Message body
Instagram sends messaging events as nested JSON:entry, then messaging.This body is different from the WhatsApp
changes and value shape.sender.id is the Instagram-scoped sender id (IGSID).Pass it back as the
recipient.id when you reply.
Comment events
Comments on your posts arrive at the same webhook URL withfield set to comments (or live_comments during a live video).Meta currently delivers comment events in two body shapes. Handle both. Shape 1:
changes array (Meta’s self-comment example):
field and value on the entry (Meta’s ordinary-comment example):
from.id, parent_id, and fields that only appear on your own comments as optional.Some deliveries omit
from.id entirely, and parent_id is only present on replies.Comments you post yourself also arrive as events. Check
from.username against your own handle if you want to skip your own replies.
Mentions of your account arrive inside these same comments events. There is no separate mentions payload to wait for.Channels are also subscribed to the
mentions, story_insights, and message_edit fields (reconnect a channel connected before this to pick the subscription up).
To act on a comment event, see Comments.
Other message events
Beyond plain text, themessaging array carries these events. All arrive at the same webhook URL.
Post shares used to arrive with
type: "share". Meta replaced it with ig_post, which adds the media id and title.If your receiver matches on
share, switch it to ig_post.
A story reply example (one item from entry[].messaging[], not a complete webhook body):
Verification GET
When you set a deployed webhook URL, HookMyApp checks that your receiver can answer a verification request.Respond with
VERIFY_TOKEN and HTTP 200.Local listen commands skip this check because they send DMs to your computer only while the command runs.
Signature verification
Every message delivery POST arrives withX-HookMyApp-Signature-256: sha256=<hex>.Compute HMAC-SHA256 over the raw request body using
WEBHOOK_HMAC_SECRET as the key.This is the HMAC signing secret from
hookmyapp channels env or hookmyapp sandbox env.It is not the
VERIFY_TOKEN.The
VERIFY_TOKEN is only echoed back on the ownership GET probe.Compare the computed value against the hex digest in the header. One POST is never signed: when you run
webhook set, HookMyApp sends an empty-body verification probe marked X-HookMyApp-Probe: webhook-verification (User-Agent HookMyApp-Webhook-Verifier).Answer it with any 2xx before checking signatures, or verification fails. For more detail, see Meta webhook docs.
Acknowledge fast
Three ways to receive DMs
- Listen in the sandbox:
hookmyapp sandbox listen --path /webhook/instagramtells HookMyApp to send test Instagram DMs to your local receiver.
Use this with the HookMyApp test Instagram account.
Keep the CLI running while you test. - Listen to your own account locally:
hookmyapp channels listen <channel> --path /webhook/instagramtells HookMyApp to send DMs from your connected Instagram account to your local receiver.
Use this to test with your real Instagram account before you deploy.
Stop the CLI when you are done. - Your own account, your own URL:
hookmyapp channels webhook set <channel> --url <your-public-https-url>sends DMs to your deployed receiver.
Use this after your receiver is live.
Next steps
- Webhook routing: Choose where incoming Instagram DMs are delivered.
- Event subscriptions: Send DMs and comments to extra URLs, next to this webhook.
- Instagram quickstart: Skip the boilerplate and clone the reference receiver.