Facebook Graph API: Access, Tokens, Posting, Review
The Facebook Graph API is Meta's HTTP API at graph.facebook.com for reading and writing Facebook data: publishing to Pages, reading comments, and pulling Page insights. To use it for other people's Pages, you create a Meta app, request Page permissions, pass Business Verification and App Review, then manage Page access tokens. Adeli owns that approved app, so you publish to Facebook with one API key.
The Facebook Graph API is Meta's HTTP API for getting data into and out of Facebook. Your app sends requests to graph.facebook.com with an access token to publish to Pages, manage comments, and read insights. To do that on your users' Pages, you first need a Meta app, Page permissions, and App Review approval for each permission.
What is the Facebook Graph API?#
The Facebook Graph API is the main programming interface to Facebook, and most people mean it when they search "Facebook API" or "fb API". Meta's Graph API overview calls it "the primary way to get data into and out of the Facebook platform."
It models Facebook as a graph of three things:
- Nodes. Individual objects with an ID: a Page, a post, a photo, a comment.
- Edges. Connections between nodes: a Page's
/feed, a post's/comments. - Fields. Properties you ask for by name:
?fields=name,followers_count.
Every request goes to https://graph.facebook.com/v{version}/.... Meta ships a new version roughly every quarter, and an unversioned call falls back to the oldest version still available, so pin a version in every request.
"Meta Graph API" and "facebook.com Graph API" are the same API. The Instagram API with Facebook Login and the Marketing API both run on it.
What can you do with the Facebook Graph API?#
For a product that posts on its users' behalf, the Facebook Graph API covers Pages: publishing, comments, messages, and insights. It doesn't reach personal profiles.
| Task | Possible? | Where it happens |
|---|---|---|
| Publish text, link, and photo posts to a Page | Yes | POST /{page-id}/feed, POST /{page-id}/photos |
| Publish video and Reels to a Page | Yes | The Video API |
| Schedule a Page post | Yes, 10 minutes to 30 days ahead | published=false plus scheduled_publish_time |
| Read and reply to comments on Page posts | Yes | /{post-id}/comments |
| Reply to Messenger conversations | Yes, within the messaging window | Messenger Platform |
| Read Page and post insights | Yes, on Pages with 100+ likes | /{object-id}/insights |
| Post to a personal profile | No | Not available through the API |
| Run ads | Yes, through the Marketing API | Separate permissions and access tiers |
How do apps get access to the Facebook Graph API?#
Apps get access through a Meta app. What people search as the "Facebook app API" is this registration in the App Dashboard, which holds your app ID, app secret, permissions, and review status.
- Create a Meta app. Register as a Meta developer and create an app for a business use case.
- Add Facebook Login for Business. Your users connect their Pages through it and grant permissions on Meta's consent screen.
- Build and test with Standard Access. Meta grants Standard Access automatically, but it only works for people who hold a role on your app.
- Complete Business Verification. Meta requires it for Advanced Access, which is what lets people without a role on your app grant permissions.
- Pass App Review for each permission. Each permission needs its own written use case and screencast.
- Keep it compliant. Advanced Access also comes with an annual Data Use Checkup.
Standard Access only covers people on your app. Everything works on your own test Pages, so the integration looks done, and the first customer without a role on your app who tries to connect gets an error.
Which permissions does a Facebook Pages integration need?#
A Pages integration needs one permission per capability, and each one that needs Advanced Access goes through App Review on its own. Map every feature to its permission before you build:
| Feature | Permission |
|---|---|
| List the Pages a user manages, so they can pick one | pages_show_list |
| Identify the Page and read its posts | pages_read_engagement |
| Publish, edit, and delete Page posts | pages_manage_posts |
| Read other people's comments on Page posts | pages_read_user_content |
| Reply to, hide, and delete comments | pages_manage_engagement |
| Subscribe to webhooks for the Page's feed and messages | pages_manage_metadata |
| Reply in the Page's Messenger inbox | pages_messaging |
| Read Page and post insights | read_insights with pages_read_engagement |
| Find Pages owned through a Business portfolio | business_management |
The user also needs the right role on the Page. Meta's Pages posts docs say they must be able to perform "CREATE_CONTENT, MANAGE, and MODERATE tasks on the Page."
How do Facebook Graph API access tokens work?#
Page actions use a Page access token, which you get from the user's token after they log in. Store the wrong one and your integration stops working within hours, or in about two months. Meta's long-lived token docs set the lifetimes:
| Token | Lifetime | Used for |
|---|---|---|
| Short-lived user token | Hours | What Facebook Login returns first |
| Long-lived user token | About 60 days | Exchanged server-side with your app secret |
| Page token from a long-lived user token | No expiration date | Publishing, comments, insights for that Page |
| App token | Until you reset the app secret | App-level calls and settings |
The production flow:
- The user logs in with Facebook Login for Business and gets a short-lived user token.
- Your server exchanges it at
GET /oauth/access_tokenwithgrant_type=fb_exchange_token. - You call
GET /me/accountswith the long-lived token and store each Page's token.
A Page token with no expiration date can still stop working. Meta says long-lived Page tokens can be "invalidated under certain conditions", such as the user revoking your app, changing their password, or losing their role on the Page. Your code has to catch the error, flag the connection, and ask the user to reconnect.
How do I publish a post to a Facebook Page with the Graph API?#
Send a POST to the Page's /feed edge with a Page access token. A text post with a link:
curl -X POST "https://graph.facebook.com/v26.0/$PAGE_ID/feed" \
-d "message=We shipped it." \
-d "link=https://example.com/changelog" \
-d "access_token=$PAGE_TOKEN"A scheduled post adds two parameters. Meta accepts a publish time between 10 minutes and 30 days out:
curl -X POST "https://graph.facebook.com/v26.0/$PAGE_ID/feed" \
-d "message=Launching Thursday." \
-d "published=false" \
-d "scheduled_publish_time=$PUBLISH_AT_UNIX" \
-d "access_token=$PAGE_TOKEN"Photos go to /{page-id}/photos, and video and Reels go through the Video API's upload flow. Swap v26.0 for the current version in Meta's changelog.
If you'd rather skip the token and version handling, the Adeli Facebook API publishes to a user's Page with one request.
How do I read Facebook Page insights with the Graph API?#
Call GET /{page-id}/insights?metric=... with read_insights and pages_read_engagement. Meta's Page insights reference lists periods from day to lifetime.
Two limits to know before you promise a dashboard to anyone:
- Pages under 100 likes return no insights. Test with a Page that has an audience.
- Metrics get deprecated. Meta retires Page insights metrics across all API versions, and a retired metric returns an error. Keep your metric list in config, not code.
How do I use the Meta Graph API Explorer?#
The Graph API Explorer is Meta's in-browser console for trying calls with your own app's settings. It works for any app on which you hold an admin, developer, or tester role.
- Pick your app from the Meta App dropdown.
- Choose User or Page token, and add permissions such as
pages_show_list. - Generate a token and run a query like
me/accounts. - Click Get Code for a sample in your language.
Use it to see what a response looks like before you write code. It can't test Advanced Access, because only people with a role on your app can use it.
What does Meta App Review check for Facebook permissions?#
Meta App Review checks that each permission is tied to a working feature and shown end to end on video. When we went through Meta's review for clients, the same things decided every permission:
- The screencast shows the whole path. The login, the user granting the permission on Meta's consent screen, and the feature working, in an English UI with captions on any button that isn't obvious.
- The video and the text match. A feature in the description that the video doesn't show got rejected, and so did the reverse. Cut claims down to what the build does.
- The use case names a feature. Say which feature needs the permission, how the integration works, and how it helps the person using it.
- The test setup is real. We prepared a test Facebook account that manages at least two Pages, with posts on them, so no screen in the recording was empty.
- The account-level gates are done. Meta asks for at least one successful API call per permission in the 30 days before you submit, plus a live privacy policy and data deletion URL. Reviewers also open your website and compare it to the submission.
Permissions are judged one by one, so a submission can come back half approved. For timing, see how long Meta app review takes.
Where does the Facebook Graph API cause friction?#
The first API call is easy. Most of the friction shows up after launch:
- Review loops. Each rejected permission costs another round, and permissions depend on each other, so one rejection can hold up a feature.
- Silent token death. Page tokens get invalidated by events on the user's side, and you find out when a scheduled post fails.
- Version deprecations. Each Graph API version has a sunset date, so you keep migrating.
- Metric churn. Insights metrics disappear across all versions at once.
- Two rate-limit systems. Meta's rate limiting docs apply 200 calls per hour per user for app tokens, and 4,800 calls per 24 hours per engaged user for Page tokens. Watch the
X-App-UsageandX-Business-Use-Case-Usageheaders, and back off on error codes 4, 17, 32, and 80001. - One integration per network. Instagram uses a separate permission set, and TikTok, YouTube, and X each have their own apps, reviews, and tokens.
Is there a faster way to use the Facebook Graph API?#
Yes. Use an API that already owns an approved Meta developer app. Adeli's Facebook API publishes through Facebook's Graph API on your behalf. Adeli maintains the developer app, completes Meta's review, and manages OAuth connections and token refresh.
- No Meta app of your own. Your team holds one Adeli API key.
- Your users' own Pages. Each user connects their own Facebook Page, scoped and isolated from other users.
- Per-platform status. Every publish returns a status for each network, plus a webhook when anything changes.
- Every network in one call. The same posting API publishes to Facebook, Instagram, TikTok, YouTube, and X.
curl https://app.tryadeli.com/api/v1/posts \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d '{"content": "We shipped it.", "platforms": ["facebook", "instagram"], "publishNow": true}'Your first three connected accounts are free, and one Facebook Page counts as one connected account.