Facebook Graph API: Access, Tokens, Posting, Review

By Mika ReyesPublished 8 min read

The short answer

The Facebook Graph API is Meta's HTTP API at graph.facebook.com for reading and writing Facebook data: publishing to Pages, reading comments, and pulling Page insights. To use it for other people's Pages, you create a Meta app, request Page permissions, pass Business Verification and App Review, then manage Page access tokens. Adeli owns that approved app, so you publish to Facebook with one API key.

The Facebook Graph API is Meta's HTTP API for getting data into and out of Facebook. Your app sends requests to graph.facebook.com with an access token to publish to Pages, manage comments, and read insights. To do that on your users' Pages, you first need a Meta app, Page permissions, and App Review approval for each permission.

What is the Facebook Graph API?#

The Facebook Graph API is the main programming interface to Facebook, and most people mean it when they search "Facebook API" or "fb API". Meta's Graph API overview calls it "the primary way to get data into and out of the Facebook platform."

It models Facebook as a graph of three things:

  • Nodes. Individual objects with an ID: a Page, a post, a photo, a comment.
  • Edges. Connections between nodes: a Page's /feed, a post's /comments.
  • Fields. Properties you ask for by name: ?fields=name,followers_count.

Every request goes to https://graph.facebook.com/v{version}/.... Meta ships a new version roughly every quarter, and an unversioned call falls back to the oldest version still available, so pin a version in every request.

"Meta Graph API" and "facebook.com Graph API" are the same API. The Instagram API with Facebook Login and the Marketing API both run on it.

What can you do with the Facebook Graph API?#

For a product that posts on its users' behalf, the Facebook Graph API covers Pages: publishing, comments, messages, and insights. It doesn't reach personal profiles.

Task Possible? Where it happens
Publish text, link, and photo posts to a Page Yes POST /{page-id}/feed, POST /{page-id}/photos
Publish video and Reels to a Page Yes The Video API
Schedule a Page post Yes, 10 minutes to 30 days ahead published=false plus scheduled_publish_time
Read and reply to comments on Page posts Yes /{post-id}/comments
Reply to Messenger conversations Yes, within the messaging window Messenger Platform
Read Page and post insights Yes, on Pages with 100+ likes /{object-id}/insights
Post to a personal profile No Not available through the API
Run ads Yes, through the Marketing API Separate permissions and access tiers

How do apps get access to the Facebook Graph API?#

Apps get access through a Meta app. What people search as the "Facebook app API" is this registration in the App Dashboard, which holds your app ID, app secret, permissions, and review status.

  1. Create a Meta app. Register as a Meta developer and create an app for a business use case.
  2. Add Facebook Login for Business. Your users connect their Pages through it and grant permissions on Meta's consent screen.
  3. Build and test with Standard Access. Meta grants Standard Access automatically, but it only works for people who hold a role on your app.
  4. Complete Business Verification. Meta requires it for Advanced Access, which is what lets people without a role on your app grant permissions.
  5. Pass App Review for each permission. Each permission needs its own written use case and screencast.
  6. Keep it compliant. Advanced Access also comes with an annual Data Use Checkup.

Standard Access only covers people on your app. Everything works on your own test Pages, so the integration looks done, and the first customer without a role on your app who tries to connect gets an error.

Which permissions does a Facebook Pages integration need?#

A Pages integration needs one permission per capability, and each one that needs Advanced Access goes through App Review on its own. Map every feature to its permission before you build:

Feature Permission
List the Pages a user manages, so they can pick one pages_show_list
Identify the Page and read its posts pages_read_engagement
Publish, edit, and delete Page posts pages_manage_posts
Read other people's comments on Page posts pages_read_user_content
Reply to, hide, and delete comments pages_manage_engagement
Subscribe to webhooks for the Page's feed and messages pages_manage_metadata
Reply in the Page's Messenger inbox pages_messaging
Read Page and post insights read_insights with pages_read_engagement
Find Pages owned through a Business portfolio business_management

The user also needs the right role on the Page. Meta's Pages posts docs say they must be able to perform "CREATE_CONTENT, MANAGE, and MODERATE tasks on the Page."

How do Facebook Graph API access tokens work?#

Page actions use a Page access token, which you get from the user's token after they log in. Store the wrong one and your integration stops working within hours, or in about two months. Meta's long-lived token docs set the lifetimes:

Token Lifetime Used for
Short-lived user token Hours What Facebook Login returns first
Long-lived user token About 60 days Exchanged server-side with your app secret
Page token from a long-lived user token No expiration date Publishing, comments, insights for that Page
App token Until you reset the app secret App-level calls and settings

The production flow:

  1. The user logs in with Facebook Login for Business and gets a short-lived user token.
  2. Your server exchanges it at GET /oauth/access_token with grant_type=fb_exchange_token.
  3. You call GET /me/accounts with the long-lived token and store each Page's token.

A Page token with no expiration date can still stop working. Meta says long-lived Page tokens can be "invalidated under certain conditions", such as the user revoking your app, changing their password, or losing their role on the Page. Your code has to catch the error, flag the connection, and ask the user to reconnect.

How do I publish a post to a Facebook Page with the Graph API?#

Send a POST to the Page's /feed edge with a Page access token. A text post with a link:

curl -X POST "https://graph.facebook.com/v26.0/$PAGE_ID/feed" \
  -d "message=We shipped it." \
  -d "link=https://example.com/changelog" \
  -d "access_token=$PAGE_TOKEN"

A scheduled post adds two parameters. Meta accepts a publish time between 10 minutes and 30 days out:

curl -X POST "https://graph.facebook.com/v26.0/$PAGE_ID/feed" \
  -d "message=Launching Thursday." \
  -d "published=false" \
  -d "scheduled_publish_time=$PUBLISH_AT_UNIX" \
  -d "access_token=$PAGE_TOKEN"

Photos go to /{page-id}/photos, and video and Reels go through the Video API's upload flow. Swap v26.0 for the current version in Meta's changelog.

If you'd rather skip the token and version handling, the Adeli Facebook API publishes to a user's Page with one request.

How do I read Facebook Page insights with the Graph API?#

Call GET /{page-id}/insights?metric=... with read_insights and pages_read_engagement. Meta's Page insights reference lists periods from day to lifetime.

Two limits to know before you promise a dashboard to anyone:

  • Pages under 100 likes return no insights. Test with a Page that has an audience.
  • Metrics get deprecated. Meta retires Page insights metrics across all API versions, and a retired metric returns an error. Keep your metric list in config, not code.

How do I use the Meta Graph API Explorer?#

The Graph API Explorer is Meta's in-browser console for trying calls with your own app's settings. It works for any app on which you hold an admin, developer, or tester role.

  1. Pick your app from the Meta App dropdown.
  2. Choose User or Page token, and add permissions such as pages_show_list.
  3. Generate a token and run a query like me/accounts.
  4. Click Get Code for a sample in your language.

Use it to see what a response looks like before you write code. It can't test Advanced Access, because only people with a role on your app can use it.

What does Meta App Review check for Facebook permissions?#

Meta App Review checks that each permission is tied to a working feature and shown end to end on video. When we went through Meta's review for clients, the same things decided every permission:

  • The screencast shows the whole path. The login, the user granting the permission on Meta's consent screen, and the feature working, in an English UI with captions on any button that isn't obvious.
  • The video and the text match. A feature in the description that the video doesn't show got rejected, and so did the reverse. Cut claims down to what the build does.
  • The use case names a feature. Say which feature needs the permission, how the integration works, and how it helps the person using it.
  • The test setup is real. We prepared a test Facebook account that manages at least two Pages, with posts on them, so no screen in the recording was empty.
  • The account-level gates are done. Meta asks for at least one successful API call per permission in the 30 days before you submit, plus a live privacy policy and data deletion URL. Reviewers also open your website and compare it to the submission.

Permissions are judged one by one, so a submission can come back half approved. For timing, see how long Meta app review takes.

Where does the Facebook Graph API cause friction?#

The first API call is easy. Most of the friction shows up after launch:

  • Review loops. Each rejected permission costs another round, and permissions depend on each other, so one rejection can hold up a feature.
  • Silent token death. Page tokens get invalidated by events on the user's side, and you find out when a scheduled post fails.
  • Version deprecations. Each Graph API version has a sunset date, so you keep migrating.
  • Metric churn. Insights metrics disappear across all versions at once.
  • Two rate-limit systems. Meta's rate limiting docs apply 200 calls per hour per user for app tokens, and 4,800 calls per 24 hours per engaged user for Page tokens. Watch the X-App-Usage and X-Business-Use-Case-Usage headers, and back off on error codes 4, 17, 32, and 80001.
  • One integration per network. Instagram uses a separate permission set, and TikTok, YouTube, and X each have their own apps, reviews, and tokens.

Is there a faster way to use the Facebook Graph API?#

Yes. Use an API that already owns an approved Meta developer app. Adeli's Facebook API publishes through Facebook's Graph API on your behalf. Adeli maintains the developer app, completes Meta's review, and manages OAuth connections and token refresh.

  • No Meta app of your own. Your team holds one Adeli API key.
  • Your users' own Pages. Each user connects their own Facebook Page, scoped and isolated from other users.
  • Per-platform status. Every publish returns a status for each network, plus a webhook when anything changes.
  • Every network in one call. The same posting API publishes to Facebook, Instagram, TikTok, YouTube, and X.
curl https://app.tryadeli.com/api/v1/posts \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"content": "We shipped it.", "platforms": ["facebook", "instagram"], "publishNow": true}'

Your first three connected accounts are free, and one Facebook Page counts as one connected account.

faq

Frequently asked questions

Is the Facebook Graph API free?

Yes. Meta doesn't charge per call for the Facebook Graph API. You pay in rate limits, which scale with your app's users and each Page's engaged users, and in engineering time: App Review up front, then token handling and version upgrades for as long as the integration runs.

Is the Meta Graph API the same as the Facebook Graph API?

Yes. "Meta Graph API" is the newer name for the same API at graph.facebook.com. It also serves the Instagram API with Facebook Login, and Meta's Marketing API for ads is built on it.

Can the Facebook Graph API post to a personal profile?

No. The Facebook Graph API publishes to Facebook Pages, not to personal profiles. A product that posts "to Facebook" for its users is posting to Pages those users manage.

What is the difference between the Graph API and the Marketing API?

The Marketing API is the part of the Graph API for ads: campaigns, ad sets, ads, audiences, and ad reporting. It uses the same host, tokens, and App Review, with its own permissions such as ads_read and ads_management and its own access tiers.

Power your next project
with one social media API

Give your users publishing, scheduling, and analytics through one integration your team can actually maintain.

Get started

Start with free credits. No credit card required.