Premium Gravity Forms add-on
JWT Prefill
Prefill your forms with signed data you can verify
JWT Prefill is a Gravity Forms add-on that prefills form fields from a signed JSON Web Token (JWT) instead of editable URL parameters. It checks the token with a form-specific private key before the form loads, can require a token within a time window, checks allow and deny lists, and generates token links with a shortcode or a Gravity Flow step.
- 30-day money-back guarantee
- Support from the developers
For site owners and developers who send people prefilled form links and need to know the data in those links was not changed.
Data you can verify
Anyone can edit a normal URL parameter. A JSON Web Token is signed with your private key, so a changed token fails the signature check and is rejected.
Only the right people open the form
Require a token to load the form, schedule when that rule applies, and block or allow specific tokens. Visitors without a valid token see a clear message instead of the form.
Set up in the form settings
You configure everything in Gravity Forms and create links with a shortcode or a Gravity Flow step. No custom code is needed.
Try it
This form runs JWT Prefill on this site. Fill in the fields and see the add-on at work.
Fill in the demo form to create a token. The confirmation shows the token and a link that opens a second form prefilled with your answers.
Use cases
- Send customers a link to an update form with their customer number already filled in, signed so you can check it.
- Open a registration form only to invited people, and to everyone after the End time you set.
- Let a Gravity Flow workflow create a personal follow-up link after an approval step and save the token in the entry.
- Give each link an expiry date so old links stop working.
- Block links that were already used by adding their tokens to a list of forbidden tokens.
- Show a claim from the token, such as a customer ID, in the notification with
{JSON Web Token:2:customer_id}.
Features
-
Prefill fields from token claims
Enable Populate fields with JWT claims and each claim fills the field with the matching parameter name. A claim
textfills a field whose dynamic population parameter istext, and one token can fill many fields. -
Signature check with a private key
Every form has its own private key, and the settings page suggests a secure 256-bit key. The private key is not included in form exports.
-
Require a token, on a schedule
Parameter gwp_token is required loads the form only when a token is passed in the URL. With Schedule gwp_token requirement you set a Start time and End time for that rule.
-
Allow and deny lists
Connect another form that holds allowed or forbidden tokens in a Single Line Text field. You can also change the messages shown for a missing, invalid, expired, not yet valid or not allowed token.
-
Generate token links
The
[gwp_jwt_link]shortcode returns a prefill URL or a complete HTML link, with options for an expiry date (exp), the URL parameter (url_param) and returning only the token. In Gravity Flow, the Generate prefill JWT step creates a token and saves it in a field. -
JSON Web Token field and merge tag
The JSON Web Token field (under Advanced Fields) stores the token in the entry and validates it on submit. Read a single claim in notifications and confirmations with a modifier, for example
{JSON Web Token:2:text}.
Ready to use JWT Prefill? 30-day money-back guarantee.
Buy now from $49Why GravityWP
Gravity Forms specialists since 2014. The people who build the add-ons also answer your questions.
Built the Gravity Forms way
Our add-ons use the official Gravity Forms add-on framework, so settings, feeds and entries work the way you already know.
Compatibility guaranteed
Works with current Gravity Forms versions and certified add-ons like Gravity Flow, GravityView and Gravity Perks. If something conflicts, we fix it.
Support from the developers
Your question goes straight to the people who wrote the code. Good feature requests often make it into the next release.
What customers say
Thank you so much for this very complete, clear and precise answer!!! It’s great to receive answers like this!
I really really appreciate all the work you and your team have put into these plugins and also for your support and responses. You guys rock.
Glad I didn’t ask for a refund with this level of excellent support.
Get JWT Prefill
Yearly license with updates and email support. Prices excl. VAT.
30-day money-back guarantee. When a license ends, everything you installed keeps working; only downloads, updates and support stop. Compare all licenses
Questions before you start? Ask us
Frequently Asked Questions
Yes. A token can hold several claims, and each claim fills the field whose dynamic population parameter has the same name.
Yes. In the form’s JWT Prefill settings, Schedule gwp_token requirement sets a Start time and End time for when a token is required, and the exp option of the [gwp_jwt_link] shortcode gives a single token an expiry date.
Yes. All settings are in the Gravity Forms form settings, and you create links with a shortcode or a Gravity Flow step. Only accepting a URL parameter other than gwp_token needs a small filter snippet.
A JSON Web Token is an open standard (RFC 7519) for passing claims between two parties in a compact, URL-safe string. It is signed with a private key, so the receiving side can check that the claims were not changed.
Everything you installed keeps working. You no longer get downloads, updates, new features and support until you renew.
Yes. If you decide not to use the add-on within 30 days of purchase, you can request a full refund through your account on my.gravitywp.com.
Requirements
- Gravity Forms 2.5 or later
- WordPress 5.0 or later, tested up to 7.0
- PHP 7.4 or later
- Optional: Gravity Flow, for the Generate prefill JWT workflow step
Current version 1.3.5, updated 2 September 2026. View the changelog
Start using JWT Prefill today
Prefill your forms with signed data you can verify
Buy now from $4930-day money-back guarantee