Compliance · 5 min read
What the Instagram Graph API Actually Lets a Tool Do
On this page
- Fact one: it is not your account, it is a token
- Fact two: you can only act on your own posts
- Fact three: there are two clocks, and they are different
- Fact four: Meta pushes, the tool does not poll
- Fact five: the limits are Meta's, not the vendor's
- Fact six: the ceiling on features is shared
- Two things to do with this
Every vendor on the official API is building inside the same box. They have different interfaces, different pricing and different opinions, but the walls do not move. Once you know where the walls are, most feature comparisons get shorter, and a few pitches stop being credible.
You do not need to write code to hold this map in your head. You need six facts.
Fact one: it is not your account, it is a token
You never hand an API tool your password. You go through Meta's consent screen, approve a specific set of permissions, and Meta issues the tool a token scoped to those permissions and to your account. Every reply that goes out afterwards is a request Meta receives, checks against that token, and either performs or refuses.

Two requirements come with this and are not negotiable: a professional account, and a Facebook Page linked to it. A vendor advertising that you can skip either is telling you it is not on the API.
Fact two: you can only act on your own posts
The API lets a tool read and reply to comments on posts and Reels belonging to the account that authorised it. Not a competitor's posts. Not a hashtag feed. Not a location tag.
This kills an entire category of pitch. "Reply to people commenting on your competitors' Reels" is not a permission that exists; anything doing it is driving the app while signed in as you. Same for bulk following, bulk liking, and anything described as "engagement" that involves accounts you have no relationship with.
Fact three: there are two clocks, and they are different
This is the single most useful thing on the page, and most buyers learn it the expensive way.

Comments: seven days. A comment can be replied to, publicly or by private reply into DM, within seven days of the comment. Older than that, nothing sends. An automation on an evergreen post keeps working for new comments and cannot resurrect old ones.
DMs: twenty-four hours. A message can be sent into a thread within twenty-four hours of that person's most recent message to you. The clock restarts on their message and nothing else. Not your reply, not a new post, not a follow.
That second rule is why "nurture sequence" and "broadcast" belong to a different product category. There is no drip campaign that survives the twenty-four hour window, because the person would have to message you before each step, which is not a sequence — it is a conversation. The comment-to-DM funnel works because the person's comment opens the door and their reply keeps it open.
Fact four: Meta pushes, the tool does not poll
When someone comments, Meta delivers an event to the vendor. The vendor's system reacts to that event. This matters to you for one practical reason: delivery is Meta's job, so "instant" is not a feature a vendor can promise, and duplicate delivery is normal — the same event can legitimately arrive twice. Ask how they handle that. A vendor who has not thought about it will send some people two identical replies on a busy day.
Fact five: the limits are Meta's, not the vendor's
There are ceilings on how much can be sent through the API, and they belong to the platform. A vendor cannot raise them and should not imply they can. What a good vendor does is stay under them deliberately — an hourly budget, a cooldown between replies to the same person, deduplication so nobody gets the same reply twice for the same trigger.
That is also the difference between a tool that survives a viral post and one that turns it into a thousand identical messages and a wave of spam reports. Compliance with the API is not the same as behaving well inside it.
The API is a licence to send. Whether sending was a good idea is a separate question that Meta does not answer for you.
Fact six: the ceiling on features is shared
Because everyone is inside the same box, here is what no compliant vendor can offer, whatever the pricing page says:
Not possible on the API
Possible, and the real product
Which means the honest comparison between vendors is not about capability. It is about what runs before a send, what happens when a check fails, whether refusals are recorded with a reason, what is metered, and whether the replies read like a person wrote them. The tools comparison is more useful once you have stopped comparing features that nobody can have.
Two things to do with this
When a feature list contains something from the left column, you have finished evaluating that vendor early, and you did it without a trial account.
When it does not, ask the six-fact questions in a single email: which permissions do you request and why, what happens to a nine-day-old comment, can you message someone who never messaged me, what happens on a duplicate event, how do you stay inside the rate limits, and where can I see a reply that was refused. Plain answers to those tell you more than a demo.
If you want the buyer's checklist version rather than the mechanism, the fifteen-minute audit is the same subject with a stopwatch on it.



