RevoplyAIDocs
Get started

Security

Verify what we send you, keep secrets on your server, and what to do when a secret or URL leaks.

Three kinds of secret connect RevoplyAI and your systems. Each is shown once and belongs on your server only: never in a browser, a mobile app, a repository or a support email.

SecretLooks likeProvesIf it leaks
Webhook signing secretwhsec_…A request to your endpoint came from usRotate it
Flow trigger URL…/hooks/rvh_…Anyone holding it may start that flowReplace the URL
API connection credentialYour own token or keyA call to your API came from usRevoke it in your system, then replace it in the connection

Only an Owner or an Admin can see, create, rotate or replace them.

Requests we send you

  • Verify every signature before trusting a body; see Signatures and the verification guide. Refuse a request signed more than 5 minutes ago, which stops a captured request being replayed later.
  • Do not rely on our IP addresses. We do not publish a fixed set of addresses our requests come from. Authenticate by signature for webhooks, and by the credential in the connection for calls to your API.
  • HTTPS only. Webhook endpoints and API connections must use https:// and resolve to public addresses. We check the address again at every connection.
  • We do not follow redirects. A 3xx answer is a failed delivery or call. Give us the final URL.

Rotating a webhook secret

Rotating (Integrations → Webhooks → Rotate) shows a new secret once. For the next 24 hours every delivery is signed with both the old and the new secret, as two v1 values, so your receiver keeps accepting deliveries while you deploy the new one.

After a leak, rotate twice: the second rotation retires the leaked secret at once, because only the two most recent secrets ever sign.

Replacing a flow trigger URL

Replace the URL in the flow's trigger shows a new URL once. The old one stops working at once and answers 404 not_found. Update every system that sends to it.

API connection credentials

A connection's token, key or password is stored encrypted and never shown again; the dashboard shows its last four characters at most. It is added to each request after the request is built, so flow variables, customer messages and the assistant never see it, and it is removed from any response text before a flow or the assistant reads it. See Requests we send.

The website widget

The widget's channel id is public by design: it sits in your page's source. Set Allowed domains on the channel so other sites cannot load it. See Security and CSP.

Reporting a vulnerability

Email support@revoplyai.com with the details. Do not include secrets or customers' data.

On this page