Instagram API Permissions: Every Scope, Explained

By Mika ReyesPublished 6 min read

The short answer

Instagram API permissions depend on your login type. Instagram Login uses instagram_business_basic plus _content_publish, _manage_comments, _manage_messages, and _manage_insights. Facebook Login uses instagram_basic, instagram_content_publish, and Page scopes. Serving accounts you don't own needs Advanced Access, App Review, and Business Verification. Adeli already holds them.

Instagram API permissions are the scopes your Meta app asks for when an Instagram professional account logs in. The names depend on which login you build. With the Instagram API with Instagram Login, every scope starts with instagram_business_. With the Instagram API with Facebook Login, you request instagram_basic and its siblings, plus Facebook Page scopes. Each permission also carries an access level, and serving accounts you don't own takes Advanced Access, which means App Review and Business Verification.

If you're new to the two logins, start with the Instagram API guide. This post is the permission reference.

Which Instagram API permissions exist?

Two separate sets, one per login. An app picks one: Meta's App Review page says "Your app can either use Facebook Login or Instagram Login but not both." Choose the login before the scopes, and choose it by where your users' accounts live.

Instagram Login Facebook Login
Host graph.instagram.com graph.facebook.com
Facebook Page needed No Yes
Scope prefix instagram_business_ instagram_ plus pages_
Hashtag search, product tagging No Yes
Messaging Yes, in the same API Through the Messenger Platform

Source: Meta's Instagram Platform overview.

What are the Instagram Login permissions?

Five scopes, and every one depends on instagram_business_basic. Request basic, then add only the features you use.

Permission What it unlocks Depends on
instagram_business_basic The account's profile info and media Nothing
instagram_business_content_publish Publishing feed photos and videos instagram_business_basic
instagram_business_manage_comments Reading, replying to, hiding, and deleting comments instagram_business_basic
instagram_business_manage_messages Viewing, managing, and replying to DMs instagram_business_basic
instagram_business_manage_insights Account and media insights instagram_business_basic

Sources: the permissions reference, the insights guide, and content publishing.

Meta's docs don't agree on insights. The insights guide requires instagram_business_manage_insights, but the permissions reference and the App Review list for Instagram Login don't include it. Follow the insights guide, since that's the endpoint you'll call.

You pass the scopes in the authorization URL as a comma-separated list (Business Login docs):

https://www.instagram.com/oauth/authorize
  ?client_id=<APP_ID>
  &redirect_uri=<REDIRECT_URI>
  &response_type=code
  &scope=instagram_business_basic,instagram_business_content_publish,instagram_business_manage_comments

What are the Facebook Login permissions?

More scopes, because the Instagram account is reached through a Facebook Page. Most Instagram permissions here pull in pages_show_list and pages_read_engagement as dependencies.

Permission What it unlocks Depends on
instagram_basic Profile info and media pages_read_user_content, pages_show_list
instagram_content_publish Publishing feed photos and videos instagram_basic, pages_read_engagement, pages_show_list
instagram_manage_comments Creating, hiding, and deleting comments instagram_basic, pages_read_engagement, pages_show_list
instagram_manage_insights Insights for the linked account instagram_basic, pages_read_engagement, pages_show_list
instagram_manage_messages Reading and replying to DMs instagram_basic, pages_read_engagement, pages_show_list
pages_show_list The list of Pages a person manages Nothing
pages_read_engagement Content posted by the Page pages_show_list
business_management Business Manager assets pages_read_engagement, pages_show_list

Source: the permissions reference.

Two extras catch people out:

  • Business Manager Page roles. If the user's Page role was granted in Business Manager, publishing and insights also need ads_management and ads_read (content publishing).
  • Hashtag search is a feature, not a scope. It needs instagram_basic plus the Instagram Public Content Access feature, both through App Review (hashtag search).

Meta's App Review list also writes the publishing scopes as instagram_content_publishing and instagram_business_content_publishing, while the permissions reference and the authorization examples use _publish. Request _publish in your code.

What is the difference between Standard and Advanced Access?

Standard Access works only for people with a role on your app. Advanced Access works for anyone. Every permission has one or the other.

Standard Access Advanced Access
Who can grant it App users with a role on your app Any app user
Fits Testing, or your own accounts Products where customers connect their own Instagram
App Review No Yes
Business Verification No Yes

Sources: Meta's access levels page and overview.

The rules, in Meta's words: "Your app must complete App Review before it can request permissions with Advanced Access" (App Review), and Business Verification "is required for all apps making requests for Advanced Access" (permissions reference). The overview also warns that some features "might not work properly" until Advanced Access is granted, so a feature that works on your test account isn't proof it will work for customers.

Which permission do I need to publish, read comments, send DMs, or read insights?

Pick the row for your feature, then the column for your login.

Task Instagram Login Facebook Login
Publish posts, Reels, carousels instagram_business_basic, instagram_business_content_publish instagram_basic, instagram_content_publish, pages_read_engagement
Read and moderate comments instagram_business_basic, instagram_business_manage_comments instagram_basic, instagram_manage_comments, pages_read_engagement
Read and reply to DMs instagram_business_basic, instagram_business_manage_messages instagram_basic, instagram_manage_messages, pages_read_engagement
Read insights instagram_business_basic, instagram_business_manage_insights instagram_basic, instagram_manage_insights, pages_read_engagement
Search hashtags Not available instagram_basic plus Instagram Public Content Access

With Facebook Login, every row also needs pages_show_list. Page Publishing Authorization can also block publishing even when every permission is granted. If the connected Page requires it, the account "cannot be published to until PPA has been completed" (content publishing).

Each feature has its own guide: access tokens, comments, and the messaging API.

What happened to business_basic and the Basic Display scopes?

They're gone. Instagram Login originally used shorter scope values: business_basic, business_content_publish, business_manage_comments, and business_manage_messages. Meta replaced them with the instagram_business_ versions and said "the old scope values will be deprecated on January 27, 2025" (Instagram Login docs). An app still asking for the old values can't call the Instagram endpoints.

The Basic Display API, and its scopes, went away too. Meta ended it on December 4, 2024, and every request to it fails. If a tutorial lists scopes without the instagram_ prefix, it was written before these changes.

Why was my permission request rejected?

Most rejections come down to asking for more than the app shows. Meta's App Review page names it directly: requesting permissions "that your app does not use or does not align with the allowed usage." The patterns we saw when we went through Meta's review:

  • Unused scopes. Each permission you request has to appear in the product and in the screencast. Drop anything you'll "probably need later."
  • Generic screencasts. The video has to show the specific permission at work: the login, the consent screen, then the feature using that data.
  • No successful call. Meta requires at least 1 successful API call before you can request Advanced Access for certain permissions. Make that call before you submit.
  • Mixed login families. Each app uses one login, so its scopes have to come from that login's set. Don't request instagram_basic alongside instagram_business_basic.
  • Missing Business Verification. Without it, Advanced Access isn't granted at all.

Our post on how long Meta app review takes covers the timeline and the resubmission loop.

How does Adeli fit in?

Adeli holds the Meta developer app and carried Meta's review, so you don't request any of these permissions. Your users connect their own Instagram accounts, Adeli refreshes every connected account's tokens, and you call one API with one API key. Adeli's Instagram API publishes feed posts, Reels, Stories, and carousels from the same endpoint as every other network, reads and moderates comments, and replies to DMs your connected accounts receive. You get a per-platform status on every publish and a webhook when anything changes.

Your first 3 connected accounts are free, and billing is per connected account with no per-post fees on Instagram.

faq

Frequently asked questions

Can one Meta app use both Instagram Login and Facebook Login?

No. Meta's App Review page says an app can use Facebook Login or Instagram Login, but not both. If you need both, you build two apps and each one goes through its own App Review for its own permission set.

Do I need a Facebook Page to use Instagram API permissions?

Only with Facebook Login. The Instagram API with Instagram Login does not need a Facebook Page linked to the professional account. With Facebook Login, the account must be connected to a Page, which is why that login also asks for pages_show_list and pages_read_engagement.

Why is the Advanced Access button greyed out?

A common cause is that your app hasn't made a successful API call with that permission. Meta's App Review page says you need at least 1 successful call before you can request Advanced Access for certain permissions. Make a real call with an account that has a role on your app, then check the button again.

Power your next project
with one social media API

Give your users publishing, scheduling, and analytics through one integration your team can actually maintain.

Try with agents

Start with free credits. No credit card required.