Fresh Reddit opportunities, ready for your backend.
LeadFast sends one signed JSON event with the post, score, match rationale, and Suggested Reply. Delivery is at least once. LeadFast never posts to Reddit.
Let an agent wire it up
Configure my backend to receive LeadFast webhook V1 events.
Use the contract at https://leadfast.vip/docs/webhooks.md.
First inspect the existing backend, its framework conventions, deployment model, raw-body handling, environment configuration, and test setup. Reuse those boundaries instead of adding a parallel service.
Create one public HTTPS POST endpoint on port 443. Preserve the exact raw request bytes. Verify LeadFast-Signature as HMAC-SHA256 using my server-side LeadFast signing secret, the LeadFast-Delivery header, and the timestamp from the signature. Reject signatures outside the five-minute tolerance window, compare digests in constant time, and deduplicate retries by LeadFast-Delivery. Return a 2xx response quickly after validation, then process the event asynchronously.
For product.understanding.updated, persist previous_version, product_version and differences. This event reports an effective monitoring change and requires no action.
For reddit.post.matched, persist the post, match, suggested_reply, and delivery ID. Do not post to Reddit automatically. Expose suggested_reply as optional source material for a human or a separately authorized workflow.
Read the signing secret from an environment variable named LEADFAST_WEBHOOK_SECRET. Never put it in browser code, logs, commits, or this prompt. Add tests for a valid signature, a changed body, an expired timestamp, and a duplicate delivery.
Do not deploy, create external resources, change DNS, or expose a public endpoint unless the current task explicitly authorizes that action. Return the implemented endpoint path, required environment variable, tests run, and exact remaining deployment configuration. If deployment is explicitly authorized, deploy through the repository's existing path and return the verified public endpoint.Endpoint and delivery
- Use one public HTTPS URL on port 443.
- Return any 2xx status within 10 seconds.
- LeadFast does not follow redirects.
- Deduplicate retries using the stable LeadFast-Delivery header.
Verify every request
Read the raw request bytes before parsing JSON. Parse the timestamp and digest from LeadFast-Signature, then compute HMAC-SHA256(secret, timestamp + "." + delivery_id + "." + raw_body). Reject timestamps outside the five-minute tolerance window and compare digests in constant time.
The signing secret is generated once per account and has no automatic expiration. Regenerating it invalidates the previous value immediately and pauses delivery until a new test succeeds.
Matched-post payload
{
"event": "reddit.post.matched",
"version": 1,
"test": false,
"sent_at": "2026-08-29T18:03:00.000Z",
"post": {
"id": "1abc234",
"title": "How do you find relevant Reddit posts early?",
"excerpt": "We keep arriving after the discussion is over...",
"url": "https://www.reddit.com/r/SaaS/comments/1abc234/",
"subreddit": "SaaS",
"published_at": "2026-08-29T18:01:00.000Z"
},
"match": {
"score": 86,
"band": "strong",
"reason": "The author has a current late-discovery problem."
},
"suggested_reply": "We make LeadFast to surface relevant Reddit posts while the conversation is still fresh.",
"post_age_seconds": 120
}Product understanding updates
The separate product.understanding.updated event reports effective monitoring changes after a website review. It contains previous_version, product_version, and a differences array, alongside version 1, sent_at and test: false. Use the same signature verification and delivery-ID deduplication. No action is required from your customer.
cURL request shape
The signature is a placeholder. Use Send test in LeadFast for an authentic signed request.
curl --request POST 'https://your-domain.example/leadfast' \
--header 'Content-Type: application/json' \
--header 'LeadFast-Event: webhook.test' \
--header 'LeadFast-Delivery: 00000000-0000-4000-8000-000000000000' \
--header 'LeadFast-Signature: t=TIMESTAMP,v1=HMAC_SHA256' \
--data '{"event":"webhook.test","version":1,"test":true,"sent_at":"2026-08-29T18:03:00.000Z"}'