Recontact — API reference

Form API

The script is invoked like so:

<script
  src="https://api.recontact.dev/v1/embed.js"
  data-domain="example.com"
  data-form-id="contact-form"
></script>

The following data fields can be specified in this script tag:

  • data-domain (required) — the registered domain.
  • data-form-id (required) — the <form> element's id.
  • data-theme — light or dark (captcha and UI theme).
  • data-size — Turnstile size.
  • data-interaction-only — "true" to only challenge suspicious visitors.
  • data-compact-reminder — "true" to show only the date (not the content) in

the return-visit reminder.

Endpoints

Base URL: https://api.recontact.dev

POST /v1/inbox/:domain/send

Sends a message to the inbox registered for :domain. Used by the embed script.

Form data:

  • user_email (required) — the submitter's email address.
  • message (required) — 2..2000 characters.
  • cf-turnstile-response (required) — a Turnstile token (the script injects this).
  • Any other fields are stored in metadata.

Protected by Turnstile and various rate limits.

POST /v1/register/:domain

Registers a domain (creates an inbox). Form data: email (required).

Returns 409 if the domain is already registered. Sends one verification email to the address. Refuses with 429 when the daily outbound-email budget is exhausted.

GET /v1/verify/:token

Verifies a notification email. Marks the inbox's notify emails verified and consumes the token.

GET /v1/embed.js

The embeddable widget script.

GET /v1/captcha

The first-party CAPTCHA page rendered inside the widget's iframe.

GET /v1/nojs

Fallback page for browsers with JavaScript disabled. Shows a contact-email link for registered domains.