# Instagram API Comments: Read, Reply, Hide, Delete

How to read, reply to, hide, and delete Instagram comments with the Graph API: endpoints, permissions for both logins, webhooks, and the limits.

Canonical page: https://www.tryadeli.com/blog/instagram-api-comments
Last updated: 2026-10-09

By Mika Reyes, Co-founder, Adeli. Published 2026-10-09.

## The short answer

The Instagram API reads, replies to, hides, and deletes comments on media owned by a professional account you're authorized for. It needs instagram_business_manage_comments (Instagram Login) or instagram_manage_comments (Facebook Login). It can't read other accounts' comments. Adeli reads, replies to, and moderates comments on any post of a connected account, including posts made outside Adeli.

The [Instagram API](https://www.tryadeli.com/blog/instagram-api-guide) lets your app **read, reply to, hide, and delete comments** on media owned by an Instagram professional account that has authorized it. You need **`instagram_business_manage_comments`** with Instagram Login or **`instagram_manage_comments`** with Facebook Login. It does not read comments on accounts that haven't connected to your app.

Each comment call below comes with a working request, followed by the permissions for both logins, webhooks, and the limits behind most "my comments are missing" bugs.

## What can the Instagram API do with comments?

**Six operations, all on media the authorized account owns.** Every one runs against `graph.instagram.com` (Instagram Login) or `graph.facebook.com` (Facebook Login), per Meta's [comment moderation guide](https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/comment-moderation).

| Operation | Request | Key parameter |
|---|---|---|
| **List comments on a post** | `GET /<IG_MEDIA_ID>/comments` | `fields` |
| **List replies to a comment** | `GET /<IG_COMMENT_ID>/replies` | `fields` |
| **Reply to a comment** | `POST /<IG_COMMENT_ID>/replies` | `message` |
| **Comment on your own post** | `POST /<IG_MEDIA_ID>/comments` | `message` |
| **Hide or unhide a comment** | `POST /<IG_COMMENT_ID>` | `hide=true` or `false` |
| **Delete a comment** | `DELETE /<IG_COMMENT_ID>` | none |

You can also **turn comments off for a post** with `POST /<IG_MEDIA_ID>` and `comment_enabled=false`, per the [IG Media reference](https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-media). Editing a comment isn't supported.

## Which permissions do I need?

**It depends on the login your app uses.** Both sets come from Meta's [IG Comment reference](https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-comment).

| | Instagram Login | Facebook Login |
|---|---|---|
| **Host** | `graph.instagram.com` | `graph.facebook.com` |
| **Base permission** | `instagram_business_basic` | `instagram_basic` |
| **Comments permission** | `instagram_business_manage_comments` | `instagram_manage_comments` |
| **Also required** | Nothing else | `pages_read_engagement`, plus `ads_management` or `ads_read` if the Page role came through Business Manager |

**Access level matters too.** Standard Access is enough for accounts you own or manage. If customers connect their own Instagram accounts, you need **Advanced Access**, which means App Review and Business Verification. Our [permissions guide](https://www.tryadeli.com/blog/instagram-api-permissions) lists every scope, and the [Meta app review guide](https://www.tryadeli.com/blog/meta-app-review-time) covers the timeline.

**Watch the `username` field.** Since August 27, 2024, Meta requires the comments permission to read the `username` of the person who commented. The [replies reference](https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-comment/replies) still lists GET without `instagram_manage_comments`. Meta's docs conflict here, so request the comments permission anyway.

## How to get comments on a post

**Call the media's `comments` edge and ask for the fields you need.** With Instagram Login:

```bash
curl -G "https://graph.instagram.com/v25.0/<IG_MEDIA_ID>/comments" \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  --data-urlencode "fields=id,text,timestamp,username,replies{id,text,username}"
```

The [comments edge reference](https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-media/comments) sets limits that explain most missing-comment reports:

- **50 per query.** The edge returns at most 50 comments, so follow the paging cursors.
- **Top-level only.** Replies come back only if you expand the `replies` field, as in the example above.
- **No timestamp filter.** You can't ask for "comments since Tuesday." Requests on recent API versions return newest first.
- **Some comments never appear.** Meta doesn't return comments on age-gated media or from restricted users, and comments on live video can only be read during the broadcast.
- **Ad comments are separate.** Comments on non-organic ads aren't on this edge. Meta points to the Marketing API.

## How to reply to an Instagram comment

**POST a `message` to the comment's `replies` edge.**

```bash
curl -X POST "https://graph.instagram.com/v25.0/<IG_COMMENT_ID>/replies" \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  -d "message=Thanks, glad it helped!"
```

Three rules from the [replies reference](https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-comment/replies):

1. **Top-level comments only.** A reply to a reply gets attached to the top-level comment instead.
2. **No replies to hidden comments.** Unhide it first.
3. **No replies on live video.** Meta suggests a private reply through the messaging API instead.

To add a fresh comment to your own post rather than reply to one, POST `message` to `/<IG_MEDIA_ID>/comments`. The token has to come from the account that created the media.

## How to hide or delete a comment

**Hide with `hide=true`, delete with a DELETE request.** Hiding can be undone, so it's the safer default for moderation.

```bash
# Hide (use hide=false to show it again)
curl -X POST "https://graph.instagram.com/v25.0/<IG_COMMENT_ID>" \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  -d "hide=true"

# Delete
curl -X DELETE "https://graph.instagram.com/v25.0/<IG_COMMENT_ID>" \
  -H "Authorization: Bearer <ACCESS_TOKEN>"
```

What the [IG Comment reference](https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-comment) says about each:

- **Hiding needs the media owner's token.** Comments the owner left on their own media stay visible even when set to `hide=true`.
- **Deleting is limited to the media owner.** Meta says a comment can only be deleted by the owner of the object it was made on, **even if the comment's author is the one trying**. The same page also says the token must come from the user who created the comment. Those two lines conflict. In practice, call DELETE with the media owner's token.
- **Live video is off-limits.** Hide and delete aren't supported on comments on live video.

## How to get new comments in real time

**Subscribe to webhooks instead of polling.** Meta's [webhooks guide](https://developers.facebook.com/docs/instagram-platform/webhooks) offers `comments` and `live_comments` fields, and the comment moderation guide says plainly: "We strongly recommend using webhooks to prevent rate limiting."

1. **Configure the webhook** for the Instagram product in the App Dashboard, pointing at your callback URL.
2. **Subscribe each account.** Send `POST /me/subscribed_apps` with `subscribed_fields=comments` using that account's token.
3. **Handle the event.** Each notification carries the comment ID. Fetch the comment with GET if you need fields the payload leaves out.

Webhooks only fire when all of these hold:

| Requirement | Why it fails without it |
|---|---|
| **App in Live mode** | Meta sends no notifications to apps in development mode |
| **Advanced Access** | Required for `comments` and `live_comments` |
| **Public account** | Private accounts don't send comment or @mention notifications |
| **Business Verification** | Listed as required for both logins |

With Instagram Login, **@mentions arrive in the `comments` notification**. With Facebook Login, `mentions` is its own field.

If you're building this into a product, Adeli's [commenting API](https://www.tryadeli.com/social-media-commenting-api) reads, replies to, and moderates comments on connected accounts without your own Meta app or token refresh job.

## Can I DM someone who commented?

**Yes, once, with a private reply.** Meta's [private replies guide](https://developers.facebook.com/docs/instagram-platform/private-replies) lets you send one message to a commenter by passing the comment ID as the recipient:

```bash
curl -X POST "https://graph.instagram.com/v25.0/<IG_USER_ID>/messages" \
  -H "Authorization: Bearer <ACCESS_TOKEN>" \
  -H "Content-Type: application/json" \
  -d '{"recipient":{"comment_id":"<IG_COMMENT_ID>"},"message":{"text":"Sending you the link here."}}'
```

- **One message.** You can send more only if the person replies, and then within 24 hours of their reply.
- **Within 7 days.** The message has to go out within 7 days of the comment. On Instagram Live, only during the broadcast.

The windows, tags, and errors that come with DMs are covered in our [Instagram Messaging API guide](https://www.tryadeli.com/blog/instagram-messaging-api). For DMs in general, Adeli reads and replies to the messages connected accounts receive.

## Is there a faster way to do this?

**Yes, if you don't want to run the Meta side yourself.** Building comments directly means a Meta app, Advanced Access for the comments permission, Business Verification, webhooks, and a token refresh job for every account.

[Adeli](https://www.tryadeli.com/product/instagram) holds the Meta developer app, carried Meta's review, and refreshes every connected account's tokens. You hold **one API key**. Adeli reads, replies to, and moderates comments on **any post of a connected account, including posts made outside Adeli**, through the same API you publish with. The endpoints are in the [comments API docs](https://www.tryadeli.com/docs/api/comments), and your **first 3 connected accounts are free**.

## Frequently asked questions

### Can I read comments on someone else's Instagram post?

Not through the official Instagram API. The comment endpoints only work on media owned by a professional account that authorized your app. Meta's reference says comments found through the Mentions API can't be read this way unless you own the comment, and points you to the Mentioned Comment node instead.

### Why is my Instagram comment list empty or incomplete?

The comments edge returns at most 50 comments per query and only top-level comments, so page through results and request the replies field for threads. Meta also leaves out comments on age-gated media and comments from restricted users. Comments on live video can only be read while the broadcast is running.

### Why aren't Instagram comment webhooks firing?

Check four things. The app has to be in Live mode, the comments permission needs Advanced Access, the Instagram account that owns the media has to be public, and the account has to be subscribed to your app through the subscribed_apps endpoint with the comments field.

## Related Adeli pages

- [Social Media Commenting API](https://www.tryadeli.com/social-media-commenting-api.md): Read, reply to, and moderate comments on Instagram, TikTok, YouTube, and Facebook posts through the same API you publish with.
- [Instagram API for Developers](https://www.tryadeli.com/product/instagram.md): Publish, schedule, and read analytics for Instagram through one API. Adeli owns the Instagram developer app, token refresh, and Meta review. Free to start.
- [All posts on the Adeli blog](https://www.tryadeli.com/blog.md)

## About the author

Mika Reyes is the CEO behind Adeli and a tech and AI content creator. She was previously co-founder and CEO of Parallax, which was acquired by Phantom, and a product lead at LinkedIn. She is a Forbes 30 Under 30 honoree.
