RevoplyAIDocs
Connect your systems

Requests we send

What every request from RevoplyAI to your systems looks like, the addresses we refuse, and the timeouts, sizes and daily limits.

This page covers every request our servers make to yours: webhook deliveries, HTTP steps, AI actions, and the test buttons for each.

Headers

HeaderWebhook deliveriesHTTP steps and AI actions
User-AgentRevoplyAI-Webhooks/1.0RevoplyAI-Automations/1.0
Content-Typeapplication/json; charset=utf-8application/json; charset=utf-8, when there is a body
Accept—application/json
AuthenticationX-Revoply-SignatureThe connection's credential

HTTP steps and AI actions send the connection's default headers, then the step's or action's own headers, then the credential, which nothing before it can replace. Header values filled in from Arabic text are sent as UTF-8.

Addresses we refuse

Every URL we call is under your control, and our servers make the call, so both are checked:

  • https:// only, with a host name that contains a dot. No username or password in the URL.
  • Names ending in .local, .internal, .localdomain or .home.arpa are refused.
  • Every address the name resolves to must be public. Refused: private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), loopback, link-local (including 169.254.169.254), carrier-grade NAT (100.64.0.0/10), multicast and reserved ranges, documentation and benchmarking ranges, IPv6 addresses outside global unicast (including fc00::/7 and fe80::/10), and NAT64, 6to4 and Teredo addresses that lead to any of these.
  • The check runs when you save the URL and again at every connection, so a name pointed at a private address after it was saved still cannot be reached.
  • No redirects are followed; a 3xx answer is a failure. No proxies, no cookies.

We do not publish a fixed list of IP addresses our requests come from. Authenticate them by signature or credential, not by address.

Timeouts

RequestLimit
Webhook delivery10 seconds for the whole request, answer included
HTTP step or AI action callThe connection's timeout, 1–15 seconds (10 by default)
Opening the connection5 seconds, within the above
Calls in one go3 calls between two customer messages, 30 seconds in all, retries included

The time counts until the whole answer is read, not only its headers.

Sizes

WhatLimit
Webhook body64 KB
Webhook answer kept in the delivery logFirst 2 KB
HTTP step or action body, once filled in64 KB
Path and query, once filled in4,096 characters
Answer to an HTTP step or action256 KB; a larger answer is a failure

Daily allowance

An account's HTTP steps and AI actions may make 10,000 calls a day together (UTC), every attempt counted, retries and tests included. After that, calls are not made until the next day: steps take their Failed path and actions tell the assistant they could not check. Webhook deliveries do not count towards it.

What we log

For each call to your API we keep the host, the path without its query string, the status, the duration and whether it was a retry, for 14 days. We do not log request or response bodies, which can hold customers' details. Credentials are removed from any answer before a flow or the assistant reads it.

On this page