FeaturesPricingBlogResourcesAboutContact
Sign inGet Started Free

Understanding Connection Permissions

What CollectSocials asks for when you connect Facebook or Instagram — and why

Last Updated: August 12, 2026

When you connect a Facebook Page or Instagram Business account, Meta shows you a list of permissions. Some of them have names like manage or business_management that can sound alarming. They are not.

CollectSocials is read-only. We use these permissions to display the content you choose — posts, photos, videos, comments, and hashtag results — inside the feeds you embed on your website. We never post, edit, delete, reply, or change any settings on your accounts.

What we do: read your selected posts and reviews and show them in your widgets.

What we never do: publish content, send messages or replies, modify your profile, or change Page or Business settings.


Why some Instagram features sign in with Facebook

Meta requires Instagram hashtag, tagged, and mention features to go through a Facebook Page that is linked to your Instagram Business account. Because of this, you sign in with Facebook for those source types — even though the content you are collecting is from Instagram.

Stories currently use the same Facebook route. That is our own setting rather than a Meta rule, and we will move stories to the direct Instagram sign-in once we have confirmed it works there.

During sign-in you may see a screen mentioning access to your Business. That is because Meta places Instagram-linked Pages inside a Business Portfolio. On that screen, choosing “Opt in to current Businesses only” is perfectly fine — it grants read access to the Page you are connecting and nothing more.

A plain Instagram account feed does not use this flow. It signs in directly with Instagram, so no Facebook account or Page is involved at all. You need an Instagram Business or Creator account; personal accounts are not supported by Instagram's API.

Signing in with Facebook remains available for account feeds if you prefer it, and it is useful when you manage several Instagram accounts across different Pages and want to pick from a list. Either route displays the same posts.


The permissions we request, in plain English

Here is every permission you may be asked to grant, and the single reason we need it. You will never see all of them at once: each sign-in asks only for what the source type you are adding actually uses.

  • pages_show_list — Lets us show you the list of Facebook Pages you manage so you can pick which one to connect.
  • pages_read_engagement — Lets us read public engagement on your Page’s posts (like and comment counts) so your widget can display them accurately.
  • pages_read_user_content — Lets us read the posts and content on your Page so we can show them in your feed.
  • pages_manage_metadata — Despite the name, we use this only to set up the webhook subscription that tells us when new content (such as mentions) arrives, so your feed stays current. We do not change your Page’s metadata.
  • instagram_business_basic — Used when you sign in with Instagram directly, without Facebook. It lets us read the profile and media (posts, photos, videos) of the Instagram Business or Creator account you log in as, so we can show them in your feed. It is the only permission that sign-in asks for.
  • instagram_basic — The equivalent permission on the Facebook sign-in route. It lets us read your Instagram Business profile and its media (posts, photos, videos) to display in your feed.
  • instagram_manage_comments — Despite the name, we use this only to read comments and tagged/mention content so it can appear in your widget. We never write, reply to, hide, or delete comments.
  • business_management — Lets us read the Page-and-Instagram link inside your Business Portfolio so hashtag, tagged, and mention features can find the right account. We do not manage your business.

“Manage” permissions are read-only in our usage

Meta groups many capabilities under broad permission names. A permission like instagram_manage_comments or pages_manage_metadata can technically allow writing — but a permission only does what the app actually calls. CollectSocials calls only the read and subscription endpoints needed to fetch and display your content. We do not call any endpoint that creates, edits, hides, or deletes anything on your accounts. In short: the names say “manage,” but our usage is strictly read-only.


Revoking access at any time

You stay in control. You can disconnect an account from inside CollectSocials, or revoke access directly from Meta at any time:

  • From CollectSocials: go to your connections page and remove the Facebook or Instagram connection. We delete the stored access tokens for it.
  • From Facebook: Settings & Privacy → Settings → Business integrations (or Apps and Websites) → find CollectSocials → Remove.
  • From Instagram: Settings → Apps and Websites → find CollectSocials → Remove.

Once access is revoked, we can no longer read your content. To also remove the content we have already cached, see our Data Deletion Instructions.


Questions about permissions?

If anything here is unclear, email us at support@collectsocials.com. For how we store and protect your data, see our Privacy Policy.