# Requests we send

Source: https://docs.revoplyai.com/connect-your-systems/requests-we-send/

> What every request from RevoplyAI to your systems looks like, the addresses we refuse, and the timeouts, sizes and daily limits.

This page covers every request our servers make to yours: webhook deliveries, HTTP steps,
AI actions, and the test buttons for each.

## Headers [#headers]

| Header         | Webhook deliveries                | HTTP steps and AI actions                               |
| -------------- | --------------------------------- | ------------------------------------------------------- |
| `User-Agent`   | `RevoplyAI-Webhooks/1.0`          | `RevoplyAI-Automations/1.0`                             |
| `Content-Type` | `application/json; charset=utf-8` | `application/json; charset=utf-8`, when there is a body |
| `Accept`       | —                                 | `application/json`                                      |
| Authentication | `X-Revoply-Signature`             | The connection's credential                             |

HTTP steps and AI actions send the connection's default headers, then the step's or
action's own headers, then the credential, which nothing before it can replace. Header
values filled in from Arabic text are sent as UTF-8.

## Addresses we refuse [#addresses-we-refuse]

Every URL we call is under your control, and our servers make the call, so both are
checked:

* `https://` only, with a host name that contains a dot. No username or password in the
  URL.
* Names ending in `.local`, `.internal`, `.localdomain` or `.home.arpa` are refused.
* Every address the name resolves to must be public. Refused: private ranges (`10.0.0.0/8`,
  `172.16.0.0/12`, `192.168.0.0/16`), loopback, link-local (including `169.254.169.254`),
  carrier-grade NAT (`100.64.0.0/10`), multicast and reserved ranges, documentation and
  benchmarking ranges, IPv6 addresses outside global unicast (including `fc00::/7` and
  `fe80::/10`), and NAT64, 6to4 and Teredo addresses that lead to any of these.
* The check runs when you save the URL and again at every connection, so a name pointed
  at a private address after it was saved still cannot be reached.
* No redirects are followed; a `3xx` answer is a failure. No proxies, no cookies.

We do not publish a fixed list of IP addresses our requests come from. Authenticate them by
signature or credential, not by address.

## Timeouts [#timeouts]

| Request                     | Limit                                                                      |
| --------------------------- | -------------------------------------------------------------------------- |
| Webhook delivery            | 10 seconds for the whole request, answer included                          |
| HTTP step or AI action call | The connection's timeout, 1–15 seconds (10 by default)                     |
| Opening the connection      | 5 seconds, within the above                                                |
| Calls in one go             | 3 calls between two customer messages, 30 seconds in all, retries included |

The time counts until the whole answer is read, not only its headers.

## Sizes [#sizes]

| What                                     | Limit                                |
| ---------------------------------------- | ------------------------------------ |
| Webhook body                             | 64 KB                                |
| Webhook answer kept in the delivery log  | First 2 KB                           |
| HTTP step or action body, once filled in | 64 KB                                |
| Path and query, once filled in           | 4,096 characters                     |
| Answer to an HTTP step or action         | 256 KB; a larger answer is a failure |

## Daily allowance [#daily-allowance]

An account's HTTP steps and AI actions may make 10,000 calls a day together (UTC), every
attempt counted, retries and tests included. After that, calls are not made until the next
day: steps take their Failed path and actions tell the assistant they could not check.
Webhook deliveries do not count towards it.

## What we log [#what-we-log]

For each call to your API we keep the host, the path without its query string, the
status, the duration and whether it was a retry, for 14 days. We do not log request or
response bodies, which can hold customers' details. Credentials are removed from any answer
before a flow or the assistant reads it.
