# LeadFast for AI agents

LeadFast finds relevant public Reddit posts while conversations are fresh, scores each match, and produces a short Suggested Reply. It delivers the result to Slack, Telegram, email, or a signed webhook. It never posts, comments, messages, votes, follows, or contacts anyone on Reddit.

## Best agent interface

Use the signed webhook V1 contract: https://leadfast.vip/docs/webhooks.md

For each `reddit.post.matched` event:

1. Verify the raw-body HMAC signature and reject timestamps outside the five-minute tolerance window.
2. Deduplicate by `LeadFast-Delivery`.
3. Use the post, match rationale, and `suggested_reply` fields.
4. Treat `suggested_reply` as optional source material, not permission to post.
5. Return 2xx quickly and do slower work asynchronously.

The setup prompt contains no signing secret and grants no authority to operate LeadFast, deploy infrastructure, or act on Reddit.

## Matched-post payload

```json
{
  "event": "reddit.post.matched",
  "version": 1,
  "test": false,
  "sent_at": "2026-08-29T18:03:00.000Z",
  "post": {
    "id": "1abc234",
    "title": "How do you find relevant Reddit posts early?",
    "excerpt": "We keep arriving after the discussion is over...",
    "url": "https://www.reddit.com/r/SaaS/comments/1abc234/",
    "subreddit": "SaaS",
    "published_at": "2026-08-29T18:01:00.000Z"
  },
  "match": {
    "score": 86,
    "band": "strong",
    "reason": "The author has a current late-discovery problem."
  },
  "suggested_reply": "We make LeadFast to surface relevant Reddit posts while the conversation is still fresh.",
  "post_age_seconds": 120
}
```

## Product-understanding changes

The distinct `product.understanding.updated` event contains `version: 1`, `test: false`, `sent_at`, `previous_version`, `product_version`, and a `differences` array. It is emitted only after effective monitoring changes are verified. Use the same signature validation and delivery deduplication.

## cURL request shape

```bash
curl --request POST 'https://your-domain.example/leadfast' \
  --header 'Content-Type: application/json' \
  --header 'LeadFast-Event: webhook.test' \
  --header 'LeadFast-Delivery: 00000000-0000-4000-8000-000000000000' \
  --header 'LeadFast-Signature: t=TIMESTAMP,v1=HMAC_SHA256' \
  --data '{"event":"webhook.test","version":1,"test":true,"sent_at":"2026-08-29T18:03:00.000Z"}'
```

## Setup prompt

```text
Configure my backend to receive LeadFast webhook V1 events.

Use the contract at https://leadfast.vip/docs/webhooks.md.

First inspect the existing backend, its framework conventions, deployment model, raw-body handling, environment configuration, and test setup. Reuse those boundaries instead of adding a parallel service.

Create one public HTTPS POST endpoint on port 443. Preserve the exact raw request bytes. Verify LeadFast-Signature as HMAC-SHA256 using my server-side LeadFast signing secret, the LeadFast-Delivery header, and the timestamp from the signature. Reject signatures outside the five-minute tolerance window, compare digests in constant time, and deduplicate retries by LeadFast-Delivery. Return a 2xx response quickly after validation, then process the event asynchronously.

For product.understanding.updated, persist previous_version, product_version and differences. This event reports an effective monitoring change and requires no action.

For reddit.post.matched, persist the post, match, suggested_reply, and delivery ID. Do not post to Reddit automatically. Expose suggested_reply as optional source material for a human or a separately authorized workflow.

Read the signing secret from an environment variable named LEADFAST_WEBHOOK_SECRET. Never put it in browser code, logs, commits, or this prompt. Add tests for a valid signature, a changed body, an expired timestamp, and a duplicate delivery.

Do not deploy, create external resources, change DNS, or expose a public endpoint unless the current task explicitly authorizes that action. Return the implemented endpoint path, required environment variable, tests run, and exact remaining deployment configuration. If deployment is explicitly authorized, deploy through the repository's existing path and return the verified public endpoint.
```
