# Security

Source: https://docs.revoplyai.com/get-started/security/

> Verify what we send you, keep secrets on your server, and what to do when a secret or URL leaks.

Three kinds of secret connect RevoplyAI and your systems. Each is shown once and belongs
on your server only: never in a browser, a mobile app, a repository or a support email.

| Secret                    | Looks like            | Proves                                  | If it leaks                                                 |
| ------------------------- | --------------------- | --------------------------------------- | ----------------------------------------------------------- |
| Webhook signing secret    | `whsec_…`             | A request to your endpoint came from us | Rotate it                                                   |
| Flow trigger URL          | `…/hooks/rvh_…`       | Anyone holding it may start that flow   | Replace the URL                                             |
| API connection credential | Your own token or key | A call to your API came from us         | Revoke it in your system, then replace it in the connection |

Only an Owner or an Admin can see, create, rotate or replace them.

## Requests we send you [#requests-we-send-you]

* **Verify every signature** before trusting a body; see [Signatures](/webhooks/signatures/)
  and the [verification guide](/guides/verify-webhook-signatures/). Refuse a request signed
  more than 5 minutes ago, which stops a captured request being replayed later.
* **Do not rely on our IP addresses.** We do not publish a fixed set of addresses our
  requests come from. Authenticate by signature for webhooks, and by the credential in the
  connection for calls to your API.
* **HTTPS only.** Webhook endpoints and API connections must use `https://` and resolve to
  public addresses. We check the address again at every connection.
* **We do not follow redirects.** A `3xx` answer is a failed delivery or call. Give us the
  final URL.

## Rotating a webhook secret [#rotating-a-webhook-secret]

Rotating (**Integrations → Webhooks → Rotate**) shows a new secret once. For the next
24 hours every delivery is signed with both the old and the new secret, as two `v1`
values, so your receiver keeps accepting deliveries while you deploy the new one.

After a leak, rotate twice: the second rotation retires the leaked secret at once, because
only the two most recent secrets ever sign.

## Replacing a flow trigger URL [#replacing-a-flow-trigger-url]

**Replace the URL** in the flow's trigger shows a new URL once. The old one stops working
at once and answers `404 not_found`. Update every system that sends to it.

## API connection credentials [#api-connection-credentials]

A connection's token, key or password is stored encrypted and never shown again; the
dashboard shows its last four characters at most. It is added to each request after the
request is built, so flow variables, customer messages and the assistant never see it,
and it is removed from any response text before a flow or the assistant reads it. See
[Requests we send](/connect-your-systems/requests-we-send/).

## The website widget [#the-website-widget]

The widget's channel id is public by design: it sits in your page's source. Set
**Allowed domains** on the channel so other sites cannot load it. See
[Security and CSP](/widget/security-and-csp/).

## Reporting a vulnerability [#reporting-a-vulnerability]

Email [support@revoplyai.com](mailto:support@revoplyai.com) with the details. Do not
include secrets or customers' data.
