Glossary

OAuth

OAuth is the standard that lets somebody grant an app limited access to their account without sharing a password. The person authorises on the platform's own login screen, and the app receives a scoped token instead of credentials.

Why it matters for creators

OAuth is the flow you have used a hundred times without naming it: the screen that appears when you connect an account, lists what the app is asking for, and returns you afterwards.

The important property is where you type your password, which is on Instagram's own page, not the app's. The tool never sees it, never stores it, and could not use it if it wanted to. What it receives is an access token scoped to the specific permissions shown on that screen.

This gives you a straightforward test for any tool asking to connect to your Instagram. If it hands you off to Instagram to log in, it is doing this correctly. If it asks for your Instagram username and password in its own form, it is not using OAuth, which means it is not using the official Graph API either, and the account is at risk regardless of how the product looks.

Related terms

Full glossary →
Access tokenPermission scopeGraph API

Every term, A–Z

Full glossary →
Access tokenAPI rate limitApp ReviewBroadcast channelClick-through rateClose FriendsCold DMComment-to-DMConversationConversion rateCreator accountDM automationDM funnelDM requestDrip sequenceEmail captureEngagement baitEngagement rateFollow gateGeneric templateGraph APIIce breakersIGSIDImpressionsInstagram Business accountInstagram InsightsInstagram LoginKeyword triggerLead magnetLink in bioLink stickerMessaging windowMeta Tech ProviderOpt-inOpt-outPermission scopePostbackPrivate replyProfessional accountProfile visitsReachSaved repliesSavesStory replySuperfanTrigger rateUGCWebhookWelcome message
Get started

Turn your audience into a living

Connect Instagram, pick a post, and watch your first automation go live — in about three minutes.

Free forever — 1,000 DMs a month, no cardLive in minutesCancel anytime