Create Accountor Login
Docs

Building Forms

Part of the MountDev Ops Forms documentation. Updated October 7, 2026

MountDev Ops Forms documentation | Updated October 7, 2026

Our Commitment

MountDev Ops is built security first. Your business data belongs to you, and you can export all of it at any time. We never use analytics or tracking of any kind inside MountDev Ops.

The Forms Page

Open Forms from the app switcher. The Forms page lists every form (action forms.list) with how many fields and submissions it has, where its submissions go, when the last one arrived, and whether it is on. Below that are the ten most recent submissions you may see. Owners and admins also see a note when spam protection keys or the sending address still need to be added in Forms Settings.

Adding or Changing a Form

Owners and admins select Add Form, or a form on the Forms page, to open its builder (action forms.get shows it). A new form starts as a contact form (first name, last name, email address, company, and message) that you can change any way you like. Add Form or Save Changes saves it (action forms.save). Everyone else can look at a form but not change it.

  • Name: for your team. It also names each submission.
  • Thank-you message: shown after someone sends the form.
  • Button: the words on the send button, like Send or Get a Quote.

A new form gets its own public address when it is first saved. The address never changes, even when you rename the form.

Fields

Each field has a label, a type, whether it is required, optional help text, and what it is used as.

  • Types: short text, long text, email address, phone number, web address, number, money, date, date and time, yes or no, one choice, and several choices. These are the same field types as your modules, checked the same way. One choice and several choices need their choices, one per line. A yes or no field that is required must be checked, which suits an agreement.
  • Used as: tells Forms what an answer means: full name, first name, last name, email address, phone number, company name, subject, or message. Each can be used once per form. CRM leads, Helpdesk tickets, the auto-reply, and the name of each submission come from these. The email address field must be the Email address type.
  • Add Field, Change, Remove, and Up and Down to change the order. Changes are saved with the form.

A form has from 1 to 40 fields. Each field has a name made from its label when it is added (like phone_number); it is what a website's own code sends. A few names are kept for Forms itself: page, page_url, referrer, landing, elapsed, ref, mdo_hp, company_website, partner_apply, and any starting with utm_.

Where Submissions Go

Every submission is kept in Forms. You can also choose:

  • Add a lead to CRM (CRM must be added, with Contacts turned on): the contact with that email address when you already have one (left exactly as it is), or a new contact marked Lead with their name, email, phone, the form as its source, and their message. When they give a company name, the company with that name, or a new one marked Prospect, and a new contact is linked to it. A form needs a field used as the email address or the name for this.
  • Open a Helpdesk ticket (Helpdesk must be added, with a support address set up): a new ticket from the person, linked to their CRM contact and company, with their message, their other answers, and the page it was sent from. Its subject is the answer to the field used as the subject, else the Ticket subject, else the form's name. Your Helpdesk team hears about it as for any new ticket. When the form has no auto-reply, the Helpdesk receipt is sent instead, so the person gets one email either way. A form needs a field used as the email address for this. If Helpdesk cannot take the ticket (for example, no support address is set up), the submission is still kept and says why.
  • Who hears about each submission: owners and admins (the starting choice), everyone with Forms, or nobody. Emails go only to people whose role lets them see every submission, from the sending address in Forms Settings.

Auto-Reply

Turn on Email the person who sent it to send an automatic reply with your own subject and message, and a copy of what they sent. Web addresses in the message become links. It needs a field used as the email address and a sending address in Forms Settings. Every email states why it was sent, and every link carries campaign (UTM) tags.

Spam Protection

Every form has these, always:

  • a hidden field that people never see and bots fill in;
  • a minimum time to fill the form in (three seconds);
  • a limit of five tries an hour from one visitor, and 300 an hour for the whole form. Tries are counted by a scrambled form of the visitor's internet address that changes every day; the address itself is never kept, and the count is forgotten after two days;
  • at most five web links in the answers.

A bot that fills in the hidden field, or sends the form too fast, is told it worked, and nothing is kept.

Check each submission with Cloudflare Turnstile (on for new forms) adds Cloudflare's check that a person is sending the form, using your own Turnstile keys from Forms Settings. Until the keys are added, a form with this on does not take submissions and tells visitors so, rather than opening itself to bots.

Your websites (optional): list the websites the form is used on, one per line, like example.com. The form then shows only on those websites and their subdomains, and takes submissions only from them, its own page, and servers that send without a website.

Putting It on Your Website

A saved form shows Put It on Your Website, with three ways and a Copy button for each:

  • Script: paste it where the form should go. It shows the form there in a frame that fits its height, and passes on the page it is on, the referrer, the first page the visitor saw, and the campaign (UTM) values. To place the form somewhere else on the page, add an empty element with the attribute data-mdo-form, or give the script data-target with a selector.
  • Iframe: for website builders that only take an iframe. The page and campaign values are not passed on.
  • Address for Your Own Code: send JSON or a plain form to this address with each field by its name, plus page_url, referrer, landing, the utm_ values, and cf-turnstile-response when spam protection is on. The answer is JSON: ok and the thank-you message, or an error that says what to fix. The form's fields and its Turnstile site key are at the same address plus /info.

Open the Form shows the form on its own.

Turning a Form Off or Deleting It

  • Turn Off and Turn On (action forms.state): an off form takes no submissions, and websites showing it say it is not available. Nothing it took in changes.
  • Delete (action forms.delete): only for a form with no submissions, so nothing is lost. A form with submissions is turned off instead.

Ask Us Anything

We’d love to hear from you!