Meta data-deletion callback
Public unauthenticated endpoint Meta calls when a Facebook user revokes the Devotel Orbit app. Verifies the HMAC-SHA256 of the signed_request against the Meta app secret, persists a durable deletion-request audit row, queues the async tenant-data erasure out of band, and replies synchronously with the confirmation URL + code Meta shows the requester. Configure this URL as the Data Deletion Callback in the Meta app dashboard.
Authorizations
Dashboard JWT token from Clerk
Headers
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
1 - 255Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.
true, false Body
Meta signed_request: base64url(HMAC-SHA256(signature)) + '.' + base64url(JSON payload)
20 - 8192Response
Deletion request accepted — returns the confirmation URL and code.
Deletion request accepted — returns the confirmation URL and code.