Security
Verify what we send you, keep secrets on your server, and what to do when a secret or URL leaks.
Three kinds of secret connect RevoplyAI and your systems. Each is shown once and belongs on your server only: never in a browser, a mobile app, a repository or a support email.
| Secret | Looks like | Proves | If it leaks |
|---|---|---|---|
| Webhook signing secret | whsec_… | A request to your endpoint came from us | Rotate it |
| Flow trigger URL | …/hooks/rvh_… | Anyone holding it may start that flow | Replace the URL |
| API connection credential | Your own token or key | A call to your API came from us | Revoke it in your system, then replace it in the connection |
Only an Owner or an Admin can see, create, rotate or replace them.
Requests we send you
- Verify every signature before trusting a body; see Signatures and the verification guide. Refuse a request signed more than 5 minutes ago, which stops a captured request being replayed later.
- Do not rely on our IP addresses. We do not publish a fixed set of addresses our requests come from. Authenticate by signature for webhooks, and by the credential in the connection for calls to your API.
- HTTPS only. Webhook endpoints and API connections must use
https://and resolve to public addresses. We check the address again at every connection. - We do not follow redirects. A
3xxanswer is a failed delivery or call. Give us the final URL.
Rotating a webhook secret
Rotating (Integrations → Webhooks → Rotate) shows a new secret once. For the next
24 hours every delivery is signed with both the old and the new secret, as two v1
values, so your receiver keeps accepting deliveries while you deploy the new one.
After a leak, rotate twice: the second rotation retires the leaked secret at once, because only the two most recent secrets ever sign.
Replacing a flow trigger URL
Replace the URL in the flow's trigger shows a new URL once. The old one stops working
at once and answers 404 not_found. Update every system that sends to it.
API connection credentials
A connection's token, key or password is stored encrypted and never shown again; the dashboard shows its last four characters at most. It is added to each request after the request is built, so flow variables, customer messages and the assistant never see it, and it is removed from any response text before a flow or the assistant reads it. See Requests we send.
The website widget
The widget's channel id is public by design: it sits in your page's source. Set Allowed domains on the channel so other sites cannot load it. See Security and CSP.
Reporting a vulnerability
Email support@revoplyai.com with the details. Do not include secrets or customers' data.