# Which of the requested features the official APIs support

Read on 2026-09-14.

No official API opens a conversation with a creator who has not interacted first. Instagram states that conversations begin when an Instagram user sends a message to your app user. Private Replies and the human_agent tag exist inside that rule: they answer someone who has already commented or written, and neither is a licence to start commercial outreach.

Read directly on Meta for Developers, TikTok for Developers, the TikTok API for Business portal and the official help centres. Every line carries the URL it came from. Anything that could not be read on an official page says so, and names the source it did come from.

---

## Where each feature runs

Four values, and only these four: **Internal to the CRM**, **API, conditional**, **Human entry**, **Not included**.

| # | Feature | Where it runs | API and permission | What a person does | Doc |
|---|---|---|---|---|---|
| 1 | Import and organise a list of creators | Human entry | The import touches no API: a spreadsheet or a list of handles is Bearvana's own data. Enrichment of an Instagram professional account is possible through Business Discovery on the Facebook Login setup, with instagram_basic, instagram_manage_insights and pages_read_engagement. TikTok returns nothing about a creator who has not authorised the app. | Supplies the list and the exact handles, settles the look-alike accounts, and enters what no API returns. | https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-user/business_discovery/ |
| 2 | Manage several authorised brand profiles | Internal to the CRM | One stored authorisation per Bearvana account, obtained through Business Login for Instagram. The CRM holds the profiles, the roles and the assignment; the authorisation is what the platform contributes. | An administrator of each Bearvana account passes the OAuth flow and switches on Allow Access to Messages. | https://developers.facebook.com/docs/instagram-platform/overview/ |
| 3 | Personalised outreach drafts for human review | Internal to the CRM | Writing, storing, reviewing and approving a draft happens in the CRM and touches no API. Sending the first message is not something an API does: no official API opens a conversation with a creator who has not interacted first. | Reads the draft, approves it, sends it through the route the creator publishes, then records that send. | https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/messaging-api/ |
| 4 | Track conversations, replies, follow-ups and campaign status | Human entry | The record is what a person enters: channel, date of the send, replies, status. On a connected Instagram account the messages webhook and the Conversations API can add real reply events, with instagram_business_basic and instagram_business_manage_messages. | Records each send and each reply, including the ones that happen off platform. | https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/conversations-api |
| 5 | Reminders and assignment to team members | Internal to the CRM | No platform API is involved. Reminders, due dates, assignment and roles are scheduled tasks in the application. | Sets the rules, owns the queue, and closes what is done. | https://developers.facebook.com/docs/development/maintaining-data-access/data-protection-assessment/ |
| 6 | Surface a creator's recent public content for review | API, conditional | On a connected account: Business Discovery media, Hashtag Search with the Instagram Public Content Access feature, plus tags and mentions of Bearvana. oEmbed embeds a post whose URL you already have; it does not find one and no longer identifies its author. | Supplies the URL worth following, and judges whether what comes back is relevant. | https://developers.facebook.com/docs/instagram-platform/instagram-api-with-facebook-login/hashtag-search/ |
| 7 | Reporting on outreach activity and reply rates | Internal to the CRM | The reporting counts what the CRM holds: drafts written, drafts approved, sends a person recorded, replies recorded, time to reply. On a connected Instagram account, reply events can be added to that count. | Records the sends, so that the numbers describe what happened rather than what the API happened to see. | https://developers.facebook.com/docs/instagram-platform/webhooks |
| 8 | Integration with the official APIs where permitted | API, conditional | Instagram Creator Marketplace API for discovery and creator insights, with instagram_creator_marketplace_discovery in Advanced Access and an eligible brand account. Marketing API Partnership Ads for amplifying content once a collaboration exists. On TikTok, the Organic API and TikTok One exist on the API for Business portal. | Decides which integrations are worth their approval cost, and passes App Review with Bearvana's own business details. | https://developers.facebook.com/docs/instagram-platform/instagram-api-with-facebook-login/creator-marketplace/ |
| 9 | TikTok direct messaging | Not included | TikTok messaging is not included in the proposed scope; availability and account eligibility to be confirmed with TikTok. | Sends and records TikTok contacts by hand, as on any channel without an integration. | https://ads.tiktok.com/help/article/marketing-api?lang=en |

## How each channel is tracked

- **Email.** Tracked from what a person records in the CRM: channel, date, and the reply when it comes. No mailbox integration is in this scope.
- **Instagram.** Tracked from what a person records. Once Bearvana connects an account it owns and the app is approved, replies can also arrive as events, and the CRM matches them to the record.
- **TikTok.** Tracked from what a person records. TikTok messaging is not included in the proposed scope; availability and account eligibility to be confirmed with TikTok.

## The authorisation setup chosen

**Instagram API with Instagram Login, Business Login for Instagram, on Instagram professional accounts that Bearvana owns.**

It needs no linked Facebook Page for messaging and reporting, and it keeps the scope to accounts Bearvana controls. Where discovery of other professional accounts is wanted, that part runs on the Facebook Login setup instead, because Business Discovery and Hashtag Search are documented there.

What Bearvana does: An administrator of each Bearvana account passes the OAuth flow, and switches on Instagram Settings, Messages and story replies, Message controls, Connected Tools, Allow Access to Messages.

Source: https://developers.facebook.com/docs/instagram-platform/overview/

---

## Feature by feature

### 1. Import and organise a list of creators

**Human entry.** Source: https://developers.facebook.com/docs/instagram-platform/instagram-graph-api/reference/ig-user/business_discovery/

The import touches no API: a spreadsheet or a list of handles is Bearvana's own data. Enrichment of an Instagram professional account is possible through Business Discovery on the Facebook Login setup, with instagram_basic, instagram_manage_insights and pages_read_engagement. TikTok returns nothing about a creator who has not authorised the app.

- Business Discovery returns professional accounts only, and no data for age-gated professional accounts.
- No official endpoint returns a follower list, an email address or a phone number, on either platform, at any access level.
- TikTok /v2/user/info/ needs a token the creator granted through OAuth. Source: https://developers.tiktok.com/docs/en/tiktok-api-v2-get-user-info

> Not verified on an official page: The guide page and the reference page do not list the same permissions for Business Discovery. The reference cites instagram_basic, instagram_manage_insights and pages_read_engagement; the Instagram Public Content Access feature was historically required too. The single list is not verified on an official page, so App Review would be asked for both.

### 2. Manage several authorised brand profiles

**Internal to the CRM.** Source: https://developers.facebook.com/docs/instagram-platform/overview/

One stored authorisation per Bearvana account, obtained through Business Login for Instagram. The CRM holds the profiles, the roles and the assignment; the authorisation is what the platform contributes.

- No connection on an account's behalf without an administrator of that account passing the OAuth flow.
- For Instagram messaging, an authorisation alone is not enough: the Allow Access to Messages toggle is a gesture only the account holder can perform. Source: https://developers.facebook.com/docs/messenger-platform/instagram/get-started
- On TikTok, approval for a scope grants nothing on its own: each user must also authorise the app for that scope. Source: https://developers.tiktok.com/doc/scopes-overview/

### 3. Personalised outreach drafts for human review

**Internal to the CRM.** Source: https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/messaging-api/

Writing, storing, reviewing and approving a draft happens in the CRM and touches no API. Sending the first message is not something an API does: no official API opens a conversation with a creator who has not interacted first.

- Private Replies answer a person who has commented on the account's own post, one message, within 7 days. They are a reply mechanism, not an outreach channel. Source: https://developers.facebook.com/docs/instagram-platform/private-replies/
- The human_agent tag extends the time to reply inside a conversation the other person opened. It does not open one. Source: https://developers.facebook.com/docs/features-reference/human-agent
- One-time Notifications, News Messaging and Sponsored Messages are not available for the Instagram Messaging API.
- Group messaging is not supported: one conversation per person.

### 4. Track conversations, replies, follow-ups and campaign status

**Human entry.** Source: https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/conversations-api

The record is what a person enters: channel, date of the send, replies, status. On a connected Instagram account the messages webhook and the Conversations API can add real reply events, with instagram_business_basic and instagram_business_manage_messages.

- The 24 hour window is the time an account has to reply after someone writes to it. It is not a duration of visibility, and it never authorises a first approach.
- The Conversations API returns details for the 20 most recent messages in a conversation. That is a limit on retrieving history, not on how long a conversation may run.
- Conversations in the Requests folder with no activity for 30 days are not returned.
- Conversations API is rate limited to 2 calls per second per professional account. Source: https://developers.facebook.com/docs/graph-api/overview/rate-limiting/

### 5. Reminders and assignment to team members

**Internal to the CRM.** Source: https://developers.facebook.com/docs/development/maintaining-data-access/data-protection-assessment/

No platform API is involved. Reminders, due dates, assignment and roles are scheduled tasks in the application.

- One obligation rather than a technical limit: an app that stores data obtained from Instagram falls inside Meta's annual Data Protection Assessment, with 60 days to answer.

### 6. Surface a creator's recent public content for review

**API, conditional.** Source: https://developers.facebook.com/docs/instagram-platform/instagram-api-with-facebook-login/hashtag-search/

On a connected account: Business Discovery media, Hashtag Search with the Instagram Public Content Access feature, plus tags and mentions of Bearvana. oEmbed embeds a post whose URL you already have; it does not find one and no longer identifies its author.

- Hashtag Search allows 30 unique hashtags per Instagram account over a rolling 7 day period. No Story hashtags, no emoji in the query.
- The Instagram Public Content Access feature needs App Review and business verification. Source: https://developers.facebook.com/docs/features-reference/instagram-public-content-access
- oEmbed stopped returning author_name, author_url and thumbnail_url on 3 Nov 2025. It embeds a known URL, it does not discover or attribute. Source: https://developers.facebook.com/docs/features-reference/oembed-read
- The recent videos of a TikTok creator who has not authorised the app are not available. Source: https://developers.tiktok.com/doc/display-api-overview/

### 7. Reporting on outreach activity and reply rates

**Internal to the CRM.** Source: https://developers.facebook.com/docs/instagram-platform/webhooks

The reporting counts what the CRM holds: drafts written, drafts approved, sends a person recorded, replies recorded, time to reply. On a connected Instagram account, reply events can be added to that count.

- A message typed by hand in an app is invisible to every API. If nobody records it, no rate can include it.
- A response rate is computed only from sends that were recorded. With no recorded sends there is no rate, and none is displayed.
- Audience demographics of a third party creator are not available through the standard APIs.

### 8. Integration with the official APIs where permitted

**API, conditional.** Source: https://developers.facebook.com/docs/instagram-platform/instagram-api-with-facebook-login/creator-marketplace/

Instagram Creator Marketplace API for discovery and creator insights, with instagram_creator_marketplace_discovery in Advanced Access and an eligible brand account. Marketing API Partnership Ads for amplifying content once a collaboration exists. On TikTok, the Organic API and TikTok One exist on the API for Business portal.

- The Creator Marketplace API discovers and evaluates creators. It sends no message and no project invitation; invitations happen in the Meta interface.
- It requires the brand to be eligible for the creator marketplace and to accept its terms. That is tested on Bearvana's own account, not on paper.
- The Organic API and TikTok One exist. Access for Bearvana is not obtained, and nothing here assumes it.

> Not verified on an official page: Whether Bearvana's accounts are eligible for the Instagram creator marketplace, and what approval level TikTok One requires, are not verified on an official page from here. Both are checked on Bearvana's own accounts before either is scoped.

### 9. TikTok direct messaging

**Not included.** Source: https://ads.tiktok.com/help/article/marketing-api?lang=en

TikTok messaging is not included in the proposed scope; availability and account eligibility to be confirmed with TikTok.

- A Business Messaging API exists on the TikTok API for Business portal. Whether a given account can use it, and on what terms, is a question for TikTok.
- Statements circulating about a reply window, a message cap and regional availability come from messaging partners rather than a TikTok page readable from here. They are not treated as facts and are not built on.

> Not verified on an official page: Availability, regional eligibility and the messaging limits are not verified on an official TikTok page. They would be confirmed with TikTok before anything depends on them.

---

## Five ways this goes wrong before the first line of code

### 1. Mistaking the Instagram Basic Display API for the current one

Meta announced on 4 Sep 2024 that the Instagram Basic Display API would stop being available on 4 December 2024. It is replaced by the Instagram API with Facebook Login or with Instagram Login. A quote built on the old API is out of date before it is written.

Source: https://developers.facebook.com/blog/post/2024/09/04/update-on-instagram-basic-display-api/

### 2. Believing a stored authorisation is enough for Instagram messaging

The right permissions must clear App Review, and one gesture stays outside the developer's control: each account switches on Instagram Settings, Messages and story replies, Message controls, Connected Tools, Allow Access to Messages. Without it the code is correct and nothing arrives.

Source: https://developers.facebook.com/docs/messenger-platform/instagram/get-started

### 3. Taking the Creator Marketplace for a contact channel

The API discovers and evaluates Instagram creators. It requires instagram_creator_marketplace_discovery in Advanced Access, an eligible brand account and acceptance of the marketplace terms. Invitations happen in the Meta interface, not through the API.

Source: https://developers.facebook.com/docs/instagram-platform/instagram-api-with-facebook-login/creator-marketplace/

### 4. Promising TikTok direct messaging

A Business Messaging API exists on the TikTok API for Business portal. Whether a given account can use it, and on what terms, has to be confirmed with TikTok. The figures that circulate about windows and message caps come from messaging partners, not from a TikTok page readable from here, so nothing in this scope depends on them.

Source: https://ads.tiktok.com/help/article/about-message-management-tools

### 5. Taking the TikTok Research API for a creator discovery tool

It returns real public data, which makes it tempting. Eligibility is closed: academic researchers at non-profit universities, independent of commercial interests. Creators, advertisers and commercial users are not eligible for access to the Research Tools.

Source: https://developers.tiktok.com/products/research-api

---

## Stack

| Piece | What it is for | Status |
|---|---|---|
| TypeScript and Next.js | One codebase for the interface and the server routes. This page is that stack. | Running on this page. |
| PostgreSQL | Creators, brand profiles, drafts, recorded sends, replies, reminders and the audit trail. One row per event, so the reporting counts events rather than guesses. | Read in the official documentation, not yet exercised. |
| Authentication and roles | Accounts for the team, with who may approve a draft and who may record a send kept apart from who may only read. | Read in the official documentation, not yet exercised. |
| Scheduled tasks | A server-side scheduler creates the follow-up reminder from a recorded send date, and raises what is overdue. No reminder exists before a send is recorded. | Read in the official documentation, not yet exercised. |
| API adapters and webhooks, server side | One adapter per platform behind a single internal interface, and a webhook endpoint for Instagram events on connected accounts. Authorisations stay on the server and never reach the browser. | Exercised against the real thing outside this page. |
| No automated browser | Nothing logs into an account, drives a session, or collects from a page. Data comes from what the team enters and from accounts Bearvana has connected. | Running on this page. |
| Ownership | The Meta app is registered to Bearvana with Bearvana's business verification, the hosting account is Bearvana's, and the database and its exports belong to Bearvana. Nothing is held on our side after handover. | Read in the official documentation, not yet exercised. |

## Scope, in two lots

### Lot 1. The CRM, usable with no external approval

- Creator records, imported from a list the team supplies, with a provenance and a date on every field.
- Several brand profiles, with roles and assignment.
- Drafts prepared for review, approval kept separate from sending, and a copy action that is never recorded as a send.
- Sends recorded by a person: channel, date, and who recorded it.
- Follow-up reminders created from the recorded send date, and an overdue queue.
- Replies recorded, and reporting that counts recorded events and shows no rate until sends exist.

### Lot 2. Integrations, limited to access that has been granted

- Instagram accounts Bearvana owns, connected through Business Login for Instagram.
- Instagram reply events arriving on the webhook and matching themselves to the record.
- Enrichment and recent public media for professional accounts, where the permissions are granted.
- Creator Marketplace discovery, if Bearvana's account is found eligible.
- Each item ships when its access is granted, and not before.

## Timeline

- **Lot 1.** Depends on nobody else. Starts on a list the team supplies.
- **App Review and business verification.** Runs on Meta's clock. Its own line on the plan, started early, never inside a development estimate.
- **Lot 2.** Each integration ships after its own access is granted. Nothing promised as connected by a fixed date.

No price appears in this file or on the page. Cost is a conversation, not a number on a public URL.

---

## What is easy to forget when costing this

- **App Review, per permission.** Every permission that touches another account goes through review, and no Meta page commits to a turnaround. Any schedule has to keep that as its own line. Source: https://developers.facebook.com/docs/permissions
- **Business verification.** Required for advanced level access to permissions since 1 Feb 2023, with Bearvana's own business details. Source: https://developers.facebook.com/docs/development/release/business-verification
- **Annual Data Protection Assessment.** Comes back every year, with 60 days to answer. Source: https://developers.facebook.com/docs/development/maintaining-data-access/data-protection-assessment/
- **Automated collection.** Meta's terms forbid automated collection without prior written permission. Nothing in this scope collects that way; the creator record is entered by a person or comes from a connected account. Source: https://www.facebook.com/legal/automated_data_collection_terms

---

Written by The AI Pipe on 14 Sep 2026 from the official documentation. No account was connected while preparing it.
