HookSend vs unofficial Instagram MCP servers: official Meta API, no password
HookSendreaches Instagram through Meta’s official API and never asks for your Instagram password, where several open-source Instagram MCP servers sign in with your username and password instead. Meta verified HOOKSEND SOFTWARE as a Tech Provider and reviewed every permission the app uses. Sources read on 30 September 2026.
The Instagram MCP servers on GitHub want my password. Will that get me banned?
Possibly, and Instagram is the one who says so. Instagram’s own help page about accounts restricted for data scraping lists giving a third-party app your username and password as one of the things that may have led to a restriction, alongside using a service to interact with Instagram in unauthorised ways. Instagram writes that in the conditional, and so does this page.
Nobody outside Meta can give you the odds, and the suspension rates quoted in vendor blog posts have no primary source behind them, so none appear here. What can be stated is what the rules say. Instagram’s Terms of Use forbid collecting or using other people’s login credentials, and forbid collecting information in an automated way without Instagram’s express permission. A server that takes your username and password and calls Instagram’s private endpoints is doing both by design, whatever the intention behind it.
The library most of these servers are built on is not shy about the trade either. instagrapi’s own maintainers put it in the territory of testing, research and controlled internal automation, point people at Instagram’s official APIs wherever those are enough for the job, and say automation built on the private one does not hold up well in production. Read on 30 September 2026, that is the most honest framing available, and it comes from the people who wrote the thing.
Does HookSend need my Instagram password?
No. There is no field for it anywhere in HookSend. You press connect, Instagram’s own authorisation screen opens, you approve it there, and Meta issues a token to HookSend. HookSend never sees, stores or transmits your Instagram password, never logs in as you, and never drives a browser pretending to be you.
One consequence is worth spelling out because it is the practical difference on the day you change your mind. Revoking access is a button: disconnect the account on Instagram’s side, or revoke the HookSend token in Settings, and it stops immediately with nothing else affected. With a password-based server, the only way to log it out is to change your Instagram password, which logs out every other thing you own at the same time.
The MCP token your AI client holds is a separate thing from the Instagram connection, and deliberately so. That token authenticates your AI client to HookSend; it has no power over your Instagram login. HookSend stores only a SHA-256 fingerprint of it, which is why it is shown once and cannot be read back.
What is the difference, line by line?
The HookSend column describes HookSend and is ours to state. The right-hand column describes the pattern shared by the password-based and cookie-based Instagram MCP servers we read on GitHub on 30 September 2026, plus what Instagram and Meta publish in the pages linked at the foot of this page. No single product is named in it, because the pattern is what matters and any one repository can change tomorrow. Two rows go against HookSend.
| What you are comparing | HookSend, on Meta’s official API | A password-based Instagram MCP server |
|---|---|---|
| How it signs in | You approve the connection on Instagram's own screen and Meta issues a token. HookSend never sees, stores or transmits your password. | An Instagram username and password in an environment variable, or session cookies copied out of a logged-in browser, held by whoever runs the server. |
| Whose API it calls | Meta's official Instagram Platform API, with every permission the app uses reviewed and approved by Meta. | Instagram's private app endpoints, reached through a reverse-engineered client. instagrapi's own maintainers point people at Instagram's official APIs wherever those are enough for the job, and say automation built on the private one does not hold up well in production. |
| What Instagram says about it | Meta publishes the API, the permissions and the limits, and verified HOOKSEND SOFTWARE as a Tech Provider before granting them. | Instagram's Terms of Use forbid collecting or using other people's login credentials, and forbid collecting information in an automated way without Instagram's express permission. |
| Account type it works on | An Instagram professional account only — a business or creator account. Meta requires it for this API, so a personal account cannot be connected at all. | A personal account too, which is the one clear advantage of the approach and the reason people reach for it. |
| Reading your inbox | Only the conversations Meta exposes to the connected account. HookSend cannot read an archive of everything ever sent to you, and cannot read a thread nobody has written in. | Typically the whole inbox the logged-in session can see, because the session is yours. Genuinely more than HookSend can do. |
| Following, unfollowing, liking | Not possible. Meta's API does not expose them, so HookSend publishes no tool for any of the three. | Usually possible, and usually the first thing that draws attention to an account. Instagram's Community Standards describe acting at very high frequencies, manually or automatically, as spam. |
| Turning it off | Revoke the HookSend token in Settings, or disconnect the account on Instagram's side. Either stops it immediately, and your password is not involved because it was never shared. | Change your Instagram password, which logs out the server along with everything else, and re-do every other login you have. |
Is there anything an unofficial Instagram MCP server can do that HookSend cannot?
Yes, four things, and pretending otherwise would be dishonest. HookSend cannot connect a personal Instagram account, because Meta requires a professional account for this API. HookSend cannot read an archive of your whole inbox. HookSend cannot follow, unfollow or like anything. And HookSend cannot start a conversation with somebody who has never messaged you.
Every one of those four is an absence in Meta’s API rather than a feature HookSend has chosen not to build, which is why no plan unlocks any of them and no amount of money will. If your use case genuinely needs a personal account, or needs to read messages from before the account was connected, HookSend is the wrong tool and this page is not going to pretend it is the right one.
What you get in exchange is the part that does not break. A token issued by Meta does not stop working because Instagram shipped a new app version, does not need a proxy, does not need a burner account, and does not make your login the thing standing between an automation and your audience. Instagram’s Community Standards describe acting at very high frequencies, manually or automatically, as spam; the official API paces HookSendinside Meta’s own published limits instead, and Meta publishes those limits so you can read them.
What is a Meta Tech Provider, and does it mean Meta checked HookSend?
Yes, twice over, and the two checks are separate. In Meta’s own framing on its Tech Providers documentation, a Tech Provider is a business Meta has verified as having a legitimate need to reach business data owned by other businesses. HOOKSEND SOFTWARE holds that verification, and it is what allows the permissions HookSend uses to be granted at all.
Meta’s documentation is explicit that this access verification is independent of App Review, so the honest statement is two statements. HOOKSEND SOFTWARE is a verified Tech Provider, and separately, Meta reviewed the HookSend app and approved every permission it uses. Anyone claiming one of those as shorthand for the other is describing half of a process, and it is worth asking any vendor which of the two they actually hold.
Neither approval is a promise about your account, and HookSend will not dress it up as one. What it means in practice is narrower and more useful: the permissions HookSend asks Meta for are ones Meta looked at and granted, the calls are documented, and if Meta changes a rule, HookSend finds out in the changelog rather than when an account stops answering.
How do I connect Instagram to an AI client without sharing my password?
Four steps, none of which involves typing an Instagram password anywhere. Switch the account to professional, approve the connection on Instagram’s own screen, create an MCP token in HookSend’s Settings, and give that token and one address to your AI client. The address is the same whichever client you use, and the 63 tools appear as soon as it connects.
Step 1
Switch the Instagram account to professional
Switch the account to a business or creator account in Instagram's own settings if it is not one already. Meta requires a professional account for this API, so a personal account cannot be connected at all.
Step 2
Connect it on Instagram's own screen
Sign up for HookSend and press connect. Instagram's own authorisation screen opens, you approve it there, and Meta issues a token to HookSend. You never type your Instagram password into HookSend, because there is nowhere to type it.
Step 3
Create an MCP token for your AI client
Open Settings and create an MCP token. The token is for your AI client, not for Instagram, and it is shown once because only a SHA-256 fingerprint of it is stored.
Step 4
Point your AI client at the connector
Add https://hooksend.app/api/mcp to Claude, Claude Code, Codex, Antigravity or any MCP client that accepts a token in a header, sending it as an Authorization header. Your AI now reaches Instagram through Meta's API, with no password anywhere in the chain. ChatGPT is its own case and has a page of its own.
Client-specific screens differ and the hub page carries them. If you are on ChatGPT or Codex, the two pages in the row below are written for those two clients and nothing else, because ChatGPT keeps its connectors behind a settings screen and Codex keeps its MCP servers in a TOML file, and the two sets of steps have nothing in common.
Where to check all of this yourself
Every rule attributed to Instagram or to Meta on this page comes from one of the five pages below, read on 30 September 2026. Meta can change any of them without telling us, so the source is worth more than this page is: if one of them now says something different, believe it and not us.
- Terms of Use
Instagram's rules for people using Instagram, including the clause about collecting other people's login credentials and the one about automated access.
- Why your account has been restricted for data scraping
Instagram's own list of things that may have led to a restriction. Giving a third-party app your username and password is one of them.
- Tech Providers
Meta's documentation for the status HookSend holds, and the one that explains why a verified Tech Provider can be granted access other apps cannot.
- Send a Private Reply to a Commenter
Meta's own page for the feature comment-to-DM is built on, including the one-message limit and the seven-day cut-off.
- Instagram Platform overview
Meta's requirement that the connected account is an Instagram professional account, and the published call limits.
Questions developers ask before they install one
- Will an Instagram MCP server that uses my password get my account banned?
- Possibly, and Instagram is the one who says so rather than us. Instagram's help page about accounts restricted for data scraping lists giving your username and password to a third-party app as one of the things that may have led to a restriction, alongside using a service to interact with Instagram in unauthorised ways. Instagram writes that in the conditional, and so do we: nobody outside Meta can tell you the odds, and the figures circulating in vendor blog posts have no primary source. We read that page on 30 September 2026.
- Does HookSend ever need my Instagram password?
- No. There is no field for it. You approve the connection on Instagram's own authorisation screen and Meta issues a token to HookSend, which is the whole of the exchange. HookSend never sees, stores or transmits your Instagram password, never logs in as you, and never drives a browser pretending to be you. If a tool asks for your Instagram password in order to automate your DMs, that is the thing Instagram's Terms of Use address when they forbid collecting and using other people's login credentials.
- What is a Meta Tech Provider?
- A business Meta has verified as having a legitimate need to reach business data owned by other businesses, in Meta's own framing on its Tech Providers documentation. HOOKSEND SOFTWARE holds that verification, which is what allows the permissions HookSend uses to be granted at all. Worth keeping the two approvals separate, because Meta does: Meta's documentation says access verification is independent of App Review, and HookSend has both — the Tech Provider verification and Meta's review and approval of every permission the app uses.
- Is instagrapi against Instagram's terms?
- Instagram's Terms of Use forbid collecting or using other people's login credentials and forbid collecting information in an automated way without Instagram's express permission, and a password-based client does both of those by design. Whether any particular use of a library breaches any particular clause is a question for Instagram and a lawyer, not for a competitor's website, so HookSend does not answer it. Worth noting instead that instagrapi's own maintainers point people at Instagram's official APIs wherever those are enough for the job.
- Can HookSend read all my Instagram DMs?
- No, and this is a real limit rather than a policy choice. HookSend sees the conversations Meta exposes to the connected professional account through the official API. HookSend cannot produce an archive of everything ever sent to the account, cannot read a thread nobody has written in, and cannot read messages belonging to a personal account, because Meta's API does not offer any of the three. A password-based server signed in as you generally can, which is the clearest thing it does that HookSend does not.
- What does the official API refuse to let HookSend do?
- Three limits belong to Meta and HookSend cannot buy its way out of any of them. Meta allows one private reply per comment, ever, across every campaign and every tool. Meta allows a reply inside a DM thread for 24 hours from that person's last message. Meta allows a comment reply only within 7 days of the comment. On top of those, HookSend cannot message somebody who has never messaged you, cannot follow or unfollow anyone, and cannot like a post.
- How many Instagram MCP servers actually use a password?
- Of 11 Instagram MCP servers we read on GitHub on 30 September 2026, 5 authenticated with an Instagram username and password or with session cookies copied from a browser, and 6 used an official Meta access token. That is a snapshot of what we could find and read on one day, not a census: most Instagram MCP servers are not tagged in a way that makes them findable, so the real population is larger and unknown. Check the README of anything you are about to install rather than trusting a count.
- Which plans include the HookSend MCP connector?
- The 15-day trial and every paid plan, from $3.50 a month (₹99 in India). The connector is not part of the Free plan, so a workspace that has finished its trial cannot connect an AI client until it upgrades. Everything the connector does counts against the same monthly DM allowance and AI credits as the dashboard.
Read next
Written 30 September 2026. The hub page at /mcp lists all 63 tools and the address to paste into your client.
Connect an Instagram account without handing over a password
15 days of every feature, no card, and the connector is included. Paid plans start at $3.50 a month (₹99 in India); the Free plan does not include the connector.
Start free