Reference
SDK lifecycle, credentials, receiver security, and troubleshooting.
Call acp.start() once when your application starts. It sends an immediate heartbeat and then repeats every 30 seconds by default. Reports are buffered and flushed every five seconds or after fifty runs. The default buffer cap is 200; excess records can be dropped.
API keys and scopesCreating an app mints an acp_ -prefixed key with 24 random bytes. The raw value is returned once. ACP stores only its SHA-256 hash and a display prefix.
Webhooks and securityThe SDK verifies the signature, timestamp, and nonce against the raw request body before applying a command. Configure the previous secret explicitly during rotation.
TroubleshootingCheck that all three env vars are set in the server environment, that sendHeartbeat() runs at startup, and that the app's own logs show no [ACP] Heartbeat failed line. The client swallows the error deliberately, so the log is the only signal.