Instagram automation rules in 2026: what is allowed and what is not

Instagram allows automation that runs through Meta's official APIs and forbids automation that works by logging in as you. That single split decides almost every question in this post. Answering a comment with a DM, replying to a story reply, hiding a comment and scheduling a post all have documented endpoints. Following, unfollowing, liking and messaging strangers have none, so any tool offering them is doing something else.
There is no grey area in the middle. Either a feature has a Meta endpoint and a published rate limit, or it does not exist in the API and the tool providing it is holding a logged-in session on your account.
The rule underneath all the others
Instagram's Terms of Use put it in one clause, and it covers more than people expect because of the last eleven words.
You can't attempt to create accounts or access or collect information in unauthorised ways. This includes creating accounts or accessing or collecting information in an automated way without our express permission, regardless of whether such automated access or collection is undertaken while logged in to an Instagram account.
Instagram Terms of Use, read 25 September 2026
Express permission is what an approved API app holds. It asked Meta for named permissions, a reviewer watched each one being used, and Meta issued a token. Being logged in as yourself does not give a script that permission, which is why a browser automation tool using your own credentials is still covered by the clause.
The messaging side has an equally blunt rule, stated in Meta's own Instagram messaging documentation: only after an Instagram user has sent your Instagram professional account a message can your app send a message to that user. Every allowed DM automation on this page begins with somebody contacting you.
What is allowed
Each row here has a documented endpoint behind it. The limits are Meta's published numbers, gathered in one table further down.
| What you want to automate | The mechanism | The documented limit |
|---|---|---|
| DM somebody who commented a keyword | Private reply to a comment on a post or reel | 750 per hour per account, 7 days to reply, one per comment |
| DM somebody who commented on a Live | Private reply to an Instagram Live comment | 100 calls per second per account |
| Reply to a DM somebody sent you | Send API on an open conversation | 24 hours from their message |
| Reply to a story reply | A story reply arrives as a direct message | 24 hours from their reply |
| Reply when somebody mentions you in their story | The mention lands as a message in the inbox | 24 hours, and the story media must not be cached |
| Offer tap-to-answer buttons in a DM | Quick replies on the Send API | Inside the same 24 hour window |
| Reply publicly to a comment | Comment endpoints on your own media | Business use case rate limits |
| Hide, unhide or delete a comment | Comment moderation endpoints | Business use case rate limits |
| Schedule a post, reel, carousel or story | Content Publishing API | 100 API-published posts per rolling 24 hours |
| Read reach and engagement figures | Insights endpoints | Business use case rate limits |
| Detect posts that mention your account | Mention identification on media | Business use case rate limits |
| Search public hashtagged media | Hashtag Search API | Platform rate limits, not business use case limits |
What is not allowed
The useful column here is the last one. When a feature has no endpoint, the tool has to get the job done some other way, and that other way is what carries the risk.
| Behaviour | Why it is not allowed | What a tool doing it must be using |
|---|---|---|
| Follow and unfollow automation | No documented Instagram permission covers following | A logged-in session in a browser or phone emulator |
| Auto-liking posts | No documented permission covers liking | The same session |
| Auto-viewing stories | No documented permission covers story views | The same session |
| Mass DMs to accounts that never messaged you | Meta only permits a message after the user messages you first | A bot, because the API refuses to open the conversation |
| Scraping followers, followings or hashtag results at volume | The Terms of Use prohibit automated collection without permission | A logged-in session, sometimes behind proxies |
| Commenting at volume on other accounts' posts | Meta's comment endpoints cover comments on your own media | A logged-in session |
| Using the human agent tag for bot replies after 24 hours | The tag is documented for a human responding manually | The API, used against its stated purpose |
| Buying followers, likes or comments | The engagement comes from accounts that are not your audience | A panel with access to many compromised accounts |
| Storing story media a mention gave you access to | Meta's story mention docs forbid caching the media on your server | An app ignoring the documentation it built against |
| Running several accounts from one panel using passwords | Every account shares one server-side login | One session, and one breach away from all of them |
Every documented limit in one place
These are Meta's numbers, not estimates from other blog posts. The 200 DMs per hour figure repeated across this niche does not appear anywhere in Meta's rate limiting documentation for private replies.
| Limit | Value | Applies to |
|---|---|---|
| Private replies to post and reel comments | 750 calls per hour | Per Instagram professional account |
| Private replies to Live comments | 100 calls per second | Per Instagram professional account |
| Private reply window | 7 days | From when the comment was posted |
| Private replies per comment | One | Enforced by Meta, per comment |
| Standard messaging window | 24 hours | From the user's message to your account |
| Human agent tag window | 7 days | A human replying manually, not a bot |
| Send API, text and links | 100 calls per second | Per Instagram professional account |
| Send API, audio and video | 10 calls per second | Per Instagram professional account |
| Conversations API | 2 calls per second | Per Instagram professional account |
| Requests folder visibility | 30 days | Inactive requests stop being returned by the API |
| Content publishing | 100 posts per 24 hours | A rolling window; a carousel counts as one post |
| Business use case calls | 4800 × impressions per 24 hours | Instagram Platform calls other than messaging |
The last row is the one that surprises people. Most Instagram Platform calls outside messaging are budgeted against your impressions in the previous day, so a bigger account gets a bigger allowance. That is why a tool can feel fast on a busy account and hit limits on a new one.
The 24-hour window is a consent rule
The messaging window gets written up as an inconvenience, and it is worth understanding what it is doing. Meta gives your app 24 hours to respond to a message an Instagram user sent you. After that the conversation closes and your app cannot reopen it. There is a human agent tag that extends the period to seven days, and Meta's policy describes it for a person replying manually when an issue cannot be resolved inside the standard window.
Read together with the rule that a business can only message somebody who messaged first, the window is the mechanism that stops the whole platform becoming a cold outreach channel. It is also why the follow-up sequences familiar from email do not translate. A three-touch drip over a week needs the recipient to keep replying, and if they stop replying the window shuts.
The permissions behind the allowed list
Meta names Instagram permissions, and you see the names on the screen where you approve a connection. Two sets exist depending on how a tool connects, and the scope names differ.
| Business Login for Instagram | Facebook Login for Business | What it allows |
|---|---|---|
| instagram_business_basic | instagram_basic | Read the profile and media |
| instagram_business_manage_messages | instagram_manage_messages | Read and send direct messages |
| instagram_business_manage_comments | instagram_manage_comments | Read, reply to, hide and delete comments |
| instagram_business_manage_insights | instagram_manage_insights | Read reach and engagement figures |
| instagram_business_content_publish | instagram_content_publish | Publish media, which is how scheduling works |
There is no row for following, liking or story views, because no such permission is documented. That absence is the single most useful thing on this page when you are reading a sales site.
How to read a feature list against this
Take any tool's features page and sort every bullet into one of the two big tables above. Three outcomes are possible.
- Everything lands in the allowed table. The tool is doing what Meta built, and your remaining questions are about price, reliability and how it behaves at the cap.
- Something lands in the not-allowed table. Whatever else is true, part of that product runs a session on your account, and connecting it connects that too.
- Something lands in neither, usually described in a way that avoids naming a mechanism. Ask which endpoint it uses. A vendor building on the documentation can answer in one sentence.
Sort features by mechanism rather than by how safe they sound. Comment-to-DM, story reply automation, comment moderation and scheduled posting all have endpoints and published limits. Follower growth, auto-liking and cold DMs have none.
Questions people ask about this
- What Instagram automation is allowed in 2026?
- Anything with a documented Meta endpoint. That includes sending a DM in answer to a comment on a post, reel or Live, replying to direct messages and story replies inside the 24 hour window, replying to and hiding or deleting comments on your own posts, scheduling posts, reels, carousels and stories through the Content Publishing API, and reading insights. Each has a published rate limit you can check.
- Is follow and unfollow automation against Instagram's rules?
- There is no documented Instagram API permission for following, unfollowing, liking or viewing stories, so a tool offering those features is not using the API for them. It works by holding a logged-in session on your account, which Instagram's Terms of Use cover in the clause about automated access without express permission. This is the category most action blocks come from.
- Can an Instagram automation tool send DMs to people who have not messaged me?
- Not through the API. Meta's Instagram messaging documentation states that only after an Instagram user has sent your professional account a message can your app send a message to that user. A comment counts as a starting point through the separate private reply route, which is why comment-to-DM works. Cold DMs to a purchased list require a tool that logs in as you.
- What is the Instagram 24-hour messaging window?
- Meta gives an app 24 hours to respond to a message an Instagram user sent to the connected professional account. After that the conversation closes and the app cannot reopen it. A human agent tag extends the period to seven days, and Meta's policy documents it for a person replying manually rather than for automated messages. The separate private reply window for comments is seven days.
- How many automated DMs can an Instagram account send per hour?
- For private replies to comments on posts and reels, Meta documents 750 calls per hour per Instagram professional account. Private replies to Instagram Live comments are documented at 100 calls per second. The 200 per hour figure repeated widely across this niche does not appear in Meta's rate limiting documentation for these calls.