On this page
- Why connecting is the hardest part of the setup
- Prerequisite: the account type
- The scopes and what each one unlocks
- The account setting everyone misses
- Tokens, expiry, and the automation that stops on a Tuesday
- Reviewing and revoking third-party access
- What these permissions do not give anyone
- Connecting to SocialAutoDM
Why connecting is the hardest part of the setup
Writing a keyword rule takes two minutes. Connecting an Instagram account correctly involves an account type, a Meta app, a set of scopes, a permission dialog, an account-level setting, and a token with a lifetime — and every one of those can fail in a way that produces the same symptom: nothing happens. That is why "it says connected but nothing works" is the most common support conversation in this category of product.
Understanding what each piece does turns a frustrating guessing game into a five-minute diagnosis. It also makes you a better buyer, because a tool that hides this entirely is a tool you cannot debug.
Prerequisite: the account type
Personal Instagram accounts cannot be used for messaging automation at all. You need a professional account — Business or Creator — because the messaging permissions only exist for those types. Switching is free and reversible, and it happens in the app rather than in any third-party tool.
- Business and Creator both work for messaging; the differences are elsewhere, in features like scheduling and music licensing.
- Switching account types does not delete content or followers.
- A newly switched account sometimes needs a few minutes before the API recognises the change.
- Some setups also involve a linked Facebook Page, depending on the connection path the tool uses.
The scopes and what each one unlocks
When you approve a connection, you are granting a specific list of permissions. The exact names vary by connection path and change over time, but the functional groups are stable, and knowing which group does what tells you immediately why a feature is missing.
- Basic profile access — identifies which account is connected. Without it there is no connection at all.
- Content access — lets the tool see your posts and Reels, which is what makes "apply this rule to this specific post" possible.
- Comment management — read comments and reply to them publicly. This is what powers public auto-replies.
- Message management — send and receive direct messages, including the private replies that comment-to-DM depends on.
- Insights — engagement metrics. Optional for automation, useful for reporting.
The mapping is direct: if a tool can post public replies but never sends DMs, message management is missing or was declined. If rules cannot be scoped to a particular post, content access is missing. If nothing arrives at all, the problem is usually further along, in the webhook subscription described in Instagram comment webhooks explained.
The account setting everyone misses
Even with every scope granted, Instagram has an account-level setting controlling whether connected tools may access your messages. If it is off, the permission exists and the messages do not flow. This single toggle is responsible for a large share of failed setups, and it is not surfaced during the OAuth dialog — you have to find it in your account’s messaging settings.
Tokens, expiry, and the automation that stops on a Tuesday
A connection is backed by an access token with a finite lifetime. Long-lived tokens last a matter of weeks or months and need refreshing before they lapse. If a tool does not refresh reliably, your automation stops without warning — typically noticed days later when someone asks why nobody received the discount code.
- Tokens expire on a schedule; refresh is a routine background task, not an exceptional event.
- Changing your Instagram password can invalidate tokens, so a security update can silently break automation.
- Removing the app from your connected-apps list revokes access immediately and permanently until you reconnect.
- Changing account type, or disconnecting a linked Facebook Page, can invalidate the connection.
- A tool should alert you when a connection lapses. If it cannot, you need your own periodic check.
The operational lesson is to treat connection health as a monitored dependency rather than a one-time setup step. A weekly test comment from a second account costs nothing and catches this class of failure before your customers do — the same vigilance argument made in what missed Instagram messages cost.
Reviewing and revoking third-party access
Most accounts that have been running for a few years have accumulated connected apps nobody remembers approving — a scheduler from two agencies ago, an analytics trial, a link-in-bio tool that was replaced. Every one of them holds permissions against your account.
- Open your Instagram settings and review the list of connected websites and apps.
- Remove anything you do not currently use or cannot identify.
- For anything you keep, confirm you know who at your company owns the relationship.
- Re-run this review quarterly, and always after someone with access leaves the team.
- Never grant permissions to a tool you found through a DM offering growth services.
Revoking is safe and instant. If you remove something you still needed, you simply reconnect it. This is also the right first action if you suspect a problem — and it is only possible because official integrations are revocable, which password-based tools are not. That asymmetry is one of the central points in official API automation versus unofficial bots.
What these permissions do not give anyone
A reasonable concern when approving a permission dialog is what the tool can now see. The boundaries are narrower than the dialog language suggests, and it is worth knowing them — both for your own comfort and for answering the question when a client asks.
- No password access. OAuth exists specifically so credentials are never shared.
- No ability to message people who have not contacted you — the platform, not the tool, enforces this.
- No access to other people’s private accounts or their message history with anyone else.
- No email addresses or phone numbers unless a person supplies them to you in conversation.
- No permanent access — you can revoke at any time from your own settings.
That last point is the one to emphasise with stakeholders. The permission is a lease, held at your discretion, and cancelling it takes three taps. What a tool does with data it has already collected is a separate question, governed by its privacy policy — ours is on the privacy page.
Frequently asked questions
Why does my Instagram account say connected but nothing happens?
Do I have to give a tool my Instagram password?
How long does a connection last?
Can I connect more than one Instagram account?
Put this into practice with SocialAutoDM
Keyword rules, instant replies and DMs on Instagram and Facebook — on Meta’s official APIs.