Requests we send
What every request from RevoplyAI to your systems looks like, the addresses we refuse, and the timeouts, sizes and daily limits.
This page covers every request our servers make to yours: webhook deliveries, HTTP steps, AI actions, and the test buttons for each.
Headers
| Header | Webhook deliveries | HTTP steps and AI actions |
|---|---|---|
User-Agent | RevoplyAI-Webhooks/1.0 | RevoplyAI-Automations/1.0 |
Content-Type | application/json; charset=utf-8 | application/json; charset=utf-8, when there is a body |
Accept | — | application/json |
| Authentication | X-Revoply-Signature | The connection's credential |
HTTP steps and AI actions send the connection's default headers, then the step's or action's own headers, then the credential, which nothing before it can replace. Header values filled in from Arabic text are sent as UTF-8.
Addresses we refuse
Every URL we call is under your control, and our servers make the call, so both are checked:
https://only, with a host name that contains a dot. No username or password in the URL.- Names ending in
.local,.internal,.localdomainor.home.arpaare refused. - Every address the name resolves to must be public. Refused: private ranges (
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16), loopback, link-local (including169.254.169.254), carrier-grade NAT (100.64.0.0/10), multicast and reserved ranges, documentation and benchmarking ranges, IPv6 addresses outside global unicast (includingfc00::/7andfe80::/10), and NAT64, 6to4 and Teredo addresses that lead to any of these. - The check runs when you save the URL and again at every connection, so a name pointed at a private address after it was saved still cannot be reached.
- No redirects are followed; a
3xxanswer is a failure. No proxies, no cookies.
We do not publish a fixed list of IP addresses our requests come from. Authenticate them by signature or credential, not by address.
Timeouts
| Request | Limit |
|---|---|
| Webhook delivery | 10 seconds for the whole request, answer included |
| HTTP step or AI action call | The connection's timeout, 1–15 seconds (10 by default) |
| Opening the connection | 5 seconds, within the above |
| Calls in one go | 3 calls between two customer messages, 30 seconds in all, retries included |
The time counts until the whole answer is read, not only its headers.
Sizes
| What | Limit |
|---|---|
| Webhook body | 64 KB |
| Webhook answer kept in the delivery log | First 2 KB |
| HTTP step or action body, once filled in | 64 KB |
| Path and query, once filled in | 4,096 characters |
| Answer to an HTTP step or action | 256 KB; a larger answer is a failure |
Daily allowance
An account's HTTP steps and AI actions may make 10,000 calls a day together (UTC), every attempt counted, retries and tests included. After that, calls are not made until the next day: steps take their Failed path and actions tell the assistant they could not check. Webhook deliveries do not count towards it.
What we log
For each call to your API we keep the host, the path without its query string, the status, the duration and whether it was a retry, for 14 days. We do not log request or response bodies, which can hold customers' details. Credentials are removed from any answer before a flow or the assistant reads it.