# Instagram API Permissions: Every Scope, Explained

Every Instagram API permission for Instagram Login and Facebook Login: what each unlocks, its dependencies, Standard vs. Advanced Access, and why reviews fail.

Canonical page: https://www.tryadeli.com/blog/instagram-api-permissions
Last updated: 2026-10-09

By Mika Reyes, Co-founder, Adeli. Published 2026-10-09.

## The short answer

Instagram API permissions depend on your login type. Instagram Login uses instagram_business_basic plus _content_publish, _manage_comments, _manage_messages, and _manage_insights. Facebook Login uses instagram_basic, instagram_content_publish, and Page scopes. Serving accounts you don't own needs Advanced Access, App Review, and Business Verification. Adeli already holds them.

Instagram API permissions are the scopes your Meta app asks for when an Instagram professional account logs in. **The names depend on which login you build.** With the **Instagram API with Instagram Login**, every scope starts with `instagram_business_`. With the **Instagram API with Facebook Login**, you request `instagram_basic` and its siblings, plus Facebook Page scopes. Each permission also carries an access level, and serving accounts you don't own takes **Advanced Access**, which means App Review and Business Verification.

If you're new to the two logins, start with the [Instagram API guide](https://www.tryadeli.com/blog/instagram-api-guide). This post is the permission reference.

## Which Instagram API permissions exist?

**Two separate sets, one per login.** An app picks one: Meta's [App Review page](https://developers.facebook.com/docs/instagram-platform/app-review) says "Your app can either use Facebook Login or Instagram Login but not both." Choose the login before the scopes, and choose it by where your users' accounts live.

| | Instagram Login | Facebook Login |
|---|---|---|
| **Host** | `graph.instagram.com` | `graph.facebook.com` |
| **Facebook Page needed** | No | Yes |
| **Scope prefix** | `instagram_business_` | `instagram_` plus `pages_` |
| **Hashtag search, product tagging** | No | Yes |
| **Messaging** | Yes, in the same API | Through the Messenger Platform |

Source: Meta's [Instagram Platform overview](https://developers.facebook.com/docs/instagram-platform/overview).

## What are the Instagram Login permissions?

**Five scopes, and every one depends on `instagram_business_basic`.** Request basic, then add only the features you use.

| Permission | What it unlocks | Depends on |
|---|---|---|
| `instagram_business_basic` | The account's profile info and media | Nothing |
| `instagram_business_content_publish` | Publishing feed photos and videos | `instagram_business_basic` |
| `instagram_business_manage_comments` | Reading, replying to, hiding, and deleting comments | `instagram_business_basic` |
| `instagram_business_manage_messages` | Viewing, managing, and replying to DMs | `instagram_business_basic` |
| `instagram_business_manage_insights` | Account and media insights | `instagram_business_basic` |

Sources: the [permissions reference](https://developers.facebook.com/docs/permissions), the [insights guide](https://developers.facebook.com/docs/instagram-platform/insights), and [content publishing](https://developers.facebook.com/docs/instagram-platform/content-publishing).

**Meta's docs don't agree on insights.** The [insights guide](https://developers.facebook.com/docs/instagram-platform/insights) requires `instagram_business_manage_insights`, but the permissions reference and the App Review list for Instagram Login don't include it. Follow the insights guide, since that's the endpoint you'll call.

You pass the scopes in the authorization URL as a comma-separated list ([Business Login docs](https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/business-login)):

```text
https://www.instagram.com/oauth/authorize
  ?client_id=<APP_ID>
  &redirect_uri=<REDIRECT_URI>
  &response_type=code
  &scope=instagram_business_basic,instagram_business_content_publish,instagram_business_manage_comments
```

## What are the Facebook Login permissions?

**More scopes, because the Instagram account is reached through a Facebook Page.** Most Instagram permissions here pull in `pages_show_list` and `pages_read_engagement` as dependencies.

| Permission | What it unlocks | Depends on |
|---|---|---|
| `instagram_basic` | Profile info and media | `pages_read_user_content`, `pages_show_list` |
| `instagram_content_publish` | Publishing feed photos and videos | `instagram_basic`, `pages_read_engagement`, `pages_show_list` |
| `instagram_manage_comments` | Creating, hiding, and deleting comments | `instagram_basic`, `pages_read_engagement`, `pages_show_list` |
| `instagram_manage_insights` | Insights for the linked account | `instagram_basic`, `pages_read_engagement`, `pages_show_list` |
| `instagram_manage_messages` | Reading and replying to DMs | `instagram_basic`, `pages_read_engagement`, `pages_show_list` |
| `pages_show_list` | The list of Pages a person manages | Nothing |
| `pages_read_engagement` | Content posted by the Page | `pages_show_list` |
| `business_management` | Business Manager assets | `pages_read_engagement`, `pages_show_list` |

Source: the [permissions reference](https://developers.facebook.com/docs/permissions).

Two extras catch people out:

- **Business Manager Page roles.** If the user's Page role was granted in Business Manager, publishing and insights also need `ads_management` and `ads_read` ([content publishing](https://developers.facebook.com/docs/instagram-platform/content-publishing)).
- **Hashtag search is a feature, not a scope.** It needs `instagram_basic` plus the **Instagram Public Content Access** feature, both through App Review ([hashtag search](https://developers.facebook.com/docs/instagram-platform/instagram-api-with-facebook-login/hashtag-search)).

Meta's App Review list also writes the publishing scopes as `instagram_content_publishing` and `instagram_business_content_publishing`, while the permissions reference and the authorization examples use `_publish`. Request `_publish` in your code.

## What is the difference between Standard and Advanced Access?

**Standard Access works only for people with a role on your app. Advanced Access works for anyone.** Every permission has one or the other.

| | Standard Access | Advanced Access |
|---|---|---|
| **Who can grant it** | App users with a role on your app | Any app user |
| **Fits** | Testing, or your own accounts | Products where customers connect their own Instagram |
| **App Review** | No | Yes |
| **Business Verification** | No | Yes |

Sources: Meta's [access levels page](https://developers.facebook.com/docs/graph-api/overview/access-levels) and [overview](https://developers.facebook.com/docs/instagram-platform/overview).

The rules, in Meta's words: "Your app must complete App Review before it can request permissions with Advanced Access" ([App Review](https://developers.facebook.com/docs/instagram-platform/app-review)), and Business Verification "is required for all apps making requests for Advanced Access" ([permissions reference](https://developers.facebook.com/docs/permissions)). The overview also warns that some features "might not work properly" until Advanced Access is granted, so a feature that works on your test account isn't proof it will work for customers.

## Which permission do I need to publish, read comments, send DMs, or read insights?

**Pick the row for your feature, then the column for your login.**

| Task | Instagram Login | Facebook Login |
|---|---|---|
| **Publish posts, Reels, carousels** | `instagram_business_basic`, `instagram_business_content_publish` | `instagram_basic`, `instagram_content_publish`, `pages_read_engagement` |
| **Read and moderate comments** | `instagram_business_basic`, `instagram_business_manage_comments` | `instagram_basic`, `instagram_manage_comments`, `pages_read_engagement` |
| **Read and reply to DMs** | `instagram_business_basic`, `instagram_business_manage_messages` | `instagram_basic`, `instagram_manage_messages`, `pages_read_engagement` |
| **Read insights** | `instagram_business_basic`, `instagram_business_manage_insights` | `instagram_basic`, `instagram_manage_insights`, `pages_read_engagement` |
| **Search hashtags** | Not available | `instagram_basic` plus Instagram Public Content Access |

With Facebook Login, every row also needs `pages_show_list`. **Page Publishing Authorization** can also block publishing even when every permission is granted. If the connected Page requires it, the account "cannot be published to until PPA has been completed" ([content publishing](https://developers.facebook.com/docs/instagram-platform/content-publishing)).

Each feature has its own guide: [access tokens](https://www.tryadeli.com/blog/instagram-api-access-token), [comments](https://www.tryadeli.com/blog/instagram-api-comments), and the [messaging API](https://www.tryadeli.com/blog/instagram-messaging-api).

## What happened to business_basic and the Basic Display scopes?

**They're gone.** Instagram Login originally used shorter scope values: `business_basic`, `business_content_publish`, `business_manage_comments`, and `business_manage_messages`. Meta replaced them with the `instagram_business_` versions and said "the old scope values will be deprecated on January 27, 2025" ([Instagram Login docs](https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login)). An app still asking for the old values can't call the Instagram endpoints.

**The Basic Display API, and its scopes, went away too.** Meta [ended it on December 4, 2024](https://developers.facebook.com/blog/post/2024/09/04/update-on-instagram-basic-display-api/), and every request to it fails. If a tutorial lists scopes without the `instagram_` prefix, it was written before these changes.

## Why was my permission request rejected?

**Most rejections come down to asking for more than the app shows.** Meta's [App Review page](https://developers.facebook.com/docs/instagram-platform/app-review) names it directly: requesting permissions "that your app does not use or does not align with the allowed usage." The patterns we saw when we went through Meta's review:

- **Unused scopes.** Each permission you request has to appear in the product and in the screencast. Drop anything you'll "probably need later."
- **Generic screencasts.** The video has to show the specific permission at work: the login, the consent screen, then the feature using that data.
- **No successful call.** Meta requires at least 1 successful API call before you can request Advanced Access for certain permissions. Make that call before you submit.
- **Mixed login families.** Each app uses one login, so its scopes have to come from that login's set. Don't request `instagram_basic` alongside `instagram_business_basic`.
- **Missing Business Verification.** Without it, Advanced Access isn't granted at all.

Our post on [how long Meta app review takes](https://www.tryadeli.com/blog/meta-app-review-time) covers the timeline and the resubmission loop.

## How does Adeli fit in?

**Adeli holds the Meta developer app and carried Meta's review, so you don't request any of these permissions.** Your users connect their own Instagram accounts, Adeli refreshes every connected account's tokens, and you call one API with one API key. [Adeli's Instagram API](https://www.tryadeli.com/product/instagram) publishes feed posts, Reels, Stories, and carousels from the [same endpoint](https://www.tryadeli.com/social-media-posting-api) as every other network, reads and moderates comments, and replies to DMs your connected accounts receive. You get a per-platform status on every publish and a webhook when anything changes.

**Your first 3 connected accounts are free**, and billing is per connected account with no per-post fees on Instagram.

## Frequently asked questions

### Can one Meta app use both Instagram Login and Facebook Login?

No. Meta's App Review page says an app can use Facebook Login or Instagram Login, but not both. If you need both, you build two apps and each one goes through its own App Review for its own permission set.

### Do I need a Facebook Page to use Instagram API permissions?

Only with Facebook Login. The Instagram API with Instagram Login does not need a Facebook Page linked to the professional account. With Facebook Login, the account must be connected to a Page, which is why that login also asks for pages_show_list and pages_read_engagement.

### Why is the Advanced Access button greyed out?

A common cause is that your app hasn't made a successful API call with that permission. Meta's App Review page says you need at least 1 successful call before you can request Advanced Access for certain permissions. Make a real call with an account that has a role on your app, then check the button again.

## Related Adeli pages

- [Instagram API for Developers](https://www.tryadeli.com/product/instagram.md): Publish, schedule, and read analytics for Instagram through one API. Adeli owns the Instagram developer app, token refresh, and Meta review. Free to start.
- [Social Media Posting & Scheduling API](https://www.tryadeli.com/social-media-posting-api.md): Adeli's social media posting and scheduling API publishes to Instagram, TikTok, YouTube, Facebook, X, and Bluesky in one request, now or at a set time. Free to start.
- [All posts on the Adeli blog](https://www.tryadeli.com/blog.md)

## About the author

Mika Reyes is the CEO behind Adeli and a tech and AI content creator. She was previously co-founder and CEO of Parallax, which was acquired by Phantom, and a product lead at LinkedIn. She is a Forbes 30 Under 30 honoree.
