Software Engineering
A self-hosted form backend API with PostgreSQL, presigned uploads and Telegram alerts: Submify
Submify is an open-source form backend: post JSON with an API key, store in your own PostgreSQL, export XLSX or PDF, upload files to your S3 storage and get Telegram alerts.
By Raktim Ranjit · Published · 6 min read
Short answer: Submify is a form backend you run yourself. A website posts JSON to one endpoint with an API key, the submission is stored in your PostgreSQL database, and you read it from a dashboard, export it as XLSX or PDF and optionally get a Telegram message. It is open source under AGPL-3.0.
Who is it for?
Developers who manage forms across several sites and need a clear route from a browser submission to storage, review and export, without handing submissions to a hosted service that creates data silos and weak observability.
How does a submission travel?
- Register, create a project and embed the project key in a form.
- The Go API validates the request, checks the API key and optional HMAC signature, applies rate limits and writes to PostgreSQL.
- The owner reviews, exports or rotates keys in a Next.js dashboard.
- Optionally, a Telegram alert fires. It is a notification channel, not the storage path, so a messaging outage is never confused with a missing submission.
How are file uploads handled?
The browser uploads directly to the owner's own S3-compatible storage through a short-lived presigned URL. The file body never passes through the application server and Submify stores only the object key, which keeps the database small and the upload path fast.
How does it resist abuse?
An embeddable endpoint accepts data from the open internet, so authentication, rate limits and optional signatures sit in the request path. Keys can be rotated per account and per project. A separate password-protected client page can expose only one project's submissions to the people responsible for that site. Before each release I run govulncheck against the Go API and npm audit against the dashboard.
What is the architecture?
Nginx is the single published port. It sends API paths to a Go and Gin service and everything else to a Next.js dashboard. All tenants share one PostgreSQL database with rows scoped by user and project. Object storage is optional and external. Browser-facing hardening such as a content security policy matters for the dashboard; Strict CSP breaks Next.js hydration records a lesson from that side.
How do I install it?
One Docker Compose stack, with a quick-start script for Linux and macOS and a PowerShell script for Windows that sets up WSL2 with a real Docker Engine so Docker Desktop is not required.
What is deliberately missing?
Email notification is not built in. I kept the core small and let the owner send mail from their own application after posting to Submify. Read the Submify case study for the data model and trade-offs.
References
Author
Raktim Ranjit is a software engineer and the founder of NodeDR Infotech. He builds and maintains the software described here.