_id }')"

curl --fail --silent --show-error -X POST https://postbag.dev/v1/routes \
  -H "Authorization: Bearer pb_live_…" \
  -H "content-type: application/json" \
  -d "$route_body"

The parts that bite

Test URL versus production URL
The test URL listens only while the editor's Listen button is active; the production URL needs the workflow toggled on. Nine of ten 'it never arrived' reports are this line.
Verify the signature if you set a secret
The Postbag-Signature header carries a timestamp and an HMAC of the raw body. The destinations feature page has a ready verification snippet you can drop into a Code node.
Respond quickly, work slowly
Set the Webhook node to respond immediately and do heavy work in later nodes. Postbag treats a slow response as a failed attempt and retries — well-meant, but noisy if your workflow likes to think first.

Questions, answered

Does self-hosted n8n behind my firewall work?
The webhook URL must be reachable from Postbag Cloud — or run Postbag yourself on the same network and keep the whole path in the house.
Why the secret?
Anyone who learns the URL could post fake submissions. The signature proves each delivery came from Postbag and wasn't altered en route.
Can n8n fetch the stored original later?
Yes — the envelope carries ids, and the full API can read any submission by id with your key.
What happens during an n8n upgrade?
Deliveries fail, retry with growing pauses, and succeed when the instance returns. Attempts that run out stay clearly marked for a one-click retry.

Give the form job to your agent.

It can build, wire and test the form before you even sign up. Claim it when it's worth keeping.