Give your agent the moment, and a useful first draft.
LeadFast finds relevant public Reddit posts early, explains the match, and includes a short Suggested Reply. Your agent can route, enrich, or queue it. LeadFast never posts to Reddit.
Let your coding agent wire LeadFast into your backend.
Paste this into your coding agent
Configure my backend to receive LeadFast webhook V1 events.
Use the contract at https://leadfast.vip/docs/webhooks.md.
First inspect the existing backend, its framework conventions, deployment model, raw-body handling, environment configuration, and test setup. Reuse those boundaries instead of adding a parallel service.
Create one public HTTPS POST endpoint on port 443. Preserve the exact raw request bytes. Verify LeadFast-Signature as HMAC-SHA256 using my server-side LeadFast signing secret, the LeadFast-Delivery header, and the timestamp from the signature. Reject signatures outside the five-minute tolerance window, compare digests in constant time, and deduplicate retries by LeadFast-Delivery. Return a 2xx response quickly after validation, then process the event asynchronously.
For product.understanding.updated, persist previous_version, product_version and differences. This event reports an effective monitoring change and requires no action.
For reddit.post.matched, persist the post, match, suggested_reply, and delivery ID. Do not post to Reddit automatically. Expose suggested_reply as optional source material for a human or a separately authorized workflow.
Read the signing secret from an environment variable named LEADFAST_WEBHOOK_SECRET. Never put it in browser code, logs, commits, or this prompt. Add tests for a valid signature, a changed body, an expired timestamp, and a duplicate delivery.
Do not deploy, create external resources, change DNS, or expose a public endpoint unless the current task explicitly authorizes that action. Return the implemented endpoint path, required environment variable, tests run, and exact remaining deployment configuration. If deployment is explicitly authorized, deploy through the repository's existing path and return the verified public endpoint.One signed event. Everything it needs.
The V1 payload contains the Reddit post, Match Score, rationale, freshness, and exact Suggested Reply. Delivery is at least once, so agents verify the signature and deduplicate by delivery ID before acting.
{
"event": "reddit.post.matched",
"version": 1,
"test": false,
"sent_at": "2026-08-29T18:03:00.000Z",
"post": {
"id": "1abc234",
"title": "How do you find relevant Reddit posts early?",
"excerpt": "We keep arriving after the discussion is over...",
"url": "https://www.reddit.com/r/SaaS/comments/1abc234/",
"subreddit": "SaaS",
"published_at": "2026-08-29T18:01:00.000Z"
},
"match": {
"score": 86,
"band": "strong",
"reason": "The author has a current late-discovery problem."
},
"suggested_reply": "We make LeadFast to surface relevant Reddit posts while the conversation is still fresh.",
"post_age_seconds": 120
}Verify before processing.
Preserve the exact raw request bytes. Compute HMAC-SHA256(secret, timestamp + "." + delivery_id + "." + raw_body), compare the digest in constant time, reject timestamps outside the five-minute tolerance window, and deduplicate by LeadFast-Delivery.
The setup prompt contains no signing secret and grants the coding agent no authority to operate LeadFast, deploy infrastructure, or act on Reddit.
Read the complete webhook guide or give an agent the Markdown version of this page, or the canonical webhook contract in Markdown.
cURL request shape
This signature is a placeholder. Use Send test in LeadFast for an authentic signed request.
curl --request POST 'https://your-domain.example/leadfast' \
--header 'Content-Type: application/json' \
--header 'LeadFast-Event: webhook.test' \
--header 'LeadFast-Delivery: 00000000-0000-4000-8000-000000000000' \
--header 'LeadFast-Signature: t=TIMESTAMP,v1=HMAC_SHA256' \
--data '{"event":"webhook.test","version":1,"test":true,"sent_at":"2026-08-29T18:03:00.000Z"}'