Security & Spam
Inletbase protects your forms and your account with several layers that work automatically. Most of it needs no setup. This page explains what those protections are and points you to the settings you control.
How your forms are protected
Every form comes with these protections built in, on all plans:
- Required API key: a submission is only accepted if it carries your form's API key, so random requests without it are turned away.
- Invisible spam filter: forms include a hidden honeypot field. If a bot fills it in, the submission is quietly dropped and no email is sent. Real visitors never see it, so there is no CAPTCHA to solve.
- Rate limits: submissions are capped at 30 per minute from one IP address and 120 per minute per API key. Extra requests get a 429 response.
- Size limit: a single submission cannot be larger than 5MB.
- Allowed domains: you can restrict which websites are allowed to submit a form, so your endpoint cannot be used from a site you did not approve.
- Encryption in transit: data is sent over a secure HTTPS connection.
You set allowed domains per form. See Form Security for how to lock a form to your sites, and Deploying & Embedding for the same on chatbots.
How your account is protected
- Two-factor authentication: add a second step at sign-in with an authenticator app, and admins can require it for the whole team. See Two-Factor Authentication.
- Roles and access: admins and members have different levels of access, so people only see what they should. See Team Management.
- Safe API keys: keys are stored securely and are never exposed in your website's public code. You can revoke a key any time it is no longer needed. See API Keys.
Frequently asked questions
Do I need to add a CAPTCHA to my forms?
No. Inletbase uses an invisible honeypot field to catch bots, so real visitors are never asked to solve a puzzle.
What are the rate limits?
Submissions are limited to 30 per minute from a single IP address and 120 per minute per API key. Requests beyond that get a 429 Too Many Requests response.
Is there a size limit on a submission?
Yes. A single submission cannot be larger than 5MB. Anything bigger is rejected.
How do I stop other sites from using my form?
Set allowed domains on the form so only your own sites can submit. You do this per form in its Deploy & Security tab.
How do I make my account more secure?
Turn on two-factor authentication, and if you are an admin you can require it for everyone in your organization.