Getting started
Webhooks
Instead of polling, register an endpoint (see Webhook endpoints) and Creator OS POSTs each event to it as it happens: a post publishing or failing, a new comment, a new DM, an account connecting. Respond with any 2xx within 4 seconds and do heavy work asynchronously. Use the event id to skip duplicates.
Failed deliveries aren’t retried automatically. Every attempt is kept for 30 days: see them with List deliveries and send any of them again with Resend a delivery.
{
"id": "evt_Gk7Qp2Vz9Ny4Tx1Lm6Rc3Wb8Js5Df0Ga7Ue2Ki4Oq9X",
"type": "comment.received",
"created": 1727290000,
"data": {
"comment": {
"id": "cmt_Lr5Tz8Qk2Wx7Ny4Bv1Hm9Jc6Pd3Fs0Ga8Ue5Ki2Oq7X",
"postId": "post_3JSJJWvgHKZH-Vjy_ggeP792GJbvjQ1pZzbqlPEgKJOO",
"platformPostId": "18053924711234567",
"platform": "instagram",
"text": "GUIDE please!",
"author": {
"username": "maya.fit",
"name": "Maya"
},
"createdAt": "2026-09-25T19:03:10.000Z",
"isReply": false,
"parentCommentId": null
},
"post": {
"id": "post_3JSJJWvgHKZH-Vjy_ggeP792GJbvjQ1pZzbqlPEgKJOO",
"platformPostId": "18053924711234567",
"content": "Three hooks that doubled my watch time 👇",
"permalink": "https://www.instagram.com/reel/C9xYz/"
},
"account": {
"id": "acc_uwsum2TkX6QB7M2BWX_F2kYykNTaWuC3V2Spge_Xm4r",
"accountId": "acc_uwsum2TkX6QB7M2BWX_F2kYykNTaWuC3V2Spge_Xm4r",
"platform": "instagram",
"username": "kevbuildsapps"
}
}
}Verify every delivery. The X-CreatorOS-Signature header holds a timestamp and an HMAC-SHA256 of <timestamp>.<raw body>, keyed by the endpoint secret you got when creating it. Compute it over the raw bytes before parsing JSON, compare in constant time, and reject timestamps older than five minutes.
The X-CreatorOS-Event header carries the event type too, so you can route before parsing.
# Signature header on every delivery:
# X-CreatorOS-Signature: t=1727290000,v1=5f2b...e91a
# v1 = hex HMAC-SHA256 of "<t>.<raw request body>" keyed by your endpoint secret.
# Reject if it doesn't match or t is more than 5 minutes old.