Integrations — every platform Mochu connects to

    Mochu is built native on Meta (Facebook + Instagram), with first-class LinkedIn, Google Business and X support. Every connection is OAuth-only — we never see your password — and every access token is encrypted at rest.

    Live integrations

    Facebook Pages
    Native, primary

    Comments under organic posts AND under paid (boosted + dark) ad creatives. Page Inbox API. Auto-reply, hide, delete, like, block. Messenger DMs in the same inbox.

    OAuth scopes: pages_show_list, pages_read_engagement, pages_manage_posts, pages_manage_engagement, pages_read_user_content, pages_messaging
    Instagram Business
    Native, primary

    Comments under posts, Reels and ads (boosted + organic). DMs via the Instagram Graph API. Story replies, mentions. Full moderation toolkit.

    OAuth scopes: instagram_basic, instagram_manage_comments, instagram_manage_insights, instagram_manage_messages
    TikTok Business · coming soon
    Coming soon

    Coming soon — comment moderation under TikTok Ads and organic videos, plus ad performance sync.

    OAuth scopes: video.list, comment.list.manage, video.upload
    LinkedIn Company Pages
    Beta

    Comments under organic company posts and sponsored content. Limited to engagement-only — no DMs (LinkedIn doesn't expose those to third parties).

    OAuth scopes: r_organization_social, rw_organization_admin
    Google Business Profile
    Beta

    Customer reviews and Q&A on Maps listings. Auto-reply via Mochu. Multi-location supported for chains.

    OAuth scopes: business.manage
    X (Twitter)
    Limited (read)

    Mentions monitoring. Auto-reply is rate-limited by X's tiers; we recommend X for sentiment monitoring rather than auto-engagement.

    OAuth scopes: tweet.read, users.read
    Resend
    Outbound email

    Weekly digest emails ('your week with Mochu') sent from hello@mochu.io. Customers can opt out per organisation.

    OAuth scopes: smtp

    Security & compliance

    • OAuth-only authentication. Mochu never sees your account password. We store the access token Meta/etc. issue us, and we encrypt every token at rest in a Supabase Vault.
    • Tokens auto-rotate. Long-lived Page tokens are exchanged for short-lived per-request tokens server-side. If a user revokes Mochu's access, we delete their tokens immediately.
    • Webhook signature verification. Every Meta webhook delivery is verified via X-Mochu-Signature-256 HMAC; unsigned requests are rejected with HTTP 401.
    • Rate-limit aware. Per-page rate limiter in Postgres keeps Mochu safely under Meta's quota. No customer has ever been temp-blocked because of Mochu.
    • GDPR + DPA. Mochu is GDPR-compliant; a Data Processing Agreement is available on request. Users can disconnect any account and request data deletion with one click.

    Coming soon

    • WhatsApp Business API — Q3 2026 — comments + DMs from WhatsApp Business catalog ads
    • Pinterest — Q4 2026 — Pin comments + Idea Pin replies
    • YouTube Shorts — Q4 2026 — comment moderation under monetised channels
    • HubSpot CRM sync — Q3 2026 — push recovered leads to HubSpot deals
    • Slack alerts — Q3 2026 — real-time lead notifications in a Slack channel
    • Zapier — On request — Zapier app for custom workflows

    Need a custom integration?

    The Agency plan (€119/month or 499 PLN) includes custom integrations via API and webhooks. Common requests we've built: lead push to HubSpot/Pipedrive, Slack alerts for high-value leads, Google Sheets export, customer-specific CRM webhooks. Write to hello@mochu.io with your use case.

    Używamy plików cookie do analityki, aby ulepszać Mochu. Możesz zaakceptować wszystkie lub zostawić tylko niezbędne. Szczegóły w Polityce prywatności.