# Setting up endpoints

Source: https://docs.revoplyai.com/webhooks/setting-up-endpoints/

> Add a webhook endpoint in the dashboard, the rules its URL must meet, and what editing, switching off and deleting do.

An endpoint is a URL your system listens on, with the events it receives and its own
signing secret. An account can have up to 10. Only an Owner or an Admin can manage them.

## Add an endpoint [#add-an-endpoint]

1. In the dashboard, open **Integrations → Webhooks** and choose **Add endpoint**.
2. Enter the **Endpoint URL**, and optionally a **Name** (up to 80 characters) to tell
   endpoints apart.
3. Choose the **Events** it should receive. Several endpoints may receive the same event;
   each gets its own delivery.
4. Save. The endpoint's **signing secret** (`whsec_…`) is shown once. Copy it into your
   server's configuration now: afterwards only its last four characters are shown, and a
   lost secret can only be replaced by [rotating it](/get-started/security/#rotating-a-webhook-secret).
5. Choose **Send test** to check your receiver; see [Testing](/webhooks/testing/).

## URL rules [#url-rules]

| Rule                                                                                                                       | Refused as           |
| -------------------------------------------------------------------------------------------------------------------------- | -------------------- |
| A full, absolute URL whose host name contains a dot, such as `https://example.com/webhooks/revoply` (so not `localhost`)   | Invalid address      |
| No username or password in it (`https://user:pass@…`) and no `#fragment`                                                   | Invalid address      |
| At most 500 characters                                                                                                     | Too long             |
| `https://` only: events carry customers' names, numbers and messages                                                       | Not HTTPS            |
| Not `revoplyai.com` or any of its subdomains                                                                               | One of our addresses |
| A public host that resolves only to public IP addresses: no private ranges, and no names ending in `.local` or `.internal` | Unreachable          |

A query string is allowed, so URLs that carry their own token (as Zapier's and Make's do)
work. Such a URL is a secret in its own right; we keep it out of our traces.

Our own addresses are refused so that events cannot loop. To start a flow when something
happens in RevoplyAI, use the flow's own triggers (a keyword, a new conversation, a tapped
button) instead of pointing a webhook at a [flow trigger](/flow-triggers/) URL.

## Edit, switch off, delete [#edit-switch-off-delete]

* **Edit** changes the name, URL or events. The URL rules are checked again.
* **Switch off** stops deliveries at once. Events that happen while an endpoint is off are
  not sent to it later. You can still send it a test.
* **Switch on** again when your receiver is fixed. Its count of failures starts over.
* **Delete** stops deliveries at once and deletes the endpoint's delivery log. It cannot
  be undone.

We switch an endpoint off ourselves when it answers `410 Gone`, or keeps failing; see
[Retries and the delivery log](/webhooks/retries-and-delivery-log/#when-we-switch-an-endpoint-off).

## Without the Business plan [#without-the-business-plan]

Endpoints are kept when an account leaves the Business plan, and can still be edited,
switched off and deleted, but nothing is sent to them. Adding an endpoint, sending tests,
rotating secrets and resending need the plan.
