# DLRI Lead Engine — deploy notes

**Components**
- `landing.html` — "Check My Rate" final expense landing page (mobile-first, brand-styled, TCPA consent block). Posts JSON to `/lead`.
- `lead-api.py` — public lead endpoint + static host for this folder.
  - `POST /lead` → appends to `leads.jsonl`, fires Telegram alert (DLRI chat), optional Twenty CRM create.
  - `GET /health` → `{ok, leads}`.
- `privacy.html`, `terms.html` — required legal pages (consent links).
- `AD-AND-NURTURE-COPY.md` / `.pdf` — 5 ad angles + speed-to-lead SMS + 5-email nurture.
- `LEAD-ENGINE-SPEC.md` / `.pdf` (parent `insurance/`) — full build spec.

**Run**
```
cd insurance/lead-engine && nohup python3 lead-api.py > /tmp/dlri-lead-api.log 2>&1 &
# env: DLRI_LEAD_BIND (default 0.0.0.0), DLRI_LEAD_PORT (default 9096), TWENTY_ENABLE=1 to push to Twenty
```
Secrets read from `~/.openclaw/credentials/dlri.env` (DLRI_TELEGRAM_CHAT) + `bot-tokens.env` (MRPABLO_BOT_TOKEN).

**Protections:** honeypot field (`company`), per-IP rate limit (8/min), 8KB body cap. Public endpoint by design (browsers post it).

**Local URL:** http://100.93.149.83:9096/landing.html (Tailscale)

**Still needed before paid ads run (money / setup — Joan's call):**
1. **Public HTTPS URL** — custom domain (e.g. getdelarosainsurance.com or a `join.` subdomain) via nginx + cert, so Meta approves the page.
2. **Twilio + A2P 10DLC** — for automated speed-to-lead SMS (needs the entity/EIN from `DLRI-ENTITY-PLAN.md`). Until then, the Telegram alert + click-to-call is the speed-to-lead path.
3. **Meta Business Manager + Pixel ID** — set `window.DLRI_PIXEL_ID` in `landing.html`; ad spend is the cost checkpoint.
4. **Twenty custom fields** — map lead fields + consent before enabling `TWENTY_ENABLE=1`.
