A plain-language overview of the access we'll request, what each permission lets us do, who on your team should connect, and what to expect during setup.
Before you start
Instagram connections work through Meta's Instagram API with Facebook Login, which has three prerequisites:
Your Instagram account is a professional account (Business or Creator) — personal accounts can't be connected.
It's linked to a Facebook Page.
The person connecting can perform tasks on that Page (they manage it).
If any of these is missing, the account won't appear in the pickers during setup.
What to expect
Connecting takes a couple of minutes. When you add the Instagram integration in Medialake, you'll be redirected to the official Facebook login screen, then walked through three steps:
Choose the Facebook Pages you want to share — we recommend "Opt in to current Pages only" and selecting just the Page(s) linked to the Instagram accounts in scope.
Choose the Instagram accounts — same recommendation: current accounts only, selected individually.
Review the access request — the permissions below, in Meta's own words.
You approve everything yourself and can revoke access at any time. We never see or store your password — the login happens entirely on Meta's site, and once you approve you're returned to Medialake.
We follow the principle of least privilege: we only request the access the work actually needs — we never post, edit, reply, or delete anything on your Instagram account. All data is read through Meta's official Instagram Platform (Graph API v25.0).
You Medialake Meta│ connect source │ ││────────────────────────▶│ ││ redirect to Meta │ ││◀────────────────────────│ ││ log in & grant access │ ││──────────────────────────────────────────────────▶││ redirect with code │ ││◀──────────────────────────────────────────────────││ │ exchange code ││ │────────────────────────▶││ │ long-lived token ││ │◀────────────────────────││ source authorized │ ││◀────────────────────────│ │
Verifying it's really us
On the consent screen, check that the app requesting access is:
App name: MedialakeAI
App ID:
714235083542447Developer / business: Medialake AI (verified by Meta)
If the app name doesn't match, stop and contact us. Never approve a Meta connection request you weren't expecting.
Who should do the connecting
The connection is tied to the person who logs in (authorized with a Meta User access token), not just your business. Please have it done by someone who:
Has access to the Facebook Page(s) linked to the Instagram account(s) — either directly (a role on the Page) or through your Business portfolio (a business member with the Page assigned; business admins see all portfolio Pages). That's how Meta discovers which Instagram accounts can be shared.
Is a permanent member of your team. If the person who authorized us leaves your company or loses their Page or business access, the connection expires and someone else will need to reconnect.
Their personal Facebook login is used only to authorize the connection — we get access to your Instagram professional account's content and insights, never their personal profile, friends, or messages.
Limiting what we can access
Two layers keep this narrow. First, the asset pickers: choosing "current only" and selecting specific Businesses, Pages, and Instagram accounts means we can never see anything you didn't tick — accounts added to your business later are excluded unless you reconnect and add them. Second, we inherit only the connecting person's own access — Pages they don't manage (directly or through their Business portfolio) never even appear in the picker.
You choose what we sync
The asset pickers during consent are the selection: only the Instagram accounts you opt in ever become visible to Medialake. After you're redirected back to Medialake, you choose which of those accounts to actively sync.
The permissions we request
On the review screen ("Review MedialakeAI's access request") you'll see these four, in Meta's wording:
Permission (scope) | Appears on the consent screen as | How we use it |
"Access profile and posts from the selected Instagram account" | READ ONLY — read the account's profile info and media | |
"Access insights for the Instagram account" | READ ONLY — read per-post performance metrics. Despite the name, we only read insights | |
"Show a list of the Pages you manage" | READ ONLY — list your Pages to find the linked Instagram accounts | |
"Manage your business" | READ ONLY (see note) — makes Instagram accounts linked to Pages you manage through your Business portfolio available in the picker |
All four are read-only in effect — nothing on your Instagram account, Facebook Pages, or Business Manager can be created, edited, replied to, or deleted by us. Meta's own description of every permission is in its Permissions Reference.
>Why business_management is here: Instagram accounts are discovered through their linked Facebook Pages, and many of those Pages aren't managed through direct personal roles — they're owned by a Business portfolio, with your team's access flowing through the business. Without this permission, the linked Instagram accounts can't be offered in the picker. That's its only job here. Meta defines the permission broadly — its official description reads "allows your app to read and write with the Business Manager API" — and the consent screen's info box describes that ceiling, not our usage: we make no changes to your Business Manager, its people, or its assets — ever. The asset pickers still rule: we only see the Businesses, Pages, and Instagram accounts you opt in.
Verified by Meta
Our app doesn't get these permissions just by asking. Each one was individually approved through Meta's App Review, where we justify and demonstrate exactly how it's used; Medialake AI is a Meta-verified business; and every year Meta requires us to recertify how each permission is used through its Data Use Checkup. Unused or unjustified permissions are revoked by Meta.
What we can't see or do
Regardless of which permissions you grant, we cannot:
See or store your password, or log in as you
Post, edit, reply to, or delete anything on Instagram or your Pages
Change anything in your Business Manager — people, asset assignments, settings
Access personal Instagram accounts, direct messages, or the connecting person's personal profile
See Businesses, Pages, or Instagram accounts you didn't opt in during consent
Staying connected
Meta access tokens expire periodically (roughly every 60 days) and Meta does not provide refresh tokens, so an expired connection can't be renewed in the background. Tokens are also revoked early if the authorizing person changes their Facebook password or resets two-factor authentication. If that happens, just reconnect from the Instagram integration in Medialake — this is normal and takes a minute.
Revoking access
You're in control at any time. To remove MedialakeAI:
Business Settings → Integrations → Connected apps → select MedialakeAI → Remove, or
Your personal Facebook Settings → Business Integrations → remove MedialakeAI
Revoking immediately stops all access; no action needed on our side.
Troubleshooting
The most common issues:
An Instagram account doesn't appear in the picker — one of the prerequisites is missing: the account isn't a professional account, isn't linked to a Facebook Page, or the connecting person doesn't manage that Page.
The connection succeeds but no accounts or content appear in Medialake — permissions alone aren't enough: Meta also needs you to opt in the Pages and the Instagram accounts on the two picker screens during consent. If either step was skipped or nothing was ticked, we can see nothing. Reconnect and select them.
Otherwise, issues typically relate to organization settings restricting third-party OAuth apps. If you get stuck, contact [email protected] and we'll walk you through it.
Further reading (Meta documentation)
Permissions Reference — what each scope grants
Instagram API with Facebook Login — the connection model and its prerequisites
Facebook Login for Business — the login flow Medialake uses
Access tokens & long-lived tokens — token lifetime and why there are no refresh tokens
You can review or withdraw any of these permissions at any time in Meta Business Settings.
