Overview
Facebook Webhooks is a webhook callback from Meta used for webhook delivery, payment notifications, service callbacks, and server-to-server integration events.
Its primary user-agent pattern is facebook-webhooks; related patterns include Facebook Webhooks.
Facebook Webhooks is Unverified at the identity-evidence level. The listed identity remains useful for detection, but this record does not currently contain authoritative evidence sufficient to authenticate the identity claim.
Facebook Webhooks is marked as respecting robots.txt directives for crawler access control.
Facebook Webhooks can usually be allowed after confirming the source and monitoring request volume.
Identity
- User-Agent Pattern
-
facebook-webhooks - Aliases
- Facebook Webhooks
- HTTP Agent Examples
-
facebook-webhooks - Robots Token
- facebook-webhooks
- Identity Type
- Observed
- Evidence Method
- Treat `facebook-webhooks` as an identity signal only. Confirm it with current operator documentation, cryptographic verification, forward-confirmed reverse DNS, source-network ownership, or other authoritative evidence before trusting the claimed identity.
Classification
- Type
- Webhook
- Kind
- Webhook
- Family
- Meta
- Operator
- Meta
- Company
- Meta
- Purpose
- Webhook
Behavior and handling
- Common Use
- Facebook Webhooks is used for webhook delivery, payment notifications, service callbacks, and server-to-server integration events.
- Detection Notes
- Facebook Webhooks traffic is primarily detected by the `facebook-webhooks` user-agent pattern; related patterns include `Facebook Webhooks`. Compare source IPs, reverse DNS, request paths, and crawl cadence with Meta infrastructure before trusting the traffic.
- Respects robots.txt
- Yes
- Spoofing Risk
- Facebook Webhooks has medium spoofing risk because the user-agent can be copied, even when the bot has strong source or documentation support.
- Risk
- Safe
- Recommended Handling
- Depends
Rules and controls
- Robots.txt Snippet
-
User-agent: facebook-webhooks Disallow: /