Integration5 min read

Meta permissions required for comment moderation tools

Which Meta OAuth permissions a comment moderation tool needs, what each one is for, and what stays private.

By CommentProtect Team · Published June 24, 2026

Before you connect any tool to your Facebook and Instagram accounts, you should understand what it is asking for and why. A comment moderation tool works through official Meta OAuth and the Graph API, and the permissions it requests map directly to the features you use.

Why these permissions exist

  • Reading comments on your Pages and Instagram Business Accounts, so they can appear in your inbox.
  • Managing those comments: hiding, replying to, and deleting them on your behalf.
  • Reading basic Page and Instagram account metadata so the tool knows what you can connect.

What connection looks like

You authorize with your Facebook profile, approve the requested permissions, and then choose which Pages and Instagram Business Accounts to protect. Access tokens are stored encrypted, and you can revoke access from Meta at any time.

What it does not do

A focused moderation tool does not need your password, does not post to your timeline unprompted, and starts processing new comments after connection. It does not reach back into your comment history.

Put this into practice

Request controlled access when you are ready to evaluate CommentProtect with your Meta workflow.