Glossary
What is a webhook?
A webhook is how one app tells another that something has happened, the moment it happens. You give the first app a web address, and it sends a short message there for each event, such as a new comment or DM, so the second app doesn’t have to keep asking.
Updated 6 October 2026
A webhook is an automatic HTTP request one app sends to a URL you choose whenever an event happens, such as a new comment, so nobody has to keep checking.
How a webhook works
Compare refreshing a parcel-tracking page with getting a text when the parcel arrives. Checking on a timer, called polling, spends requests on “nothing new” and is always a little late. A webhook turns it around: the service that knows about the event sends the news to you.
- You register a URL, often called a callback or endpoint, with the service, and choose which events you want to hear about.
- When one happens, the service sends an HTTP POST request to that URL with the details as JSON: what happened, to which object, and when.
- Your server checks that the request is genuine, answers 200 OK to confirm it arrived, and then acts on it.
- If a delivery fails, the service tries again for a limited time, then gives up.
Tip: A webhook only reports. To act on the news, such as replying to a comment, the receiving app still calls the service’s API with its own access token.
How Meta’s webhooks work for Instagram and Facebook
Every comment-to-DM and auto-reply tool built on Meta’s official API depends on webhooks, and Meta’s documentation sets the rules:
- A handshake first. When a developer saves the URL in Meta’s App Dashboard, Meta sends a GET request with hub.mode set to subscribe, a hub.verify_token the developer chose and a hub.challenge number. The server checks the token and sends the challenge back.
- Signed deliveries. Each notification carries an X-Hub-Signature-256 header, a SHA-256 signature of the payload made with the app’s App Secret, so the receiver can reject forgeries.
- Batches and retries. Meta can group up to 1,000 updates in one request, though batching isn’t guaranteed. A failed delivery is retried straight away, then a few more times, less and less often, over 36 hours.
- Duplicates. Meta asks developers to handle deduplication, so a careful tool records each event and ignores repeats.
- A proper certificate. The endpoint needs a valid TLS certificate; self-signed ones aren’t supported.
Instagram adds conditions of its own. The app must be set to Live, it needs Advanced Access to receive comment notifications, the app has to be subscribed to each connected account, and the account that owns the post must be public for comment and @mention notifications to be sent. Comments during a Live arrive only while the broadcast is on.
| Instagram field | What it reports |
|---|---|
| comments | New comments on the account’s posts and Reels |
| live_comments | Comments made during a Live broadcast |
| messages | DMs to the account, including Story replies and Story mentions |
| messaging_postbacks | Taps on buttons the account sent |
| message_reactions | Reactions to messages in a chat |
| messaging_seen | Read receipts for messages |
| mentions | @mentions of the account |
| story_insights | Performance figures for the account’s Stories |
Notice what isn’t there: no field for new followers. That’s why no tool built on the official API can DM someone the instant they follow; the person has to comment or message first.
When a comment automation goes quiet
Webhooks are why an auto-reply can land moments after a comment, and they’re the first thing to check when replies stop. The usual causes:
- The account was disconnected or its access expired. Reconnecting the account in the tool usually fixes it.
- The account went private or became a personal account. Meta only sends comment notifications for public professional accounts.
- Another app answered first. If two automation tools are connected to one account, each receives the same comment, and since Meta allows one private reply per comment, only the first succeeds.
Tip: Building one yourself? Answer 200 OK at once and do the slow work afterwards, check the signature before trusting the body, and store each event’s ID so a retried delivery never sends the same DM twice.
An example
A print shop asks followers to comment PROOF on a Reel. When someone does, Meta posts the comment’s text, ID and author to the webhook URL of the shop’s automation tool, which answers under the comment and in a private reply.
Questions people ask
What’s the difference between a webhook and an API?
An API is how your app asks a service for something or tells it to do something, such as sending a message. A webhook works the other way round: the service tells your app when something happens. Most automations need both, a webhook to hear about the comment and an API call to answer it.
Is a webhook secure?
It can be. The URL is public, so anyone could send it a request; what makes it safe is checking each one. Meta signs every notification with the app’s secret, and the receiving server should reject any request whose signature doesn’t match.
Can I use webhooks without writing code?
Yes. Services such as Zapier and Make can receive webhooks and pass the data on to other apps, and comment-to-DM tools handle Meta’s webhooks for you once you connect your account.
Does Instagram send a webhook when someone follows me?
No. Meta’s list of Instagram webhook fields covers comments, messages, mentions, reactions and similar events, but not follows. A tool can’t greet new followers the moment they follow; it can only reply once they message or comment.
Do Facebook Pages use webhooks too?
Yes. A Page subscribed to an app sends notifications through the same system, for events such as new comments on the Page’s posts and Messenger messages. The handshake, the signature and the retries work the same way.
Sources
Related terms
- API rate limitAn API rate limit caps how many requests an app may make to a service in a set period, such as 750 private replies an hour for one Instagram account.
- OAuth loginOAuth lets an app act on your account without your password: you approve specific permissions on the account’s own site, and the app receives a token.
- Instagram API with Instagram LoginThe Instagram API with Instagram Login lets apps work with an Instagram professional account that signs in with Instagram, without a linked Facebook Page.
- Messenger PlatformThe Messenger Platform is Meta’s free API that passes messages sent to a Facebook Page, or a linked Instagram account, to an app and lets the app reply.
- Advanced AccessAdvanced Access lets a Meta app request a permission from any user, not just its own team. Each permission or feature is approved separately in App Review.
- Meta App ReviewMeta App Review is the check an app must pass, permission by permission, before it can use Meta’s APIs for people outside its own team.
More terms
Comment-to-DM, without writing code
DMFast runs on Meta’s official APIs: someone comments your keyword and gets a reply and a DM in seconds. It works from ChatGPT and Claude too. Free plan, no card.
Start free