Data flow
Incoming messages
- ThreadsA customer comments on your account's post or mentions your account.
- Meta webhookMeta sends a notification to
/webhooks/threads(fieldsrepliesandmentions). TheX-Hub-Signature-256signature is verified; notifications without a valid signature are rejected. - Account routingComments are matched to the account that owns the post; mentions to the account that was mentioned. One webhook serves all workspaces.
- StorageEach message is stored only once (the same message from the webhook and from sync isn't duplicated). Customer replies to your replies go into the same conversation; Solved/Closed conversations are reopened.
- InteractionThe conversation list in the browser refreshes every 5 seconds; the open conversation every 4 seconds.
Backup sync
If the webhook isn't active yet (before App Review) or something was missed, every 5 minutes the server fetches comments from the last 10 posts and the latest mentions of each active account. For accounts that recently received a webhook, only mentions are checked. The Sync button in Threads channels does the same for a single account.
Outgoing messages (replies)
- SendAttachments are stored on the server under random names (Meta downloads them from a public URL). A reply always goes to the latest incoming message in the conversation.
- ContainerThe server creates a media container on Threads. Status: Processing.
- Status checkThe browser checks every 3 seconds; if the browser is closed, a cron job that runs every minute takes over. Videos take longer to process.
- PublishedThe container is published: Sent + a link to Threads. The first response time and first responder are recorded; the conversation becomes Replied.
- FailedIf Threads rejects the reply (e.g. the account isn't allowed to reply), the status becomes Failed with the reason. Replies not confirmed within 10 minutes are also marked failed, with a suggestion to check Threads first.
Account tokens
Access tokens are valid for 60 days and are renewed automatically (checked daily) once fewer than 7 days remain. If Meta rejects a token (e.g. permissions were revoked), the account's status becomes Token expired, the Owner is notified in the app and by email, and the account needs to be reconnected. Tokens are stored encrypted.
Deletion
Conversations and tickets are kept while the workspace is active, until the Owner deletes them or a data deletion request is made. Webhook logs are kept for 30 days. Disconnecting an account deletes its token; the conversation history is kept.