Instagram Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Instagram Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Demo
A Model Context Protocol server that wraps the Instagram Graph API so Claude (or any MCP client) can read, publish, comment, DM, and pull insights from an Instagram Business or Creator account.
24 tools across five capability areas — profile/media, publishing, comments, DMs, and insights — built on FastMCP + httpx.
pip install instagram-mcpOr with uv:
uv tool install instagram-mcpYou need an Instagram account switched to Business or Creator, linked to a Facebook Page. In the app dashboard, walk through Instagram → API setup with Facebook login → Step 1: Generate access tokens and link your account.
Generate a token with these scopes (in Graph API Explorer or the Instagram API setup page):
instagram_basicinstagram_content_publishinstagram_manage_commentsinstagram_manage_messagesinstagram_manage_insightspages_show_listpages_read_engagementbusiness_managementWhile your app is in Development mode, only accounts in your app's Roles list (admins/developers/testers) can authenticate. That's fine for personal use. For other users, you need App Review with Advanced Access.
The fastest way: run the bundled helper.
instagram-mcp-get-tokenIt will ask for your short-lived user token + app ID/secret, exchange it for a long-lived user token, list your linked IG accounts, and write .env for you.
Manual alternative:
# Exchange short-lived user token → long-lived (~60 days)
curl -G "https://graph.facebook.com/v21.0/oauth/access_token" \
--data-urlencode "grant_type=fb_exchange_token" \
--data-urlencode "client_id=YOUR_APP_ID" \
--data-urlencode "client_secret=YOUR_APP_SECRET" \
--data-urlencode "fb_exchange_token=SHORT_LIVED_TOKEN"
# Find your Pages and their IG accounts
curl -G "https://graph.facebook.com/v21.0/me/accounts" \
--data-urlencode "fields=name,instagram_business_account,access_token" \
--data-urlencode "access_token=LONG_LIVED_USER_TOKEN"Use the Page's access_token (never expires) and the instagram_business_account.id of the linked IG account.
.envIG_USER_ID=17841446575432302
IG_ACCESS_TOKEN=EAAxxxxxxxxxxxxxxxxxxx
IG_GRAPH_VERSION=v21.0
IG_GRAPH_HOST=graph.facebook.comSet IG_GRAPH_HOST=graph.instagram.com if your token came from the Instagram Login path instead of Facebook Login.
Edit ~/.config/Claude/claude_desktop_config.json (Linux) or ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
{
"mcpServers": {
"instagram": {
"command": "instagram-mcp",
"env": {
"IG_USER_ID": "17841446575432302",
"IG_ACCESS_TOKEN": "EAAxxxxxxxxxxxxxxxxxxx"
}
}
}
}Restart Claude Desktop. You should see 24 tools under the instagram server.
| Tool | What it does |
|---|---|
get_my_profile | Profile info: bio, followers, media count, etc. |
list_my_media | One page of recent posts |
list_all_media | Auto-paginate through all media |
get_media | Fetch a single media item |
list_tagged_media | Posts the account is tagged in |
list_stories | Currently-live stories (24h window) |
| Tool | What it does |
|---|---|
search_hashtag | Resolve a #tag to its ID |
hashtag_top_media | Top-ranked posts for a hashtag |
hashtag_recent_media | Recent posts for a hashtag (24h window) |
| Tool | What it does |
|---|---|
publish_image | Single image post from a public URL |
publish_reel | Reel (waits for container processing) |
publish_story | Image or video story |
publish_carousel | 2-10 item carousel |
get_publish_limit | Show 24h publish quota usage |
| Tool | What it does |
|---|---|
list_comments | Top-level comments + nested replies |
get_comment_replies | Replies under a specific comment |
reply_to_comment | Post a reply |
hide_comment | Hide / unhide |
delete_comment | Delete a comment you own |
| Tool | What it does |
|---|---|
list_conversations | DM conversations |
get_conversation | Messages in a conversation |
send_dm | Send a DM (optionally with a message_tag) |
| Tool | What it does |
|---|---|
get_account_insights | Account-level metrics with optional metric_type |
get_media_insights | Per-media insights |
your images/videos on a publicly accessible URL first.
user-initiated window. Pass a message_tag (e.g. HUMAN_AGENT) to send outside that window. Tags require Meta approval.
in 2024): views, accounts_engaged, total_interactions, profile_views, likes, comments, shares, saves. reach and follower_count don't.
error: truealong with status, message, code, subcode, and fbtrace_id in the response — that's the Graph API error, not a Python traceback.
git clone https://github.com/AleemHaider/instagram-mcp
cd instagram-mcp
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
pytestMIT — see LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.