The Instagram private reply API, explained without the jargon

A private reply is the one direct message Instagram allows you to send to somebody who has commented on your post, and the private reply API is the call that sends it. It is addressed to the comment rather than to the person, Meta allows exactly one per comment, and it has to go out within seven days of the comment being written.
The comment id is the whole point. Meta will not let an app message an Instagram user who has never messaged the account, so a private reply names the comment instead of the commenter. That is the loophole Meta wrote on purpose, and the only documented route from a comment to a DM.
What Meta means by a private reply
Meta's definition is narrow. A private reply is a single message to an Instagram user who commented on a professional account's post, ad, reel or live broadcast. You are answering one specific comment, and Instagram knows which one, because the comment's id is what you put in the request where a recipient's name would normally go.
Only one message can be sent to the Instagram user who commented.
Meta, Instagram private replies documentation, read 25 September 2026
Three things follow from that sentence, and each one shapes what a comment-to-DM campaign can honestly promise. You get one message, so the first DM has to carry the thing you offered. The permission is tied to a comment, so it expires when the comment's window does. And a deleted comment takes its private reply with it.
Why an ordinary DM cannot do this
Meta's Instagram messaging guide is blunt about who a business may message: only after an Instagram user has sent the professional account a message can the app send that user anything. A comment is not a message. Neither is a like, a follow or a story view. If you have somebody's username and nothing else, there is no documented call that opens a conversation with them, and any tool offering to do it is not using the API for that part.
The interesting part is that both calls go to the same endpoint. A private reply and an ordinary DM differ in one field, and the field decides whether Instagram accepts the message at all.
# A private reply: addressed to a comment
POST https://graph.instagram.com/v25.0/<IG_ACCOUNT_ID>/messages
Authorization: Bearer <access token>
{
"recipient": { "comment_id": "<COMMENT_ID>" },
"message": { "text": "Here's the link you asked for" }
}
# An ordinary DM: addressed to a person, and only allowed
# once that person has messaged you first
POST https://graph.instagram.com/v25.0/<IG_ACCOUNT_ID>/messages
Authorization: Bearer <access token>
{
"recipient": { "id": "<INSTAGRAM_SCOPED_USER_ID>" },
"message": { "text": "Just following up on that link" }
}That is the entire difference. Meta's Instagram messaging documentation gives the host as graph.instagram.com and the path as the account id followed by /messages, and v25.0 is the API version HookSend calls. You do not need to be able to write this. You need to recognise it, because a vendor who shows you something in this shape is describing the real endpoint, and one who cannot describe the call at all is usually describing something else.
| Private reply | Ordinary send | |
|---|---|---|
| Who it is addressed to | A comment id | A person's scoped user id |
| When you are allowed to send | Within 7 days of the comment | Within 24 hours of their last message |
| How many you get | One per comment, ever | As many as the window allows |
| Needs the person to have messaged first | No | Yes |
| Documented hourly cap | 750 per account | Governed by the Send API limits |
One DM per comment, and Meta enforces it
This is the rule people are most often surprised by, because it is invisible until two things collide. Try to send a second private reply to a comment that already has one and Meta refuses the call with an error saying the comment is invalid for a private reply. There is no retry that fixes it and no plan that raises it.
It bites in a specific way: when two campaigns match the same comment. Somebody duplicates a campaign to test a new message, or runs an any-post campaign alongside one aimed at a single reel, and both see the word LINK in the same comment. Only the first can deliver. A tool that does not know the rule sends the second call anyway, gets the refusal, and writes a failure into your log that you cannot do anything about.
Seven days, and why that is not the 24 hour window
Meta accepts a private reply up to seven days after the comment was created. Live broadcasts are the exception: a private reply to a live comment can only be sent while the broadcast is still running, which is why live campaigns behave differently from everything else.
Seven days sounds generous until you realise what it is for. It is not there so you can sit on a lead for a week. It is there so a spike does not have to be thrown away. A reel that collects three thousand keyword comments in an hour is over the hourly cap four times, and the extra comments can be answered later the same evening instead of being dropped.
| Rule | Value | Consequence |
|---|---|---|
| Messages per comment | 1 | The first DM has to carry the offer |
| Window after the comment | 7 days | A backlog can be cleared over hours, not seconds |
| Window on a live comment | The broadcast only | Nothing can be queued for after the live ends |
| Private replies per hour | 750 per account | Comments on posts and reels |
| Private replies to live comments | 100 per second | A different limit for a different call |
The seven day private reply window and Instagram's 24 hour messaging window are two different clocks measuring two different things. Seven days is how long you have to answer a comment. Twenty-four hours is how long you have to keep replying after somebody messages you.
What happens after the private reply lands
The private reply starts a conversation, and from that point the comment is irrelevant. If the person writes back, Instagram's standard messaging window opens and you can reply for the next 24 hours. If they never write back, you have had your one message.
Buttons are how most tools get round the one-message limit without breaking it. A private reply can carry a button template rather than plain text: an opening message with a tappable button under it. Meta's messaging policy counts tapping a call-to-action button in a message among the actions that open the standard window, and the tap arrives at the app as a postback webhook, so the second message is a reply to something the person did rather than a second private reply.
Templates have shapes to respect. HookSend trims a button template's body at 640 characters and a button label at 20, and sends at most three link buttons in one message. If your carefully written DM is arriving truncated, or a button label is losing its last word, that is usually why.
Four questions that tell you whether a tool uses this properly
None of these need a demo, and all four have a right answer that comes straight out of the documentation above.
- What happens when a post collects more keyword comments in an hour than the cap allows? Queue is the right answer, because the seven day window means there is time. Drop or skip means you lose the overflow from the post that actually worked.
- What happens when two of my campaigns match the same comment? The honest answer names the one-per-comment rule and says the second is skipped. A tool that claims both will send has not met the error yet.
- How long after a comment will it still send? Anything under seven days is leaving a window Meta gave you unused, and anything over seven days is a promise the API cannot keep.
- Can it DM people who liked the post, viewed the story or follow the account but never commented? No Meta permission allows that. An offer to do it means part of the product is not running on the API.
The fourth question is the one that separates the category. Everything else in this post is mechanics you can look up, and the mechanics are the same for every approved tool, because there is only one endpoint to call.
Questions people ask about this
- What is the Instagram private reply API?
- It is the part of Meta's Instagram messaging API that sends a direct message in answer to a comment. The request goes to the account's messages endpoint and names the comment's id as the recipient rather than a person, which is what allows it to reach somebody who has never messaged the account. Meta permits one private reply per comment, sent within seven days of the comment.
- How is a private reply different from sending a normal DM?
- Both go to the same endpoint and differ in one field. A private reply is addressed to a comment id and may be sent once, within seven days of that comment. An ordinary DM is addressed to a person's Instagram-scoped user id and is only allowed after that person has messaged the account, inside the 24 hour messaging window. Without a comment or a prior message, neither call is available.
- Can I send more than one DM per comment?
- No. Meta allows a single private reply per comment and refuses any further attempt with an error saying the comment is invalid for a private reply. A second message becomes possible only if the person replies to your DM or taps a button in it, which opens Instagram's 24 hour messaging window. No plan or tool raises this limit.
- How long after a comment can a private reply be sent?
- Seven days from when the comment was created, for comments on posts, reels and ads. Comments on an Instagram Live broadcast are the exception: a private reply to one can only be sent while the broadcast is still running. The seven day window is why a well-built tool queues a spike rather than dropping the comments it cannot answer immediately.
- Do I need a Business or Creator account to use private replies?
- Yes. Meta only allows private replies on an Instagram professional account, so a personal account has to be switched to Business or Creator first. Switching is free, takes about a minute in the Instagram app, and can be reversed. The app also needs Instagram permissions granted through Meta's own authorisation screen, never an Instagram password.