โ˜ฐ

Premium Gravity Forms add-on

JWT Prefill

Prefill your forms with signed data you can verify

JWT Prefill is a Gravity Forms add-on that prefills form fields from a signed JSON Web Token (JWT) instead of editable URL parameters. It checks the token with a form-specific private key before the form loads, can require a token within a time window, checks allow and deny lists, and generates token links with a shortcode or a Gravity Flow step.

  • 30-day money-back guarantee
  • Support from the developers
Staff create a signed personal link for a customer. The link opens the renewal form with name, customer number and plan filled in and an expiry notice; with one character of the token changed, the form refuses it.

For site owners and developers who send people prefilled form links and need to know the data in those links was not changed.

Data you can verify

Anyone can edit a normal URL parameter. A JSON Web Token is signed with your private key, so a changed token fails the signature check and is rejected.

Only the right people open the form

Require a token to load the form, schedule when that rule applies, and block or allow specific tokens. Visitors without a valid token see a clear message instead of the form.

Set up in the form settings

You configure everything in Gravity Forms and create links with a shortcode or a Gravity Flow step. No custom code is needed.

Try it

This form runs JWT Prefill on this site. Fill in the fields and see the add-on at work.

Fill in the demo form to create a token. The confirmation shows the token and a link that opens a second form prefilled with your answers.

Checkboxes
Radio Button

Use cases

  • Send customers a link to an update form with their customer number already filled in, signed so you can check it.
  • Open a registration form only to invited people, and to everyone after the End time you set.
  • Let a Gravity Flow workflow create a personal follow-up link after an approval step and save the token in the entry.
  • Give each link an expiry date so old links stop working.
  • Block links that were already used by adding their tokens to a list of forbidden tokens.
  • Show a claim from the token, such as a customer ID, in the notification with {JSON Web Token:2:customer_id}.

Features

  • Prefill fields from token claims

    Enable Populate fields with JWT claims and each claim fills the field with the matching parameter name. A claim text fills a field whose dynamic population parameter is text, and one token can fill many fields.

  • Signature check with a private key

    Every form has its own private key, and the settings page suggests a secure 256-bit key. The private key is not included in form exports.

  • Require a token, on a schedule

    Parameter gwp_token is required loads the form only when a token is passed in the URL. With Schedule gwp_token requirement you set a Start time and End time for that rule.

  • Allow and deny lists

    Connect another form that holds allowed or forbidden tokens in a Single Line Text field. You can also change the messages shown for a missing, invalid, expired, not yet valid or not allowed token.

  • Generate token links

    The [gwp_jwt_link] shortcode returns a prefill URL or a complete HTML link, with options for an expiry date (exp), the URL parameter (url_param) and returning only the token. In Gravity Flow, the Generate prefill JWT step creates a token and saves it in a field.

  • JSON Web Token field and merge tag

    The JSON Web Token field (under Advanced Fields) stores the token in the entry and validates it on submit. Read a single claim in notifications and confirmations with a modifier, for example {JSON Web Token:2:text}.

Ready to use JWT Prefill? 30-day money-back guarantee.

Buy now from $49

Why GravityWP

Gravity Forms specialists since 2014. The people who build the add-ons also answer your questions.

Built the Gravity Forms way

Our add-ons use the official Gravity Forms add-on framework, so settings, feeds and entries work the way you already know.

Compatibility guaranteed

Works with current Gravity Forms versions and certified add-ons like Gravity Flow, GravityView and Gravity Perks. If something conflicts, we fix it.

Support from the developers

Your question goes straight to the people who wrote the code. Good feature requests often make it into the next release.

What customers say

Thank you so much for this very complete, clear and precise answer!!! It’s great to receive answers like this!
Owner, online platform
I really really appreciate all the work you and your team have put into these plugins and also for your support and responses. You guys rock.
Gravity Forms developer, freelance
Glad I didn’t ask for a refund with this level of excellent support.
Independent developer

Get JWT Prefill

Yearly license with updates and email support. Prices excl. VAT.

1 site

$49/year

Buy for 1 site

50 sites

$179/year

$3.58 per site
Includes priority support

Buy for 50 sites

All Access

$139/year

All 14 premium add-ons, 1 site
$9.93 per add-on

Get All Access

30-day money-back guarantee. When a license ends, everything you installed keeps working; only downloads, updates and support stop. Compare all licenses

Questions before you start? Ask us

Frequently Asked Questions

Can I prefill multiple fields from one JWT?

Yes. A token can hold several claims, and each claim fills the field whose dynamic population parameter has the same name.

Can I limit when a token is needed or valid?

Yes. In the form’s JWT Prefill settings, Schedule gwp_token requirement sets a Start time and End time for when a token is required, and the exp option of the [gwp_jwt_link] shortcode gives a single token an expiry date.

Can I use JWT Prefill without coding?

Yes. All settings are in the Gravity Forms form settings, and you create links with a shortcode or a Gravity Flow step. Only accepting a URL parameter other than gwp_token needs a small filter snippet.

What is a JSON Web Token (JWT)?

A JSON Web Token is an open standard (RFC 7519) for passing claims between two parties in a compact, URL-safe string. It is signed with a private key, so the receiving side can check that the claims were not changed.

What happens when my license expires?

Everything you installed keeps working. You no longer get downloads, updates, new features and support until you renew.

Can I get a refund?

Yes. If you decide not to use the add-on within 30 days of purchase, you can request a full refund through your account on my.gravitywp.com.

Requirements

  • Gravity Forms 2.5 or later
  • WordPress 5.0 or later, tested up to 7.0
  • PHP 7.4 or later
  • Optional: Gravity Flow, for the Generate prefill JWT workflow step

Current version 1.3.5, updated 2 September 2026. View the changelog

Documentation and tutorials

All JWT Prefill documentation

Changelog of JWT Prefill

v1.3.5

  • License and Update handler improvements

v1.3.4

  • License and Update handler improvements

1.3.3

  • Added option to not include empty or 0 values in the json

1.3.2

  • Fix an issue where multipe column list fields could not be populated.

1.3.1

  • Fixed an issue regarding the frequency of update checks to increase performance.

1.3

  • Update the license handler.

1.2.8

  • Fix a fatal error when exp/iat parameters are used to populate fields.
  • Fixed: translated user validation messages not being displayed settings.
  • Fixed: shortcode not working in admin requests like resend notification.

1.2.7

  • Added filter for validation messages.
  • Added the 'url_param' and 'return_format' argument to the gwp_jwt_link shortcode.
  • Fixed: translated user validation messages not being displayed settings.
  • Fixed: shortcode not working in admin requests like resend notification.

1.2.6

  • Implement the 'gwp_prefill_token_url_parameter' filter hook to allow customizing the gwp_token url parameter.

1.2.5

  • Updated dependencies to fix a security issue in a third party library.

1.2.4

  • Wrap user notices in a div for styling.
  • Fix PHP notice when form_url_postfix shortcode paramater is empty.

1.2.3

  • Fix deployment process using gravitywpprefill as folder name instead of gravitywp-prefill.

1.2.2

  • Fix form-url parameters in shortcode not working correctly.

1.2.1

  • fix issue while retrieving claims with the JWT-field merge tag.

1.2

  • First public release.
  • Updated lcobucci/jwt library to 4.1.5.
  • Several UI improvements.

Start using JWT Prefill today

Prefill your forms with signed data you can verify

Buy now from $49

30-day money-back guarantee

Proudly powered by WordPress