Accounts
account_updated
Sent when the
status of one of the team's accounts changes (for example, when its authorization expires or is renewed).Other changes to the account do not send this event.
relationships.object.data identifies the account, and included contains the account.
The payload below is the default JSON:API document. The webhook's payload_include, payload_fields and payload_transformation_template change it, and its filter decides whether the event is sent at all.
Request
We send the event to your webhook's url with POST (or the webhook's http_method) and a JSON:API document as the body (Content-Type: application/vnd.api+json). See Receiving Webhooks for retries and Webhook Event Signatures to verify the request.
Headers
| Header | Description |
|---|---|
X-TINT-Signature | timestamp,signature, where timestamp is the Unix time (in seconds) at which the delivery was signed and signature is the Base64-encoded HMAC-SHA256 of timestamp.body, keyed with the webhook's signing secret. Only sent when the webhook has a signing secret. Every attempt is signed again, so retries carry a new timestamp. See Webhook Event Signatures. |
API-Version | The API version the payload was serialized with, unless the webhook overrides this header. |
User-Agent | Always TINT Webhook/2.0, unless the webhook overrides this header. |
Payload
| Field | Type | Description |
|---|---|---|
data | object | |
data.id | string | The event ID. It stays the same on every retry of this event, so use it to detect duplicate deliveries. It is also the ID to use with Retrieve a webhook event. |
data.type | string | Always event. One of event. |
data.attributes | object | |
data.attributes.name | string | The event name. One of account_updated. |
data.attributes.created_at | string (date-time) | When the event happened (the event was recorded), not when this delivery was sent. Retries keep the original value. |
data.relationships | object | |
data.relationships.object | object | The account this event is about. |
data.relationships.object.data | object | |
data.relationships.object.data.type | string | One of account. |
data.relationships.object.data.id | string | |
data.relationships.team | object | The team the webhook belongs to. |
data.relationships.team.data | object | |
data.relationships.team.data.type | string | One of team. |
data.relationships.team.data.id | string |
Included resources
The sideloaded resources: the account.
account
| Field | Type | Description |
|---|---|---|
id | string | The unique identifier of the account. |
type | string | The resource type. One of account. |
attributes | object | |
attributes.type (optional) | string | The type of account, i.e. the external service it connects to. |
attributes.external_id (optional) | string | The ID of this account at the source. For credential-based accounts this is derived from the credentials (for example the host of the site, or an MD5 digest of the API key). |
attributes.status (optional) | string | ok when the stored credentials are valid, expired when they need to be reauthorized, and pending while the account is being set up. One of ok, expired, pending. |
attributes.name (optional) | string or null | The display name of the account at the source. |
attributes.username (optional) | string or null | The username or handle of the account at the source, when it has one. |
attributes.image_url (optional) | string or null (uri) | The URL of the account's profile picture, when available. |
attributes.site (optional) | string or null | The store URL, server URL or AWS region the account is tied to (e.g. for shopify, magento, woocommerce, ftp, http, sftp, and s3). null for other account types. |
attributes.expires_at (optional) | string or null (date-time) | The time when the stored credentials are known to expire, or null if they don't expire. |
attributes.capabilities (optional) | array of string | What the account can be used for. Determined by the account type. |
attributes.meta (optional) | object | Additional, source-specific information about the account (for example profile statistics). Empty for most account types. |
attributes.followers_count (optional) | integer or null | The number of followers of the account at the source, when known. |
attributes.follows_count (optional) | integer or null | The number of accounts this account follows at the source, when known. |
attributes.media_count (optional) | integer or null | The number of media items published by the account at the source, when known. |
attributes.likes_count (optional) | integer or null | The number of likes received by the account at the source, when known. |
attributes.created_at (optional) | string (date-time) | The time when the account was connected. |
attributes.updated_at (optional) | string (date-time) | The time when the account was last updated. |
relationships (optional) | object | |
relationships.social_feeds (optional) | object | The social feeds using this account. Only included when the access token has the social_feeds:read scope. data is only present when social_feeds is included (include=social_feeds) and only lists the social feeds of boards the user can access. |
relationships.social_feeds.data (optional) | array of object | |
relationships.social_feeds.meta (optional) | object | |
relationships.subaccounts (optional) | object | The pages, organizations, channels, etc. that can be accessed with this account. data is only present when subaccounts is included (include=subaccounts); otherwise meta.included is false. |
relationships.subaccounts.data (optional) | array of object | |
relationships.subaccounts.meta (optional) | object |
Example
{
"data": {
"id": "1377452",
"type": "event",
"attributes": {
"created_at": "2025-03-14T16:42:07.000Z",
"name": "account_updated"
},
"relationships": {
"object": {
"data": {
"type": "account",
"id": "310"
}
},
"team": {
"data": {
"type": "team",
"id": "1"
}
}
}
},
"included": [
{
"id": "310",
"type": "account",
"attributes": {
"external_id": "17841400000000000",
"created_at": "2025-03-14T16:42:07.000Z",
"updated_at": "2025-03-14T16:42:07.000Z",
"status": "ok",
"name": "Acme Outdoors",
"username": "acmeoutdoors",
"expires_at": "2025-05-13T16:42:07.000Z",
"image_url": "https://cdn.example.com/accounts/310/avatar.jpg",
"capabilities": [
"ingest",
"compose"
],
"meta": {},
"likes_count": null,
"media_count": 214,
"followers_count": 5210,
"follows_count": 180,
"site": null,
"type": "instagram_business"
},
"relationships": {
"subaccounts": {
"meta": {
"included": false
}
}
}
}
]
}Responses
| Status | Description |
|---|---|
404 | 404 Not Found or 410 Gone stops delivery of this event immediately: it is marked failure and not retried. The attempt still counts toward the webhook's failure limit. |
410 | 404 Not Found or 410 Gone stops delivery of this event immediately: it is marked failure and not retried. The attempt still counts toward the webhook's failure limit. |
2XX | Any status below 400 (typically 2XX) acknowledges the event: we mark it success and don't send it again. The response body is ignored (we store it with the attempt, for your reference). Redirects are not followed, and a 3XX response also counts as acknowledged, so point the webhook at the final URL. |
| Other | Any other 4XX or 5XX status, a timeout or a connection error fails the attempt, and we retry up to 7 more times with an increasing delay (roughly 1 minute, 1 minute, 2 minutes, 13 minutes, 1 hour, 4 hours, then 13 hours later), after which the event is marked failure. More than 50 failed attempts for the same webhook within a week, without a successful delivery in between, set the webhook to inactive. |