Create an endpoint
events (or send an empty list) to receive everything, including events
added later.
Events
The list is closed and names are
object.past_tense. New events are added over
time; existing ones are never renamed.
Payload
Every delivery shares one envelope:data carries the resource in the same shape the REST API returns it, so the
post in post.published is the post you’d get from GET /v1/posts/{id}.
Verifying a delivery
Each request carries anx-plugkit-signature header:
v1 is the HMAC-SHA256 of <t>.<raw body>, keyed with your endpoint secret.
Compute it over the raw body — parsing and re-serialising the JSON changes
the bytes and breaks the comparison.
Delivery and retries
Answer2xx within 10 seconds. Anything else — an error status, a timeout,
a connection refused — is retried up to 6 attempts with backoff: 30s, 2min,
8min, 32min, ~2h, then the delivery is marked FAILED.
Events are queued and sent by a worker, never inside the request that triggered
them. A slow endpoint of yours never slows down a publication, and a broken one
never makes it fail.
Deliveries are at least once: a retry after a response you sent late will
arrive twice. Deduplicate on the payload’s id.
Inspect what happened:
Managing endpoints
These are PlugKit’s outbound webhooks. The inbound plumbing — subscribing
an account to Meta’s own webhooks so DMs reach the inbox at all — happens
automatically when an account is connected. It can be re-run for Instagram
(
POST /v1/connect/instagram/{accountId}/subscribe-webhooks) and WhatsApp
(POST /v1/connect/whatsapp/{accountId}/subscribe-webhooks); a Facebook Page
subscribes once at connection time, so a Page that missed it has to be
reconnected.