Changelog
What changed in the API, webhooks, MCP server and command line, newest first.
Updated September 26, 2026
Webhook signatures cover the timestamp
- Every webhook and REST hook delivery now carries
x-commentgate-signature-v2: v2=<hex>, the HMAC-SHA256 of<timestamp>.<raw body>withx-commentgate-timestampas the timestamp. Because the timestamp is signed, a captured delivery cannot be replayed later with a new one. - Verify
x-commentgate-signature-v2and reject any delivery whose timestamp is more than 5 minutes old. The Node.js, Express and Python samples do both. - Deprecated:
x-commentgate-signature(sha256=over the body alone) is still sent for one release so existing receivers keep working. It is removed in the next release.
Settings that cover every account
- A key whose creator is limited to some accounts now gets
forbiddenfrom guidance, protections and subscribing a hook, because each of those covers every account. Reading still works, within the creator's accounts.
Webhook comment status matches the API
- Webhook and REST hook bodies now name a comment that was left up
visibleincomment.status, the same as the REST API. Before, they saidallowed. - Deprecated:
comment.legacy_statusstill carries the old name (allowed,hidden,deleted,revieworpending) for one release so existing integrations keep working. Switch tocomment.status;legacy_statusis removed in the next release.
Developer docs
- The developer docs moved to one page per topic. The endpoint, field, event, MCP tool and CLI references are now generated from the code, so they always match what runs. Old
/developers#sectionlinks still lead to the right page. - The event catalogue lists every webhook event with an example body, including
ad.healthandinsights.weekly.
API v1, webhooks, MCP server and command line
- REST API v1: comments and actions, the autopilot, contacts and tags, reports, sales from tracked links, REST hooks and key checks, for Facebook, Instagram, TikTok, YouTube and Threads.
- Signed webhooks with retries, from Settings or from code.
- The hosted MCP server at
https://commentgate.com/mcp, with OAuth sign-in for Claude, ChatGPT and Cursor. - The command line tool:
npm install -g commentgate. - The Zapier and Make apps, built on REST hooks.