Blog / Official vs third-party

Instagram Public Data API: Access Limits

By the InScrape API team · Published 2026-08-14 · 4 min read

A connected glass globe with a defined access boundary

Before you design a feature on Instagram data, you need to know exactly where the line is. Building on a field that turns out to be private means rewriting the feature; building on a field a vendor exaggerated means explaining to a customer why the number is wrong.

Here is the inventory, field by field.

Publicly readable

Everything below is visible to a logged-out visitor on a public account, which is what makes it available through a public data API.

Profile

Field Notes
handle, full_name Stable identity fields
follower_count The number, not the list — those are separate endpoints
following_count Same
media_count Total public posts
biography Full text with line breaks
external_url The one link in bio
is_verified, is_private, is_business Flags
category Business category where the account sets one
profile_pic_url Expires — mirror it if you need persistence

Posts and reels

Field Notes
shortcode, permalink Stable identifiers
caption Full text, hashtags and mentions included
like_count Public, unless the account hides likes
comment_count Public
play_count Reels only. Plays, not unique viewers
taken_at ISO 8601 timestamp
Media URLs Expiring CDN links

Lists

Comments with author, like count and timestamp. Follower and following lists on public accounts. Tagged posts, where the account has not restricted the tagged tab. Hashtag posts and totals. Account search results.

Not publicly readable

These require the account owner's authorisation through the official API. If a provider offers them for arbitrary accounts, they are estimating.

Field Why not
Reach Unique accounts that saw a post. Owner-only metric.
Impressions Total views including repeats. Owner-only.
Saves Never exposed publicly.
Shares Never exposed publicly.
Profile visits Owner-only.
Story viewers The list of who watched. Owner-only, and the one most often misrepresented.
Audience demographics Age, gender, location breakdowns. Owner-only.
Email and phone Only where published as a business contact. Never inferred.
Anything on a private account 200 with available profile details; billed at the endpoint rate.

The three fields providers misrepresent

Play count sold as views or reach. Play count is public and useful, but it counts plays, not unique viewers. Comparing it to a reach figure from Instagram's own analytics gives two different numbers, and your customer will notice.

Follower count sold as a followers API. A profile endpoint returning follower_count is not a followers API. If you need the identities — for audience overlap, lead generation or quality auditing — you need an endpoint that actually paginates the list, and it costs more to run. Check which one you are buying before you build the feature.

Engagement rate presented as a platform metric. Instagram does not publish an engagement rate. Every engagement rate you have ever seen is computed by someone from likes, comments and follower count, using a formula they chose. That is fine — just know it is a derived number and check the denominator, because "per follower" and "per view" produce very different answers.

What this means for common features

Influencer vetting. Fully buildable. Follower count, recent post engagement and a follower sample give you a real quality score. What you cannot show is reach — and you should say so rather than substituting play count silently.

Competitor tracking. Fully buildable, and better than what the competitor sees themselves in one respect: you can track them daily and keep the history, which their own analytics does not do beyond a rolling window.

Social listening. Fully buildable through comments, hashtag posts and tagged posts. The limitation is depth: reading every comment on a viral post costs real money, so cap depth and prioritise by engagement.

Story analytics. Partially buildable. You can capture stories while live, including link stickers. You cannot get viewers or exits, and no public API ever will.

Audience demographics. Not buildable from public data. Providers that offer it are inferring from a follower sample — which can be reasonable, if disclosed, and misleading if not.

Freshness is part of the contract

A public data API returns a snapshot. The question is how old that snapshot is, and whether the API tells you.

Every successful response here carries requested_at, so a four-hour-old follower count can be labelled as one in your own product. When you need it fresher, run the lookup on the schedule your product needs:

curl "https://api.socialscrape.dev/v1/instagram/profile?handle=natgeo" \
  -H "x-api-key: $INSCRAPE_KEY"

A provider that does not tell you how old a number is has made freshness your problem while charging you as though it were theirs.

The rule

Design features on the public column. Where you need something from the private column, that account has to connect through the official API — and the two can coexist in the same product.


More: Instagram API without login, Graph API vs scraping API, or the profile endpoint and followers endpoint.

Try it with 100 free credits.

No credit card, credits never expire, and failed requests are not charged.