Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk4 min

Using PHP to POST: How to Include a Form ID

An HTML id is not form data. Add a named hidden input such as form_id, validate it in PHP, and read it from $_POST; JSON requests require php://input instead.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An HTML form’s id identifies the element in the page; it is not submitted automatically. To send a form identifier to PHP, add a named hidden input inside the form, then read that field from $_POST.

Use a named hidden field for the form identifier

Only successful, named form controls become submitted fields. The id attribute is useful for labels, CSS, and JavaScript, but PHP receives the control’s name and value.

Attribute Purpose Available to PHP as submitted data?
id Identifies an element in the document and connects labels such as <label for="email">. No, not by itself.
name Defines the key sent with the control’s value. Yes, when the control is successful.
value Provides the value sent for that named control. Yes, paired with its name.

For a form marker, use a hidden control such as <input type="hidden" name="form_id" value="contact">.

Complete HTML and PHP example

HTML form

<form action="handle.php" method="post">
  <input type="hidden" name="form_id" value="contact">

  <label for="email">Email</label>
  <input id="email" name="email" type="email" required>

  <button type="submit">Send</button>
</form>

The hidden input is between the opening and closing <form> tags. Its name is form_id, so the submitted key is form_id=contact.

PHP handler

<?php
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
    $formId = $_POST['form_id'] ?? '';

    if ($formId !== 'contact') {
        http_response_code(400);
        exit('Unexpected form.');
    }

    $email = $_POST['email'] ?? '';
    echo htmlspecialchars(
        $email,
        ENT_QUOTES | ENT_SUBSTITUTE,
        'UTF-8'
    );
}

$_POST['form_id'] ?? '' supplies an empty fallback when the field is missing. The strict comparison accepts only the expected marker; an unexpected or absent value receives an HTTP 400 response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Posting several forms to one PHP endpoint

When multiple forms use the same handler, give each one a distinct marker and branch after reading and validating it.

<form action="handle.php" method="post">
  <input type="hidden" name="form_id" value="contact">
  <input name="email" type="email" required>
  <button type="submit">Send message</button>
</form>

<form action="handle.php" method="post">
  <input type="hidden" name="form_id" value="search">
  <input name="query" type="search" required>
  <button type="submit">Search</button>
</form>
<?php
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
    http_response_code(405);
    exit('POST required.');
}

$formId = $_POST['form_id'] ?? '';

switch ($formId) {
    case 'contact':
        $email = $_POST['email'] ?? '';
        // Validate and process the contact form.
        break;

    case 'search':
        $query = $_POST['query'] ?? '';
        // Validate and process the search form.
        break;

    default:
        http_response_code(400);
        exit('Unexpected form.');
}

Important validation and security limits

  • A hidden input is client-controlled. Anyone can edit it in browser developer tools or send a handcrafted request, so never use form_id as authentication, authorization, or proof that a request came from your page.
  • Validate the marker against an allowlist such as contact and search, and validate every other submitted field for the operation you perform.
  • When placing submitted text into HTML, escape it with htmlspecialchars() using an appropriate encoding such as UTF-8. Validation and output escaping address different risks.
  • Keep the input’s name stable. Changing only its id does not change the key PHP receives; changing name does.

When $_POST is the right place to read the ID

For a normal HTML form using method="post", browsers commonly send either application/x-www-form-urlencoded or multipart/form-data. PHP parses these standard form submissions into $_POST (with uploaded files handled separately through $_FILES).

Make the request method explicit and handle missing fields rather than assuming every request contains the marker:

<form action="handle.php" method="post" enctype="multipart/form-data">
  <input type="hidden" name="form_id" value="contact">
  ...
</form>
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If the client sends JSON instead

JSON is a different request format. A JSON body is not automatically decoded into $_POST. Read the raw request body from php://input, decode it, and verify that decoding succeeded.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
<?php
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
    http_response_code(405);
    exit('POST required.');
}

$raw = file_get_contents('php://input');
$data = json_decode($raw, true);

if (!is_array($data)) {
    http_response_code(400);
    exit('Invalid JSON.');
}

$formId = $data['form_id'] ?? '';
if ($formId !== 'contact') {
    http_response_code(400);
    exit('Unexpected form.');
}

$email = $data['email'] ?? '';

Use this raw-body approach only for JSON requests; ordinary browser form posts should continue to use $_POST.

Quick troubleshooting checklist

  • Confirm the hidden input is inside the <form> element.
  • Confirm it has both name="form_id" and the intended value.
  • Confirm the form uses method="post" and its action points to the handler you are inspecting.
  • Read $_POST['form_id'], not an HTML element’s id.
  • Check that JavaScript or disabled controls are not preventing submission.
  • If the request is JSON, inspect php://input instead of expecting the key in $_POST.
  • Log or inspect request keys during development, but remove sensitive debugging output from production.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.