Instagram API Comments: Read, Reply, Hide, Delete
The Instagram API reads, replies to, hides, and deletes comments on media owned by a professional account you're authorized for. It needs instagram_business_manage_comments (Instagram Login) or instagram_manage_comments (Facebook Login). It can't read other accounts' comments. Adeli reads, replies to, and moderates comments on any post of a connected account, including posts made outside Adeli.
The Instagram API lets your app read, reply to, hide, and delete comments on media owned by an Instagram professional account that has authorized it. You need instagram_business_manage_comments with Instagram Login or instagram_manage_comments with Facebook Login. It does not read comments on accounts that haven't connected to your app.
Each comment call below comes with a working request, followed by the permissions for both logins, webhooks, and the limits behind most "my comments are missing" bugs.
What can the Instagram API do with comments?
Six operations, all on media the authorized account owns. Every one runs against graph.instagram.com (Instagram Login) or graph.facebook.com (Facebook Login), per Meta's comment moderation guide.
| Operation | Request | Key parameter |
|---|---|---|
| List comments on a post | GET /<IG_MEDIA_ID>/comments |
fields |
| List replies to a comment | GET /<IG_COMMENT_ID>/replies |
fields |
| Reply to a comment | POST /<IG_COMMENT_ID>/replies |
message |
| Comment on your own post | POST /<IG_MEDIA_ID>/comments |
message |
| Hide or unhide a comment | POST /<IG_COMMENT_ID> |
hide=true or false |
| Delete a comment | DELETE /<IG_COMMENT_ID> |
none |
You can also turn comments off for a post with POST /<IG_MEDIA_ID> and comment_enabled=false, per the IG Media reference. Editing a comment isn't supported.
Which permissions do I need?
It depends on the login your app uses. Both sets come from Meta's IG Comment reference.
| Instagram Login | Facebook Login | |
|---|---|---|
| Host | graph.instagram.com |
graph.facebook.com |
| Base permission | instagram_business_basic |
instagram_basic |
| Comments permission | instagram_business_manage_comments |
instagram_manage_comments |
| Also required | Nothing else | pages_read_engagement, plus ads_management or ads_read if the Page role came through Business Manager |
Access level matters too. Standard Access is enough for accounts you own or manage. If customers connect their own Instagram accounts, you need Advanced Access, which means App Review and Business Verification. Our permissions guide lists every scope, and the Meta app review guide covers the timeline.
Watch the username field. Since August 27, 2024, Meta requires the comments permission to read the username of the person who commented. The replies reference still lists GET without instagram_manage_comments. Meta's docs conflict here, so request the comments permission anyway.
How to get comments on a post
Call the media's comments edge and ask for the fields you need. With Instagram Login:
curl -G "https://graph.instagram.com/v25.0/<IG_MEDIA_ID>/comments" \
-H "Authorization: Bearer <ACCESS_TOKEN>" \
--data-urlencode "fields=id,text,timestamp,username,replies{id,text,username}"The comments edge reference sets limits that explain most missing-comment reports:
- 50 per query. The edge returns at most 50 comments, so follow the paging cursors.
- Top-level only. Replies come back only if you expand the
repliesfield, as in the example above. - No timestamp filter. You can't ask for "comments since Tuesday." Requests on recent API versions return newest first.
- Some comments never appear. Meta doesn't return comments on age-gated media or from restricted users, and comments on live video can only be read during the broadcast.
- Ad comments are separate. Comments on non-organic ads aren't on this edge. Meta points to the Marketing API.
How to reply to an Instagram comment
POST a message to the comment's replies edge.
curl -X POST "https://graph.instagram.com/v25.0/<IG_COMMENT_ID>/replies" \
-H "Authorization: Bearer <ACCESS_TOKEN>" \
-d "message=Thanks, glad it helped!"Three rules from the replies reference:
- Top-level comments only. A reply to a reply gets attached to the top-level comment instead.
- No replies to hidden comments. Unhide it first.
- No replies on live video. Meta suggests a private reply through the messaging API instead.
To add a fresh comment to your own post rather than reply to one, POST message to /<IG_MEDIA_ID>/comments. The token has to come from the account that created the media.
How to hide or delete a comment
Hide with hide=true, delete with a DELETE request. Hiding can be undone, so it's the safer default for moderation.
# Hide (use hide=false to show it again)
curl -X POST "https://graph.instagram.com/v25.0/<IG_COMMENT_ID>" \
-H "Authorization: Bearer <ACCESS_TOKEN>" \
-d "hide=true"
# Delete
curl -X DELETE "https://graph.instagram.com/v25.0/<IG_COMMENT_ID>" \
-H "Authorization: Bearer <ACCESS_TOKEN>"What the IG Comment reference says about each:
- Hiding needs the media owner's token. Comments the owner left on their own media stay visible even when set to
hide=true. - Deleting is limited to the media owner. Meta says a comment can only be deleted by the owner of the object it was made on, even if the comment's author is the one trying. The same page also says the token must come from the user who created the comment. Those two lines conflict. In practice, call DELETE with the media owner's token.
- Live video is off-limits. Hide and delete aren't supported on comments on live video.
How to get new comments in real time
Subscribe to webhooks instead of polling. Meta's webhooks guide offers comments and live_comments fields, and the comment moderation guide says plainly: "We strongly recommend using webhooks to prevent rate limiting."
- Configure the webhook for the Instagram product in the App Dashboard, pointing at your callback URL.
- Subscribe each account. Send
POST /me/subscribed_appswithsubscribed_fields=commentsusing that account's token. - Handle the event. Each notification carries the comment ID. Fetch the comment with GET if you need fields the payload leaves out.
Webhooks only fire when all of these hold:
| Requirement | Why it fails without it |
|---|---|
| App in Live mode | Meta sends no notifications to apps in development mode |
| Advanced Access | Required for comments and live_comments |
| Public account | Private accounts don't send comment or @mention notifications |
| Business Verification | Listed as required for both logins |
With Instagram Login, @mentions arrive in the comments notification. With Facebook Login, mentions is its own field.
If you're building this into a product, Adeli's commenting API reads, replies to, and moderates comments on connected accounts without your own Meta app or token refresh job.
Can I DM someone who commented?
Yes, once, with a private reply. Meta's private replies guide lets you send one message to a commenter by passing the comment ID as the recipient:
curl -X POST "https://graph.instagram.com/v25.0/<IG_USER_ID>/messages" \
-H "Authorization: Bearer <ACCESS_TOKEN>" \
-H "Content-Type: application/json" \
-d '{"recipient":{"comment_id":"<IG_COMMENT_ID>"},"message":{"text":"Sending you the link here."}}'- One message. You can send more only if the person replies, and then within 24 hours of their reply.
- Within 7 days. The message has to go out within 7 days of the comment. On Instagram Live, only during the broadcast.
The windows, tags, and errors that come with DMs are covered in our Instagram Messaging API guide. For DMs in general, Adeli reads and replies to the messages connected accounts receive.
Is there a faster way to do this?
Yes, if you don't want to run the Meta side yourself. Building comments directly means a Meta app, Advanced Access for the comments permission, Business Verification, webhooks, and a token refresh job for every account.
Adeli holds the Meta developer app, carried Meta's review, and refreshes every connected account's tokens. You hold one API key. Adeli reads, replies to, and moderates comments on any post of a connected account, including posts made outside Adeli, through the same API you publish with. The endpoints are in the comments API docs, and your first 3 connected accounts are free.