Timberdocs

Using Timber

Forms

Every site needs a contact form. Timber ships with a real form builder and an inbox, and a Contact form is live at /contact from the first minute.

Building a form#

Drag-and-drop fields:

Text · Email · Phone · Number · URL · Date · Paragraph · Dropdown · Radio buttons · Checkboxes · Consent checkbox · File upload · Hidden · Heading · Text/HTML · Page break (multi-step)

Each field has a label, key, placeholder, help text, required flag, width (full or half), default, options, min/max, allowed file types, and conditional logic — show a field only when another one equals / doesn't equal / contains / is empty / is not empty a value.

Start from a template (contact, newsletter, feedback survey, job application, event registration…) or from scratch.

Where a form lives#

  • Its own page, e.g. /contact, with an eyebrow, heading, intro and bullet points beside the form.
  • Embedded anywhere with a shortcode: [form id="contact"] — in pages, Builder blocks and snippets.

What happens on submit#

  1. Spam protection — a hidden honeypot field, a minimum fill time, and a per-IP rate limit. Spam is flagged, not shown.
  2. Validation — required fields, email format, option whitelists, length caps, file type and size checks.
  3. Saved to the inbox (unless you turn storage off).
  4. Notification email to you, with reply-to set to the submitter. Route different answers to different recipients.
  5. Autoresponder to the person who submitted, using merge tags.
  6. Confirmation: a message, a redirect to a URL, or a redirect to one of your pages.
  7. Webhook: a JSON POST to any URL, signed with HMAC-SHA256 in the X-PF-Signature header.

Merge tags#

Use them in subjects, messages and confirmations: {name}, {email}, {field_key}, {field_key|fallback}, {all_fields}, {form_title}, {ref}, {site_name}, {page_url}, {date}.

Form settings#

Per form: submit label, subject template, store on/off, store IP on/off, honeypot, minimum seconds, rate limit, entry limit, open and close dates, one entry per email, CSS class, and a custom "closed" message.

The inbox#

Forms → Submissions shows entries with filters for all, unread, starred, spam, search, and per-form views. Mark read/unread, star, delete, export, and reply straight from the inbox (replies use your email settings and signature).

The privacy form#

A Privacy data request form (/privacy/data-request) comes pre-built for access, deletion, correction and opt-out requests, with a 30-day response promise you can edit. See Privacy & cookies.

Timber is open source. Built by indies, for indies. © 2026