Glossary

What is a webhook?

A webhook is how one app tells another that something has happened, the moment it happens. You give the first app a web address, and it sends a short message there for each event, such as a new comment or DM, so the second app doesn’t have to keep asking.

Updated 6 October 2026

A webhook is an automatic HTTP request one app sends to a URL you choose whenever an event happens, such as a new comment, so nobody has to keep checking.

Automation and Meta's API

How a webhook works

Compare refreshing a parcel-tracking page with getting a text when the parcel arrives. Checking on a timer, called polling, spends requests on “nothing new” and is always a little late. A webhook turns it around: the service that knows about the event sends the news to you.

  1. You register a URL, often called a callback or endpoint, with the service, and choose which events you want to hear about.
  2. When one happens, the service sends an HTTP POST request to that URL with the details as JSON: what happened, to which object, and when.
  3. Your server checks that the request is genuine, answers 200 OK to confirm it arrived, and then acts on it.
  4. If a delivery fails, the service tries again for a limited time, then gives up.

Tip: A webhook only reports. To act on the news, such as replying to a comment, the receiving app still calls the service’s API with its own access token.

How Meta’s webhooks work for Instagram and Facebook

Every comment-to-DM and auto-reply tool built on Meta’s official API depends on webhooks, and Meta’s documentation sets the rules:

  • A handshake first. When a developer saves the URL in Meta’s App Dashboard, Meta sends a GET request with hub.mode set to subscribe, a hub.verify_token the developer chose and a hub.challenge number. The server checks the token and sends the challenge back.
  • Signed deliveries. Each notification carries an X-Hub-Signature-256 header, a SHA-256 signature of the payload made with the app’s App Secret, so the receiver can reject forgeries.
  • Batches and retries. Meta can group up to 1,000 updates in one request, though batching isn’t guaranteed. A failed delivery is retried straight away, then a few more times, less and less often, over 36 hours.
  • Duplicates. Meta asks developers to handle deduplication, so a careful tool records each event and ignores repeats.
  • A proper certificate. The endpoint needs a valid TLS certificate; self-signed ones aren’t supported.

Instagram adds conditions of its own. The app must be set to Live, it needs Advanced Access to receive comment notifications, the app has to be subscribed to each connected account, and the account that owns the post must be public for comment and @mention notifications to be sent. Comments during a Live arrive only while the broadcast is on.

Instagram fieldWhat it reports
commentsNew comments on the account’s posts and Reels
live_commentsComments made during a Live broadcast
messagesDMs to the account, including Story replies and Story mentions
messaging_postbacksTaps on buttons the account sent
message_reactionsReactions to messages in a chat
messaging_seenRead receipts for messages
mentions@mentions of the account
story_insightsPerformance figures for the account’s Stories

Notice what isn’t there: no field for new followers. That’s why no tool built on the official API can DM someone the instant they follow; the person has to comment or message first.

When a comment automation goes quiet

Webhooks are why an auto-reply can land moments after a comment, and they’re the first thing to check when replies stop. The usual causes:

  • The account was disconnected or its access expired. Reconnecting the account in the tool usually fixes it.
  • The account went private or became a personal account. Meta only sends comment notifications for public professional accounts.
  • Another app answered first. If two automation tools are connected to one account, each receives the same comment, and since Meta allows one private reply per comment, only the first succeeds.

Tip: Building one yourself? Answer 200 OK at once and do the slow work afterwards, check the signature before trusting the body, and store each event’s ID so a retried delivery never sends the same DM twice.

An example

A print shop asks followers to comment PROOF on a Reel. When someone does, Meta posts the comment’s text, ID and author to the webhook URL of the shop’s automation tool, which answers under the comment and in a private reply.

Questions people ask

What’s the difference between a webhook and an API?

An API is how your app asks a service for something or tells it to do something, such as sending a message. A webhook works the other way round: the service tells your app when something happens. Most automations need both, a webhook to hear about the comment and an API call to answer it.

Is a webhook secure?

It can be. The URL is public, so anyone could send it a request; what makes it safe is checking each one. Meta signs every notification with the app’s secret, and the receiving server should reject any request whose signature doesn’t match.

Can I use webhooks without writing code?

Yes. Services such as Zapier and Make can receive webhooks and pass the data on to other apps, and comment-to-DM tools handle Meta’s webhooks for you once you connect your account.

Does Instagram send a webhook when someone follows me?

No. Meta’s list of Instagram webhook fields covers comments, messages, mentions, reactions and similar events, but not follows. A tool can’t greet new followers the moment they follow; it can only reply once they message or comment.

Do Facebook Pages use webhooks too?

Yes. A Page subscribed to an app sends notifications through the same system, for events such as new comments on the Page’s posts and Messenger messages. The handshake, the signature and the retries work the same way.

Sources

Related terms

More terms

Comment-to-DM, without writing code

DMFast runs on Meta’s official APIs: someone comments your keyword and gets a reply and a DM in seconds. It works from ChatGPT and Claude too. Free plan, no card.

Start free