Recommended Free Tools
An HTML form’s id identifies the element in the page; it is not submitted automatically. To send a form identifier to PHP, add a named hidden input inside the form, then read that field from $_POST.
Use a named hidden field for the form identifier
Only successful, named form controls become submitted fields. The id attribute is useful for labels, CSS, and JavaScript, but PHP receives the control’s name and value.
| Attribute | Purpose | Available to PHP as submitted data? |
|---|---|---|
id |
Identifies an element in the document and connects labels such as <label for="email">. |
No, not by itself. |
name |
Defines the key sent with the control’s value. | Yes, when the control is successful. |
value |
Provides the value sent for that named control. | Yes, paired with its name. |
For a form marker, use a hidden control such as <input type="hidden" name="form_id" value="contact">.
Complete HTML and PHP example
HTML form
<form action="handle.php" method="post">
<input type="hidden" name="form_id" value="contact">
<label for="email">Email</label>
<input id="email" name="email" type="email" required>
<button type="submit">Send</button>
</form>
The hidden input is between the opening and closing <form> tags. Its name is form_id, so the submitted key is form_id=contact.
PHP handler
<?php
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$formId = $_POST['form_id'] ?? '';
if ($formId !== 'contact') {
http_response_code(400);
exit('Unexpected form.');
}
$email = $_POST['email'] ?? '';
echo htmlspecialchars(
$email,
ENT_QUOTES | ENT_SUBSTITUTE,
'UTF-8'
);
}
$_POST['form_id'] ?? '' supplies an empty fallback when the field is missing. The strict comparison accepts only the expected marker; an unexpected or absent value receives an HTTP 400 response.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
Posting several forms to one PHP endpoint
When multiple forms use the same handler, give each one a distinct marker and branch after reading and validating it.
<form action="handle.php" method="post">
<input type="hidden" name="form_id" value="contact">
<input name="email" type="email" required>
<button type="submit">Send message</button>
</form>
<form action="handle.php" method="post">
<input type="hidden" name="form_id" value="search">
<input name="query" type="search" required>
<button type="submit">Search</button>
</form>
<?php
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
http_response_code(405);
exit('POST required.');
}
$formId = $_POST['form_id'] ?? '';
switch ($formId) {
case 'contact':
$email = $_POST['email'] ?? '';
// Validate and process the contact form.
break;
case 'search':
$query = $_POST['query'] ?? '';
// Validate and process the search form.
break;
default:
http_response_code(400);
exit('Unexpected form.');
}
Important validation and security limits
- A hidden input is client-controlled. Anyone can edit it in browser developer tools or send a handcrafted request, so never use
form_idas authentication, authorization, or proof that a request came from your page. - Validate the marker against an allowlist such as
contactandsearch, and validate every other submitted field for the operation you perform. - When placing submitted text into HTML, escape it with
htmlspecialchars()using an appropriate encoding such as UTF-8. Validation and output escaping address different risks. - Keep the input’s
namestable. Changing only itsiddoes not change the key PHP receives; changingnamedoes.
When $_POST is the right place to read the ID
For a normal HTML form using method="post", browsers commonly send either application/x-www-form-urlencoded or multipart/form-data. PHP parses these standard form submissions into $_POST (with uploaded files handled separately through $_FILES).
Rank #2
Make the request method explicit and handle missing fields rather than assuming every request contains the marker:
<form action="handle.php" method="post" enctype="multipart/form-data">
<input type="hidden" name="form_id" value="contact">
...
</form>
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If the client sends JSON instead
JSON is a different request format. A JSON body is not automatically decoded into $_POST. Read the raw request body from php://input, decode it, and verify that decoding succeeded.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →<?php
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
http_response_code(405);
exit('POST required.');
}
$raw = file_get_contents('php://input');
$data = json_decode($raw, true);
if (!is_array($data)) {
http_response_code(400);
exit('Invalid JSON.');
}
$formId = $data['form_id'] ?? '';
if ($formId !== 'contact') {
http_response_code(400);
exit('Unexpected form.');
}
$email = $data['email'] ?? '';
Use this raw-body approach only for JSON requests; ordinary browser form posts should continue to use $_POST.
Quick Recap
Rank #4
Quick troubleshooting checklist
- Confirm the hidden input is inside the
<form>element. - Confirm it has both
name="form_id"and the intendedvalue. - Confirm the form uses
method="post"and itsactionpoints to the handler you are inspecting. - Read
$_POST['form_id'], not an HTML element’sid. - Check that JavaScript or disabled controls are not preventing submission.
- If the request is JSON, inspect
php://inputinstead of expecting the key in$_POST. - Log or inspect request keys during development, but remove sensitive debugging output from production.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




