Integration

Foundation CMS and Zapier

Zapier connects a Foundation CMS site to the thousands of apps it already supports. Form enquiries arrive in a Zap through the site's signed webhook, and a Zap can publish to the site through the content API with a key that only reaches that one site.

Overview

This integration connects Foundation CMS with Zapier. Foundation CMS is Swarm Labs' multi-tenant content management system on Cloudflare Workers. It holds a site's content and hands it to the site as whole, typed records, and every site runs as its own Worker with its own database and media bucket. Foundation CMS does not need a Zapier app to work with it: a form's webhook can point at a Zap's Catch Hook, and Zapier's webhook action can call the Foundation CMS content API with a site key sent as a Bearer token.

Business Context and Core Use Case

Many businesses already run their admin in Zapier: new enquiries into a CRM, a spreadsheet and a team chat; new products or events from another system onto the website. Foundation CMS fits into those Zaps without custom code. It is especially useful for the destinations the CMS's own delivery deliberately does not try to cover, such as CRMs that expect nested data or several steps.

The Applications Involved

Foundation CMS (Foundation CMS) sends each form submission as a signed webhook and accepts reads and writes through its content API.

Zapier (Zapier) catches the webhook, transforms it and passes it on, or calls the API to publish.

How the Integration Works

For enquiries, create a Zap with a Catch Hook trigger and set its address as the destination of the form's webhook channel; every accepted submission arrives as the Foundation CMS envelope, signed. For publishing, make a site key with only the abilities the Zap needs and call /api/v1/content/{type} with it, giving related entries by slug and categories by label.

Immediate Operational Value

Every enquiry can reach every tool the business uses, without waiting for a dedicated integration, and other systems can keep the website's content current without anyone retyping it.

Security, Access, and Governance

Form webhooks are signed over their timestamp as well as their body, with a secret shown once when it is made, so the receiver can reject anything that did not come from the site and a captured request cannot be replayed. API keys are scoped to one site and named abilities, hashed at rest and record when they were last used. Every delivery attempt is logged with the host it reached, so a broken Zap shows up as failed deliveries rather than silence.

Summary

A signed webhook out and a scoped API in: that is all Zapier needs to wire a Foundation CMS site into the rest of a business.

Frequently asked questions

Is there a Foundation CMS app in Zapier?

It is not needed. Forms send a standard signed webhook to a Catch Hook, and Zapier's webhook action can call the content API.

Can a Zap publish to the website?

Yes, with a site key that has the right abilities. Entries can be published, saved as drafts or scheduled.

How do I know a webhook really came from the site?

It is signed over its timestamp and body with a secret shown once, so it can be verified and replays rejected.

Want Foundation CMS and Zapier
wired up for you?