REST hooks
REST hooks subscribe a URL to one event from code, and CommentGate sends every matching event to it within seconds until you unsubscribe. The Zapier and Make apps use exactly this. Deliveries are signed, retried and deduplicated like webhooks.
Updated September 26, 2026
Subscribe
POST/api/v1/hooks
Subscribes a URL to one event. Every matching event is sent to it within seconds, until you unsubscribe. Subscribe once per event you want. See the event catalogue for every body.
Who can call it: Any API key.
Body
- target_url string · up to 2,000 characters· required
- A public
httpsURL, with no user name or password and no private or local address. - event enum· required
- The event to send.
One of:
comment.received,comment.hidden,comment.review,comment.needs_reply,message.received,lead.captured,contact.updated - integration enum · default api
- Names the hook in Settings:
zapier,makeorapi.One of:
zapier,make,api
Example
curl -X POST https://commentgate.com/api/v1/hooks \
-H "Authorization: Bearer $COMMENTGATE_API_KEY" \
-H "content-type: application/json" \
-d '{"target_url":"https://hooks.zapier.com/hooks/standard/123/abc","event":"comment.hidden","integration":"zapier"}' 201 Created. Created, with the signing secret. It is shown only here.
{
"data": {
"id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
"event": "comment.hidden",
"target_url": "https://hooks.zapier.com/hooks/standard/123/abc",
"integration": "zapier",
"enabled": true,
"created_at": "2026-09-23T11:59:01.525Z",
"last_delivered_at": null,
"last_error": null,
"signing_secret": "whsec_EXAMPLE0000000000000000000000"
}
} 200 OK. The same target_url already listens to the same event: the existing hook, without the secret.
{
"data": {
"id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
"event": "comment.hidden",
"target_url": "https://hooks.zapier.com/hooks/standard/123/abc",
"integration": "zapier",
"enabled": true,
"created_at": "2026-09-23T11:59:01.525Z",
"last_delivered_at": null,
"last_error": null
}
} Errors
| HTTP | Code | When |
|---|---|---|
| 400 | invalid_request | A bad URL or an unknown event |
| 401 | unauthorized | Missing, unknown or revoked key |
| 403 | forbidden | The key's creator can no longer moderate, or is limited to some accounts |
| 422 | unprocessable | The workspace already holds 100 hooks |
List hooks
GET/api/v1/hooks
Every hook an integration created in the workspace, newest first. last_delivered_at and last_error show how the latest delivery went. Webhooks people added in Settings are not listed.
Who can call it: Any API key.
Example
curl https://commentgate.com/api/v1/hooks \
-H "Authorization: Bearer $COMMENTGATE_API_KEY" 200 OK. The hooks.
{
"data": [
{
"id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
"event": "comment.hidden",
"target_url": "https://hooks.zapier.com/hooks/standard/123/abc",
"integration": "zapier",
"enabled": true,
"created_at": "2026-09-23T11:59:01.525Z",
"last_delivered_at": null,
"last_error": null
}
]
} Errors
| HTTP | Code | When |
|---|---|---|
| 401 | unauthorized | Missing, unknown or revoked key |
Also as commentgate hooks list.
Unsubscribe
DELETE/api/v1/hooks/:id
Stops deliveries at once. The API cannot remove a webhook someone added in Settings.
Who can call it: Any API key.
Path parameters
- id string· required
- The hook id.
Example
curl -X DELETE https://commentgate.com/api/v1/hooks/8f1bee66-640e-4cbd-bc3f-f58ba092a457 \
-H "Authorization: Bearer $COMMENTGATE_API_KEY" 200 OK. Removed.
{
"data": {
"id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
"deleted": true
}
} Errors
| HTTP | Code | When |
|---|---|---|
| 401 | unauthorized | Missing, unknown or revoked key |
| 404 | not_found | No hook with that id in this workspace |
Also as commentgate hooks delete.
Sample deliveries
GET/api/v1/hooks/samples/:event
Up to three recent deliveries for that event, built from the workspace's own comments and messages in exactly the delivery shape, or one made-up example when there are none yet. Zapier uses it to show sample data while a Zap is being built; it is handy for testing a receiver too.
Who can call it: Any API key.
Path parameters
- event string· required
- A hook event, such as
comment.hidden.
Example
curl https://commentgate.com/api/v1/hooks/samples/comment.hidden \
-H "Authorization: Bearer $COMMENTGATE_API_KEY" 200 OK. An array of delivery bodies. See the event catalogue for each shape.
Errors
| HTTP | Code | When |
|---|---|---|
| 401 | unauthorized | Missing, unknown or revoked key |
| 404 | not_found | Not a hook event |
Deliveries
Each delivery is a signed POST with the body shown for its event in the event catalogue, with event set to the event the hook subscribed to. Verify it as described under verifying signatures, using the signing_secret from the subscribe response.
Hooks also appear in Settings, then Alerts, where people can pause or remove them. Revoking an API key removes every hook it created.
Campaign step deliveries
A campaign step "Send to Zapier or a webhook" sends the person to one of these hooks (or a webhook from Settings). Its body is in the event catalogue.
In the help center
- Get alerts in Slack, Discord or email
Choose where CommentGate tells you about comments that need you, a sudden rush of harmful comments, new leads and more, and exactly which events each place hears about.
- Connect Zapier and Make
Start a Zap or a Make scenario when a comment arrives, is hidden, needs you or turns into a lead, and hide, reply or record a sale from any other app.
- Every step, and where it works
What each campaign step does, and which of Facebook, Instagram, TikTok, YouTube, Threads and WhatsApp allow it, with the reason when one does not.