Skip to main content
GET
Meta's URL verification (hub.challenge) on the public webhook URL

Headers

Idempotency-Key
string

Optional. If a submission already exists for this tenant with the same key, the request short-circuits with 200 before the monthly quota is charged, so retries are free.

Path Parameters

workspace
string
required

Workspace (tenant) slug. Must not be one of the reserved roots reserved for app internals (api, admin, stripe, v1, assets, settings, favicon.ico, robots.txt, sitemap.xml, index.html, app.js, styles.css, export.js, portal, brand, trial-info, .well-known, mcp) — those never reach the ingest handler.

project
string
required

Project slug within the workspace.

webhook
string
required

Webhook slug. This high-entropy slug IS the credential — no key, token or cookie is sent. A disabled webhook answers 503 rather than 404.

Query Parameters

hub.mode
string
required
Allowed value: "subscribe"
hub.challenge
string
required
Maximum string length: 2048
hub.verify_token
string
required

Response

The challenge, verbatim.

The response is of type string.