ScavioScavio
Pricing
Tools
Sign InsGet Startedg
Blog
instagraminstagram-apioauthsocial-databasic-display-api

Instagram API Without OAuth: What Actually Needs Meta Login in 2026

Only owned-account metrics need Meta's OAuth chain. Public Instagram profile and post data needs none of it, and Scavio returns it as JSON from a username.

August 19, 2026
12 min read
Try Scavio FreePricing

50 free credits · no credit card

Owned-account metrics are the only thing that needs Meta login. Everything public — profiles, posts, comments, hashtags — is readable with no OAuth chain, no app review and no Facebook Page, and Scavio's /api/v1/instagram/profile returns it as JSON from a username alone. Meta switched off the Basic Display API on 4 December 2024, and the replacement it pushed everyone onto is where the 60-day token treadmill starts. If you are only reading public data, you can skip that treadmill entirely.

If you are three days into Meta's login flow and still not holding a working token, stop and answer one question first: are you pulling data for accounts that authorize you, or public data about accounts that never will?

That single question decides whether you need any of it. The Graph API and its OAuth chain are mandatory for owned-account insights, the private metrics only the account holder can see. Public profile and post data is a different problem with a different answer, and a lot of people grind through app review before realising most of what they wanted sat on the public side the whole time.

Does Instagram support OAuth?

Yes, and that is the part people underestimate. It is not one login. A working Instagram Graph integration walks a chain: Facebook Login, then a Business Login permission grant, then the Facebook Page, then the Instagram professional account connected to that Page, and only then the access token you actually make calls with. Each hop has its own token type and its own expiry, and the docs for each hop live in a different place.

The common experience is losing an entire day just working out which APIs are needed and which token belongs where, with the official documentation as the hardest part of the job. Parts of it are occasionally wrong, and things break when Meta ships changelog updates.

None of that is a reason to avoid the Graph API if you need what it returns. It is a reason to be certain you need it.

What happened to the Instagram Basic Display API

Meta announced the shutdown on 4 September 2024 and gave 90 days. On 4 December 2024 the Basic Display API stopped serving, and every integration built on it went dark. Not loudly: the typical failure is a feed component that renders an empty container with no console error, so the site looks fine to the deploy pipeline and broken to whoever visits it. The people who found out first were usually clients, not developers.

Basic Display was the easy path. It authenticated a personal account, returned that account's own media, and asked almost nothing of you. Nothing that replaced it is that cheap. There are now two supported doors, and picking the wrong one costs a week:

  • Instagram API with Instagram Login — you log in with the Instagram account directly, no Facebook Page in the chain. This is the closest thing to a Basic Display replacement, and it is what most plugin vendors migrated to.
  • Instagram API with Facebook Login — the full Graph path, requiring a professional account connected to a Facebook Page. Necessary for the deeper business endpoints, heavier to set up.

Both are OAuth. Both hand you an access token. And that token is where the ongoing cost lives.

The 60-day treadmill nobody prices in

Long-lived Instagram tokens expire after 60 days. You can refresh one before it lapses, but a refresh is an action that has to actually happen: a job that runs, succeeds, and stores the new value. Let it lapse and refreshing is no longer available to you, because re-authorization means a human logging into that account again.

Per site that is roughly six mandatory refresh events a year. The arithmetic gets unpleasant once you run more than one:

Bar chart of mandatory Instagram token refreshes per year: 1 client site needs 6, 3 sites need 18, 6 sites need 36, 12 sites need 73, 25 sites need 152. Reading the same profiles as public data requires none.

Six client sites is thirty-six deadlines a year, each one a silent single point of failure, and every one of them is unbillable work. Plugins that advertise automatic refresh do mostly work, but "mostly" is carrying weight there — the refresh runs on the site's own cron, which means it fails exactly when the site is already having a bad week.

The important thing is that this cost is attached to authenticating as the account. It is not the price of Instagram data in general. If what you actually need is a public profile and its recent posts, no token exists in the design, so there is nothing to expire.

Is there a public Instagram API?

Not an official one. Meta retired the old public Instagram API years ago, and Basic Display, which was the last low-friction door, closed in December 2024. But public profile and post data is publicly rendered, and reading it does not involve OAuth, an app review, or a Facebook Page.

What is available without any login:

  • Profile fields: username, full name, follower and following counts, media count, bio, external URL, verified and private flags
  • Post fields: shortcode, media type, like and comment counts, timestamp, caption, media URLs
  • Public comment threads, hashtag and user search, public reels and tagged posts

That covers most competitor research, creator vetting, campaign tracking, and lead-enrichment use cases. It does not cover anything private, and no vendor can sell you private data without the account's consent.

Is there a free Instagram API?

Meta's Graph API has no per-call fee, so it is "free" in the sense that the cost is your engineering time and the app review process. For public data, the honest answer is that you are choosing between maintaining a collection layer yourself or paying someone per call.

The self-hosted route is not free either. The recurring cost is not writing the scraper, it is the week Instagram changes a layout, your parser dies quietly, and nobody notices until someone asks why the numbers went flat. That is the line item that never makes it into the build-versus-buy spreadsheet.

Evaluating a managed public-data vendor

Teams weighing a managed provider against building in-house usually evaluate on four axes: reliability, field coverage, operational effort, and vendor dependence. Those are the right axes. Here is what actually separates vendors on each.

Test the failure cases before the happy path. Request a private account, a deleted account, and an account that never existed. Some APIs return HTTP 200 with an empty or status-flagged body rather than a 4xx, which means a naive integration cheerfully stores nulls and bills you for it. You want to know that behavior on day one, not after a backfill. Check whether failed lookups are billed, too, because several providers charge for them.

Check how long media URLs live. Instagram serves images and video from a signed CDN, and those links expire in hours. A response that hands you image_versions2 or video_versions entries is giving you a URL with a clock on it. If you are persisting media, you have to fetch and rehost it during the same job. Storing the link is storing garbage.

Diff one real response against the documentation. Field coverage claims drift from actual payloads. Pull a live response, print the keys, and compare. This takes ten minutes and it is the single highest-value thing you can do during a trial.

Read the pricing model, not the price. Per-call, per-row, and bandwidth-based pricing produce wildly different bills for the same job. A 5,000-profile backfill can be twenty dollars or four hundred depending on which model you picked, and the per-unit headline number tells you nothing about which.

On vendor dependence: building in-house does not remove the dependency, it just moves it. You are still dependent on Instagram, only now without a support address. The real mitigation is architectural. Keep your own storage schema, normalize at the boundary, and never let a vendor's response shape leak into your database. Do that and switching providers is a day of work instead of a rewrite.

What a public lookup actually returns

A profile call against a managed API returns the public fields directly, no token dance:

Bash
curl -X POST https://api.scavio.dev/api/v1/instagram/profile \
  -H "Authorization: Bearer $SCAVIO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"username": "nasa"}'
JSON
{
  "data": {
    "pk": "528817151",
    "id": "528817151",
    "username": "nasa",
    "full_name": "NASA",
    "follower_count": 104407058,
    "following_count": 92,
    "media_count": 4888,
    "is_private": false,
    "is_verified": true,
    "biography": "Making the seemingly impossible, possible.",
    "external_url": "https://www.nasa.gov",
    "edge_followed_by": { "count": 104407058 }
  },
  "response_time": 687,
  "credits_used": 10
}

Eighteen fields, 687ms, ten credits. Note that pk is a string, not an integer, and that follower_count is duplicated inside edge_followed_by.count — an artifact of Instagram's own two lineages of profile payload.

Posts come back from /api/v1/instagram/user/posts with the fields you would expect to aggregate on: code (the shortcode), media_type, like_count, comment_count, play_count, and taken_at as a Unix timestamp. There are 123 fields per item. caption is an object rather than a plain string, which is the kind of thing you only learn by pulling a real response rather than reading a field list.

Two things about that endpoint are worth knowing before you build on it. The items are nested at data.data.items, not data.items. And the count parameter is a request, not a promise — asking for 3 returned 12, so page your loop off pagination_token and the length of what you got back, never off the number you asked for.

Where our own API behaves badly

Three warts, because you will hit them and it is cheaper to read about them than to debug them.

A username that does not exist returns HTTP 200 and bills you. Not a 404:

JSON
{
  "data": {
    "status": false,
    "errorMessage": "The requested resource does not exist. Please check the input parameters and verify manually (post, video, comment, user, etc.).",
    "attempts": "1"
  },
  "response_time": 4633,
  "credits_used": 10
}

A caller doing data.get("follower_count", 0) records that account as having zero followers and is confidently wrong at scale. Key your guard on payload presence, not on the status code.

The profile response has two shapes. Most calls return the flat 18-field object above. Occasionally the same request for the same username comes back as a single data key wrapping a much larger nested object, with the values under data.data.about and friends instead. It happened once in eight calls while writing this, on an account that returned the flat shape three times immediately afterwards, so it is not per-account and not something you can detect from the input. Normalize on the way in:

Python
def profile(payload):
    d = payload["data"]
    if set(d.keys()) == {"data"}:      # nested lineage
        d = d["data"]
    if not d.get("username"):          # billed-junk 200
        raise LookupError(d.get("errorMessage", "no profile in payload"))
    return d

Good behaviour worth stating too: omitting both username and user_id returns a clean HTTP 400 with Either username or user_id is required and costs nothing. Validation errors are free; upstream misses are not.

Frequently asked questions

Is the Instagram API free?

Meta charges no per-call fee, so the Graph API is free in cash and expensive in time: app review, a Facebook Page, and a token you refresh six times a year per account. For public data there is no free official door at all since Basic Display closed, so the real choice is maintaining a parser yourself or paying per call. Scavio charges 10 credits per profile lookup, at $0.01 a credit.

What replaced the Instagram Basic Display API?

Two things, depending on what you need. Instagram API with Instagram Login authenticates the Instagram account directly and is the nearest replacement for personal feed use. Instagram API with Facebook Login is the full Graph path and requires a professional account connected to a Facebook Page. Both are OAuth, and both issue a token that expires in 60 days.

Do I need OAuth to read a public Instagram profile?

No. Public profile and post data is publicly rendered and carries no authorization requirement. OAuth exists to prove you are the account holder, which only matters for the private metrics. Scavio's /api/v1/instagram/profile takes a username and returns the public fields with one API key.

How long does an Instagram access token last?

Long-lived tokens last 60 days. You can refresh one while it is still valid, but if it lapses, refreshing is no longer possible and someone has to log in again. That is roughly six mandatory refresh jobs per account per year, which is where multi-site setups get expensive.

Can I get Instagram follower counts without an API key from Meta?

Yes. Follower and following counts, media count, bio, and verified status are all public profile fields. They need no Meta app, no review, and no token. A managed endpoint returns them as JSON from the username.

Why did my Instagram feed plugin stop working?

Almost certainly Basic Display. It stopped serving on 4 December 2024, and the usual symptom is a blank feed with no front-end error. The fix is migrating to Instagram API with Instagram Login and a per-site long-lived token, or dropping the auth requirement entirely by reading the same posts as public data.

The decision, compressed

Owned-account metrics mean OAuth, and there is no way around it. Public data means no OAuth, and your real choice is maintaining a parser or paying per call.

If it is the second one, evaluate on failure behavior, media URL lifetime, payload-versus-docs drift, and pricing model. Those four questions separate vendors far more reliably than a feature table does.

What you now own, and what it costs to hand over

If you migrated off Basic Display, look at what is actually on your plate. A Meta developer app per client. A long-lived token per site, each with its own 60-day clock. A refresh job you have to trust, running on infrastructure you do not watch, whose failure mode is a blank feed nobody reports. Six sites is thirty-six of those deadlines a year. None of it is billable, and none of it makes the feed any better than it was in November 2024.

If the data you are rendering is public — a profile, its recent posts, the counts under them — Scavio absorbs that whole layer. There is no token in the design, so there is nothing to expire, nothing to refresh, and no re-authorization email to send a client. When Instagram changes a payload shape it is our on-call, not your Saturday. What you keep is a single API key that does not rotate on a clock.

The price is per call: 10 credits for a profile lookup, 2 credits for a page of posts, at $0.01 per credit, with no monthly commitment. Six client sites refreshed hourly, profile plus posts, is about 52,000 credits a month — roughly $520 if you genuinely need hourly. At the once-a-day refresh most brochure feeds actually need, the same six sites come to 2,160 credits, or about $21.60 a month.

Start with 50 free credits, no card required — enough to pull four full profiles and a page of posts for each, and check every field named above against your own client accounts before you decide.

Full request and response reference lives in the Instagram API docs, and the endpoint list with per-call credit costs is on the Instagram API page. If your project also needs the private metrics, you will still be writing the Graph integration, and this post does not change that.

Continue reading

amazonai-agents

Your Agent's Web Search Tool Cannot See the Price

11 min read
ebayebay-api

eBay Sold Listings Now Require a Login. What Can Price Research Use Instead?

12 min read
ScavioScavio

One scraper API for every social, search, e-commerce and real estate platform. Built for AI agents.

Product

  • Features
  • Pricing
  • Dashboard
  • Affiliates

Developers

  • Documentation
  • API Reference
  • Quickstart
  • MCP Integration
  • Python SDK

Alternatives

  • Tavily Alternative
  • SerpAPI Alternative
  • Firecrawl Alternative
  • Exa Alternative
  • Serper Alternative
  • Tavily vs Scavio
  • SerpAPI vs Scavio
  • All alternatives
  • Compare Scavio vs alternatives

Search APIs

  • Google Search API
  • Amazon Product API
  • YouTube API
  • Reddit API
  • Walmart Product API
  • TikTok API
  • Instagram API

Tools

  • All Tools

© 2026 Scavio. All rights reserved.

Featured on TAAFT
Terms of ServicePrivacy Policy