← All workCase 06 / 07
Live at hooklink.appInstagram automation

Automation thatplays by the rules.

A Meta-verified Instagram automation platform: comments, DMs, story replies and live comments trigger instant replies — at scale, inside every one of Meta's limits.

Product
Hooklink hooklink.app↗
Client
Creator tools · India
Role
Full-stack engineer
Surfaces
Web app · Meta API
The brief

Creators and businesses lose leads in their comments. Instagram automation fixes that — but only if it stays within Meta's rate limits and messaging windows, or accounts get restricted.

So the core of the product isn't the builder UI. It's an engine that takes in webhooks, schedules work fairly across thousands of accounts, and refuses to send anything Meta would object to.

01

Creator dashboard

Automation builder, analytics, leads, run logs, link-in-bio page and billing.

02

Automation engine

A queue-driven worker that ingests webhooks and executes replies within platform limits.

03

Admin panel

Users, automations, billing, payouts, tickets, queue monitor and audit log.

04

Mobile API

Sign-in, token refresh and App Store billing for the iOS app.

System map

How it fitstogether.

Every surface talks to one platform core. This is the shape of the system as it runs in production.
Creator dashboardiOS appAdmin panelPublic link pagesPlatform coreNext.js API+ workerWebhook intakeFair schedulerRate limiterCompliance guardsRun ledgerMeta Graph APIRedis queuesRazorpayApp Store billingEmail
The hard parts

What made ithard — and how.

The problems that don't show up in a screenshot, but decide whether a product survives real users.
01

Webhooks that never time out

The problem

Meta expects an instant response to every webhook — and retries or disables endpoints that are slow.

The approach

Each webhook is signature-checked in constant time, de-duplicated, stored and queued before responding. All real work happens later in the worker.

HMAC verificationDedupQueues
02

Rate limits, per account, by design

The problem

Every Instagram account has its own call budget. Exceed it and the account is throttled.

The approach

Each account gets an atomic token bucket in Redis, deliberately set below Meta's ceiling and counted in API calls rather than messages.

Token bucketRedis Lua
03

Fairness when one post goes viral

The problem

A single viral post can generate thousands of events and starve every other customer.

The approach

A custom scheduler claims accounts one at a time with priority tiers, so rewards and paid users go first and no account can monopolise the workers. A load test verifies fairness, limits and idempotency.

SchedulingPriority tiersLoad testing
04

Compliance checked at send time

The problem

Messaging windows and one-reply-per-comment rules can expire between queueing a job and running it.

The approach

Guards run at execution, not enqueue: the 24-hour window, the private-reply window, one reply per comment and one response per user per post — backed by unique database keys.

Policy guardsIdempotency
05

Failures that heal themselves

The problem

Tokens expire, networks blip and permissions get revoked.

The approach

Errors are classified as transient, permanent or auth. Transient ones back off and retry, auth failures prompt a reconnect, tokens refresh automatically before expiry and are stored encrypted.

Error taxonomyEncryption at rest
Inside the system

Everythingit does.

01Comment, DM, story-reply, live-comment and shared-post triggers
02Keyword matching and post targeting
03Buttons, media, follow-ups and reply variants
04Lead capture and follower-gated rewards
05Run and job ledger with readable errors
06Analytics with CSV export
07Link-in-bio pages with their own analytics
08Referral programme and support desk
Built with
Built with
01

Product

Next.js · React · TypeScript · Tailwind · Framer Motion

02

Engine

BullMQ · Redis · Lua · Prisma · MySQL

03

Platform

Meta Graph API · NextAuth · Razorpay · App Store Server API

04

Ops

PM2 · CI/CD · PWA

Building something like this?

Let’s scope yours.