Glossary

What is OAuth login?

OAuth is the standard behind buttons like “Log in with Instagram” and “Continue with Facebook.” Instead of giving another app your password, you sign in on Instagram or Facebook itself, approve a list of permissions, and the app receives a token that lets it do only those things.

Updated 6 October 2026

OAuth lets an app act on your account without your password: you approve specific permissions on the account’s own site, and the app receives a token.

Automation and Meta's API

How OAuth login works, step by step

  1. You click Connect Instagram in an app. It sends you to an authorisation page on instagram.com, naming the permissions it wants, usually with a random “state” value it will check when you return.
  2. You log in there if you aren’t already, see the app’s name and the permissions, and approve or cancel.
  3. Instagram sends you back to the app with an authorisation code. Meta’s documentation says the code is valid for 1 hour and works only once.
  4. The app’s server swaps the code, together with its app secret, for an access token, and uses that token for every request after.
  5. If you cancel, you’re still sent back, with an error instead of a code, and nothing is connected.

Your password never passes through the app. That’s the point: the app holds a token tied to specific permissions, which can be withdrawn, instead of a key to the whole account. The framework behind it, OAuth 2.0, was published by the Internet Engineering Task Force in 2012 as RFC 6749, and most “Log in with” buttons on the web are built on it.

Tokens, expiry and reconnecting

With Business Login for Instagram, the first token the app receives is short-lived, and the app exchanges it for a long-lived one that lasts 60 days. That token can be refreshed once it’s at least 24 hours old, if it hasn’t expired and the account still grants the basic permission. A token nobody refreshes for 60 days expires for good, and the account has to log in again.

That’s why an automation tool sometimes asks you to reconnect. The token may have expired, you may have removed the app, or the account may no longer be a professional one. Until you reconnect, the tool can’t act for the account, so comments and DMs go unanswered.

Tip: Before typing your password, check the address bar. The real page is on instagram.com or facebook.com; a look-alike login form on any other address is phishing.

What the permissions mean

The approval screen lists what the app is asking for, and it’s worth reading. Business Login for Instagram uses permissions such as these:

PermissionWhat it lets the app do
instagram_business_basicSee the account’s basic profile details, such as its username, and its media
instagram_business_manage_commentsRead comments on the account’s posts and reply to them
instagram_business_manage_messagesRead and send the account’s DMs
instagram_business_content_publishPublish posts to the account

Facebook Pages connect through Facebook Login, the same idea on facebook.com, with Page permissions such as pages_messaging for Messenger. Whichever you’re approving, compare the list with the job. A comment and DM tool needs comments and messages; if it also wants to publish posts, it should say why.

An example

A photographer clicks Connect Instagram in a booking app, lands on instagram.com, sees it wants only her profile, comments and messages, and approves. The app can now answer DMs for her studio account without ever learning her password.

Questions people ask

Does the app see my Instagram password?

No. You type it on Instagram’s own page, and the app only receives a token with the permissions you approved. If an app asks for your Instagram password in a form of its own, that isn’t OAuth, and it’s a reason to stop.

Why does an app keep asking me to reconnect Instagram?

Most often its access has run out. A long-lived Instagram token lasts 60 days and has to be refreshed by the app; if that doesn’t happen, or you removed the app’s access, it needs a new token, and logging in again provides one.

How do I remove an app’s access to my Instagram account?

Instagram’s settings include a list of the apps and websites connected to your account, and removing an app there ends its access. It’s tidy to disconnect inside the app as well, so it stops trying to use the old token.

Is OAuth the same as two-factor authentication?

No. Two-factor authentication protects your own login with a second step, such as a code. OAuth decides what another app may do once you’ve logged in. They work together: if two-factor is on, you complete it on Instagram’s page during the OAuth flow.

Can I connect a personal Instagram account?

Not to tools that handle DMs or comments. Business Login for Instagram is built for professional accounts, Business or Creator, and Meta’s messaging API doesn’t work with personal ones. Switching to a professional account is free in your settings.

Sources

Related terms

More terms

Comment-to-DM, without writing code

DMFast runs on Meta’s official APIs: someone comments your keyword and gets a reply and a DM in seconds. It works from ChatGPT and Claude too. Free plan, no card.

Start free