Skip to content
Developer docs REST hooks

REST hooks

REST hooks subscribe a URL to one event from code, and CommentGate sends every matching event to it within seconds until you unsubscribe. The Zapier and Make apps use exactly this. Deliveries are signed, retried and deduplicated like webhooks.

Updated September 26, 2026

Subscribe

POST/api/v1/hooks

Subscribes a URL to one event. Every matching event is sent to it within seconds, until you unsubscribe. Subscribe once per event you want. See the event catalogue for every body.

Who can call it: Any API key.

Body

target_url string · up to 2,000 characters· required
A public https URL, with no user name or password and no private or local address.
event enum· required
The event to send.

One of: comment.received, comment.hidden, comment.review, comment.needs_reply, message.received, lead.captured, contact.updated

integration enum · default api
Names the hook in Settings: zapier, make or api.

One of: zapier, make, api

Example

Request
curl -X POST https://commentgate.com/api/v1/hooks \
  -H "Authorization: Bearer $COMMENTGATE_API_KEY" \
  -H "content-type: application/json" \
  -d '{"target_url":"https://hooks.zapier.com/hooks/standard/123/abc","event":"comment.hidden","integration":"zapier"}'

201 Created. Created, with the signing secret. It is shown only here.

201 Created response
{
  "data": {
    "id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
    "event": "comment.hidden",
    "target_url": "https://hooks.zapier.com/hooks/standard/123/abc",
    "integration": "zapier",
    "enabled": true,
    "created_at": "2026-09-23T11:59:01.525Z",
    "last_delivered_at": null,
    "last_error": null,
    "signing_secret": "whsec_EXAMPLE0000000000000000000000"
  }
}

200 OK. The same target_url already listens to the same event: the existing hook, without the secret.

200 OK response
{
  "data": {
    "id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
    "event": "comment.hidden",
    "target_url": "https://hooks.zapier.com/hooks/standard/123/abc",
    "integration": "zapier",
    "enabled": true,
    "created_at": "2026-09-23T11:59:01.525Z",
    "last_delivered_at": null,
    "last_error": null
  }
}

Errors

HTTPCodeWhen
400invalid_requestA bad URL or an unknown event
401unauthorizedMissing, unknown or revoked key
403forbiddenThe key's creator can no longer moderate, or is limited to some accounts
422unprocessableThe workspace already holds 100 hooks

List hooks

GET/api/v1/hooks

Every hook an integration created in the workspace, newest first. last_delivered_at and last_error show how the latest delivery went. Webhooks people added in Settings are not listed.

Who can call it: Any API key.

Example

Request
curl https://commentgate.com/api/v1/hooks \
  -H "Authorization: Bearer $COMMENTGATE_API_KEY"

200 OK. The hooks.

200 OK response
{
  "data": [
    {
      "id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
      "event": "comment.hidden",
      "target_url": "https://hooks.zapier.com/hooks/standard/123/abc",
      "integration": "zapier",
      "enabled": true,
      "created_at": "2026-09-23T11:59:01.525Z",
      "last_delivered_at": null,
      "last_error": null
    }
  ]
}

Errors

HTTPCodeWhen
401unauthorizedMissing, unknown or revoked key

Also as commentgate hooks list.

Unsubscribe

DELETE/api/v1/hooks/:id

Stops deliveries at once. The API cannot remove a webhook someone added in Settings.

Who can call it: Any API key.

Path parameters

id string· required
The hook id.

Example

Request
curl -X DELETE https://commentgate.com/api/v1/hooks/8f1bee66-640e-4cbd-bc3f-f58ba092a457 \
  -H "Authorization: Bearer $COMMENTGATE_API_KEY"

200 OK. Removed.

200 OK response
{
  "data": {
    "id": "8f1bee66-640e-4cbd-bc3f-f58ba092a457",
    "deleted": true
  }
}

Errors

HTTPCodeWhen
401unauthorizedMissing, unknown or revoked key
404not_foundNo hook with that id in this workspace

Also as commentgate hooks delete.

Sample deliveries

GET/api/v1/hooks/samples/:event

Up to three recent deliveries for that event, built from the workspace's own comments and messages in exactly the delivery shape, or one made-up example when there are none yet. Zapier uses it to show sample data while a Zap is being built; it is handy for testing a receiver too.

Who can call it: Any API key.

Path parameters

event string· required
A hook event, such as comment.hidden.

Example

Request
curl https://commentgate.com/api/v1/hooks/samples/comment.hidden \
  -H "Authorization: Bearer $COMMENTGATE_API_KEY"

200 OK. An array of delivery bodies. See the event catalogue for each shape.

Errors

HTTPCodeWhen
401unauthorizedMissing, unknown or revoked key
404not_foundNot a hook event

Deliveries

Each delivery is a signed POST with the body shown for its event in the event catalogue, with event set to the event the hook subscribed to. Verify it as described under verifying signatures, using the signing_secret from the subscribe response.

Hooks also appear in Settings, then Alerts, where people can pause or remove them. Revoking an API key removes every hook it created.

Campaign step deliveries

A campaign step "Send to Zapier or a webhook" sends the person to one of these hooks (or a webhook from Settings). Its body is in the event catalogue.

In the help center

  • Get alerts in Slack, Discord or email

    Choose where CommentGate tells you about comments that need you, a sudden rush of harmful comments, new leads and more, and exactly which events each place hears about.

  • Connect Zapier and Make

    Start a Zap or a Make scenario when a comment arrives, is hidden, needs you or turns into a lead, and hide, reply or record a sale from any other app.

  • Every step, and where it works

    What each campaign step does, and which of Facebook, Instagram, TikTok, YouTube, Threads and WhatsApp allow it, with the reason when one does not.