Destination security and limits
How Dcision protects outgoing requests — https only, SSRF guard, no redirects, secrets — what each destination type sends and stores, who can configure what, and every destination limit.
Outgoing requests
Webhooks, API requests, workflows and agents call URLs you configure, so Dcision guards every connection:
- https only. A URL starts with
https://, or with a secret that holds the whole URL.http://URLs are refused when you save. - Public addresses only. The host name is resolved when Dcision connects, and every address is checked at that moment, inside the connection itself — a name can't resolve to a public address for the check and a private one for the request. Literal IP addresses are checked too.
- No credentials in URLs.
https://user:password@…is refused: put credentials in a header, with a secret. - No redirects. A
3xxanswer is a failed delivery; Dcision never follows it. - Short and bounded. 10 seconds per delivery attempt (up to 25 seconds for LLM and
syncagent calls), answers read up to 64 KB.
Blocked addresses:
| Range | What it is |
|---|---|
0.0.0.0/8 | "This" network |
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 | Private networks |
100.64.0.0/10 | Carrier-grade NAT |
127.0.0.0/8 | Loopback |
169.254.0.0/16 | Link-local, including cloud metadata services |
192.0.0.0/24, 192.0.2.0/24, 192.88.99.0/24, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24 | Reserved, test and benchmarking ranges |
224.0.0.0/4, 240.0.0.0/4 | Multicast, reserved and broadcast |
::, ::1, fc00::/7, fe80::/10, fec0::/10, ff00::/8, 2001:db8::/32, 100::/64 | IPv6 unspecified, loopback, unique local, link-local, site-local, multicast, documentation and discard |
IPv4-mapped, IPv4-compatible, NAT64 (64:ff9b::/96) and 6to4 (2002::/16) addresses | Blocked when the IPv4 address inside is |
Host names that end in .local, .internal or .localdomain — and names that resolve to any blocked address, such as internal service names — are refused too.
Secrets
- Workspace secrets are encrypted with AES-256-GCM and never appear in the decision schema, responses, execution logs or the Playground — previews mask them as
••••. - The values of your headers are never written to Dcision's logs; keep tokens in secrets anyway, because the app shows a masked preview of every delivery's request, headers included.
- The signing secret is encrypted too, and only Admins and the Owner can reveal or rotate it.
What leaves Dcision
| Type | What the receiver gets |
|---|---|
reply | Nothing leaves: the text is returned to the caller. |
function | Nothing leaves: the function name and params are returned to the caller. |
llm | The model provider — under your key and account — gets the route's prompt and the input: the whole state unless you set input. |
agent | Your agent gets the whole state as input, the instructions, tools, params and the decision's answers. |
webhook | The answers, confidence, weighted levels, composites, action, reason and params — never the state. |
workflow | The params and the decision's answers — never the state. |
http | Exactly what your URL, headers and body template contain. |
Map only what a receiver needs: params are the data-minimization tool of destinations.
What Dcision stores
- The execution keeps the run's
destinationsentries — including function params, fixed replies, LLM texts and agent answers — whatever the decision'sstoreInputandstoreOutputsettings. They follow the execution's log retention and appear inGET /v1/executions. If params carry personal data, the entries do too. - Deliveries keep their status, attempts, the answer's status code, latency and first 1,024 characters, a masked preview of the request — method, URL, headers and the body's size, never the body — and, encrypted, the full request while it may be resent. They are deleted 30 days after they were created.
See Security and data for the rest of what Dcision stores.
Who can configure what
| Action | Viewer | Member | Admin | Owner |
|---|---|---|---|---|
| See destinations, deliveries and their status | ✓ | ✓ | ✓ | ✓ |
| Add, edit and deploy destinations | — | ✓ | ✓ | ✓ |
| Run destinations for real in the Playground | — | ✓ | ✓ | ✓ |
| Resend a failed delivery | — | ✓ | ✓ | ✓ |
| See secret names | — | ✓ | ✓ | ✓ |
| Manage secrets and the signing secret | — | — | ✓ | ✓ |
| Save LLM provider keys (Settings → Engine) | — | — | ✓ | ✓ |
Limits
| Limit | Value |
|---|---|
| Destinations per decision | 20 |
| Destinations that fire per execution | 10 |
LLM answers and sync agents per execution | 3 |
| Conditions per destination | 5 |
| Params per destination | 30 |
| Fixed param value | up to 500 characters |
| Headers per destination | 20 |
| Header value | up to 2,048 characters |
| URL | up to 2,048 characters |
http body template | up to 10,000 characters |
| Destination description | up to 2,000 characters |
| Reply text | up to 4,000 characters |
| Reply buttons | up to 10, up to 80 characters each |
| LLM prompt, LLM input, agent instructions | up to 8,000 characters each |
| Agent tools | up to 50 |
LLM and sync agent timeout | 1,000 to 25,000 ms, default 20,000 |
LLM maxTokens | 16 to 2,048, default 512 |
LLM temperature | 0 to 2, default 0.3 |
Agent answer returned in response | up to 16,000 characters |
| Delivery attempts | 6, over about 7 hours |
| Delivery attempt timeout | 10 seconds |
| Deliveries per workspace | 600 per minute |
| Delivery retention | 30 days |
| Workspace secrets | 50, values up to 4,096 characters |
Testing destinations
Preview destinations in the Playground with secrets masked, run them for real with livemode false, use test API keys and follow deliveries, attempts and receiver answers.
API overview
Base URL, versioning, request and response conventions, headers and IDs of the Dcision public API.