Integration layer for Homa CRM
Connect Homa CRM to your Meta business channels
Securely connect authorized Instagram, Facebook, Messenger and WhatsApp business assets to Homa CRM through one centralized integration layer.
- OAuth-based authorization
- No Meta passwords collected
- Encrypted token storage
- Revoke access at any time
Meta business channels
- Instagram professional
- Instagram messaging
- Facebook Pages
- Messenger
- WhatsApp Business
Homa Meta Platform
- OAuth authorization
- Token vault
- Webhook receiver
- Tenant isolation
Homa CRM modules
- Unified inbox
- Contacts
- Automation
- Reporting
Supported integrations
One authorization layer for your Meta business assets
Homa Meta Platform connects the business channels your team already operates. Each integration is scoped to the assets you explicitly authorize.
Instagram Professional Accounts
Link Instagram professional accounts that are connected to a business asset so Homa CRM can reference the correct profile context.
Requires a professional (business or creator) Instagram account.
Instagram Messaging
Route authorized Instagram direct messages into Homa CRM so conversations stay attached to the right customer record.
Requires messaging permissions and an approved messaging use case.
Instagram Content and Comments
Read and respond to comments on authorized media, and reference published content alongside customer activity.
Requires content and comment permissions granted for the linked account.
Facebook Pages
Connect the Facebook Pages you administer and keep Page-level context available inside Homa CRM.
Requires sufficient administrative access on the Page.
Messenger
Bring authorized Page conversations into the Homa CRM inbox with the same handling as other channels.
Requires Page messaging permissions and an approved use case.
WhatsApp Business Platform
Connect authorized WhatsApp Business accounts and eligible phone numbers for business messaging workflows.
Requires a WhatsApp Business account, an eligible phone number and platform approval.
Meta Webhooks
Receive event notifications on a verified HTTPS endpoint with signature verification and idempotent processing.
Requires webhook subscription configuration in the Meta app.
Business Asset Management
Review which business assets are connected, when they were authorized, and disconnect any of them from Homa CRM.
Visibility is limited to the assets you authorize.
How it works
Four steps from sign-in to a connected channel
The authorization flow always begins in Homa CRM and completes on Meta. Homa never sees your Meta credentials at any point.
- 01
Sign in to Homa CRM
Start from your existing Homa CRM workspace. Your Homa account determines which tenant the integration belongs to.
- 02
Start a secure Meta authorization flow
Homa redirects you to Meta’s official authorization screen. You enter your credentials with Meta, never with Homa.
- 03
Select authorized business assets
On Meta’s screen you choose which Pages, Instagram accounts or WhatsApp Business assets to grant access to.
- 04
Manage connected channels inside Homa
Return to Homa CRM to see connected assets, review granted permissions and disconnect anything you no longer need.
Security and control
Designed so you keep control of every authorization
The controls below describe how the platform is designed and, where noted, how it is implemented today. They are not claims of any third-party certification.
OAuth-based authorization
All access originates from Meta’s official authorization mechanisms rather than credential sharing.
No collection of Meta passwords
Homa does not request, receive, transmit or store your Meta account password at any stage.
Encrypted token storage
Access tokens are intended to be held server-side and encrypted at rest, never exposed to browser code.
Least-privilege permissions
The platform is designed to request only the permissions needed for the features you enable.
Tenant-level isolation
Connected assets and tokens are scoped to the Homa tenant that authorized them.
Access revocation
You can disconnect an integration from Homa CRM, and separately revoke it from your Meta account settings.
Audit logging
Authorization and disconnection events are recorded so integration changes can be reviewed.
Data deletion requests
A public deletion request path is available to every user, independent of the Homa CRM interface.
Webhook signature verification
Incoming webhook payloads are verified before processing, and unsigned data is not trusted.
Secure secret management
Application secrets are kept in server-side configuration and are never bundled into client code.
Use cases
What teams do with a connected channel
These are the workflows the integration is built to support once the relevant permissions have been granted.
Unified social inbox
Handle messages from multiple authorized channels in one place.
Customer support
Resolve support conversations without leaving the CRM record.
Lead management
Turn inbound conversations into qualified records and follow-up tasks.
Comment management
Review and reply to comments on authorized media from one queue.
Social engagement
Track engagement on connected accounts alongside customer history.
Message automation
Apply routing and templated responses within platform policy limits.
WhatsApp customer communication
Run approved business messaging on authorized phone numbers.
CRM contact synchronization
Attach channel identities to the matching Homa CRM contact.
Activity history
Keep a chronological record of channel interactions per contact.
Reporting
Report on volume and response performance across connected channels.
For developers
Integration reference for engineering teams
The developer portal documents the authorization flow, webhook handling and token lifecycle, and marks clearly which parts depend on Meta review.
OAuth flow
Authorization request, redirect URI, state parameter and code exchange.
/docs/oauthWebhooks
Verification challenge, signature checks, deduplication and retries.
/docs/webhooksAccess tokens
Storage, encryption at rest, rotation, expiration and revocation.
/docs/tokensPermission scopes
Least privilege, standard versus advanced access and App Review.
/docs/permissionsAPI integration
Architecture overview, environment separation and configuration.
/docs/getting-startedError handling
Cancelled authorizations, invalid state, rate limits and outages.
/docs/errorsToken revocation
How revocation is triggered and what the platform does in response.
/docs/tokensData deletion
Request lifecycle, confirmation references and retention exceptions.
/docs/data-deletion
Frequently asked questions
Answers before you authorize
A short selection of the questions we are asked most often about permissions, data and deletion.
Connect your business communication channels to Homa
Start the authorization flow when your business assets are ready, or reach out if you need help confirming eligibility first.