What Exactly is an API?

Currently, no third-party tools can automatically post scheduled content to your Instagram profile. Truth is, it’s not the tools’ fault; Instagram doesn’t allow any tool the functionality to post directly to Instagram because of its limited API.

Social media tools like Socialtap work because social media platforms (like Instagram) have APIs (application programming interfaces).

An app like Instagram doesn’t want to show you everything that’s going on under its hood — so it provides an API that responds only to the requests it allows. A tool like Socialtap can send a request to Instagram: for example, it can request that Instagram provide the number of likes you received on your most recent Instagram post. Instagram’s API receives that request, and delivers to Socialtap the number of likes you received. Socialtap’s Reports feature visualizes the answer for you.


A wise social media manager is security minded

If you’re taking risks with your personal Instagram account, then the risk is yours (and your family’s if family photos are involved). However, if you’re managing social media for a business, you have responsibility for a company’s assets.

For you agencies and social media managers, the risks are even higher. A choice that goes against security and ethical best practices could result in a bad performance review at best and getting fired at worst.

It’s not worth risking your job just to post directly to Instagram.

Great social media managers are as mindful of security as they are of content. If you are hiring a community manager or social media manager, consider asking candidates such security-minded questions as:

  • Where do you plan to share your company logins?
  • How often do you do a check up on connected apps?

For the latter question, a social media manager should regularly review what apps have access to the Instagram account’s information.  To see what apps are connected and revoke access to apps you no longer use, login to your Instagram account on the web and select “Edit Profile,” then select “Authorized Applications.” Review the list of apps and what permissions they have.

The risk of using third-party apps that claim to post  directly to Instagram

There are some apps that have reverse-engineered the Instagram API so that they can automatically post directly to Instagram for users. You might think this is a clever way to get around the posting issue, but it is in direct violation of Instagram’s Platform Policy, which states, “Don’t reverse engineer the Instagram APIs or any of Instagram’s apps.”

You’re taking a huge risk by using a third-party software that reverse engineers the Instagram API so that you can schedule content that automatically posts. When you use an app that attempts to post to Instagram in ways that are not authorized, you may experience one or more of the following consequences:

1. Deleted content

Your published media could be deleted from Instagram. This has happened to many users.

2. Banned account

Instagram can ban or delete your account for violating Instagram’s terms and policies.

3. Security breach

You may lose access to your account or it may be hacked. Keep security in mind when you use an app by a developer you don’t know and who is not an official Instagram partner.

No matter how reliable the platform or how fine-tuned your security practices are, there is still a risk. For example, even the social scheduling tool Buffer experienced a security breach. If established companies with security teams can still experience security issues, then a third-party tool that uses APIs inappropriately and doesn’t use best security practices is even more vulnerable.

Would you post your Instagram login and password to a public webpage or a forum? Of course not! By providing them to a company you don’t know and is probably headquartered in a country you’ve never been to, you’re potentially doing that.

Why increase that risk?

These apps require you to give them your login credentials, like your password. No third-party app should ask you for your password directly. It should redirect to Instagram. For example, when you try to add an Instagram profile to your Socialtap account, Socialtap redirects you to Instagram.com, where you login directly to Instagram and allow Socialtap access as a third-party app. Socialtap is not provided with your password.

This means no one has your login info but you. 

4. A guilty conscience

For some social media managers, this is also an ethical choice. A social media platform is offering an API with limited functionality because the company’s values are focused on “keeping it real” on Instagram and avoiding mass automation. Do you really want to use shady apps to go against the values of the social network you rely on to promote your business?

Do you still feel that the benefits outweigh the risks of using a third party scheduled post tool for Instagram? Let us know in the comments!