Blog

Before you connect Instagram to a marketing tool: what small businesses should check first

Connecting a social account to a scheduling or AI marketing tool hands it a key to post as you. After the Klue token breach and Meta's tighter publishing rules, here is what to check before you click Connect.

21 September 2026 · 8 min read

#instagram#social media tools#oauth#marketing automation#small business security
Original illustration of a social account key being handed to a marketing tool through a checked gate

Image: Original illustration by Vritul

Every marketing tool has the same button. Connect Instagram. Connect Facebook. Connect LinkedIn.

It takes ten seconds, and most business owners click it the way they accept cookie banners. Then the tool posts on their behalf for months, and nobody thinks about what was actually handed over.

We have spent the last month building the connections layer of Figlix, our own marketing system, against the real Meta, LinkedIn, Google, Pinterest, Reddit, and X developer platforms. It has been a useful education in what that button does, what it cannot do, and what a small business should check before pressing it.

What "connect" actually hands over

When you connect an account, you are not giving the tool your password. You are approving a list of permissions on a consent screen, and the platform hands the tool a token: a long string that lets it act as your account within those permissions, without you being present.

That token lives in the tool's database. On Facebook and Instagram it typically lasts about sixty days before it must be refreshed or you must reconnect. Between those points, the tool can do whatever the permissions allow, whenever it likes.

Read the consent screen properly, once. If a scheduling tool asks to manage your ads, read your Page's engagement data, and see your business portfolio, ask why. Some of those are legitimate. A tool that only schedules posts does not need ad management.

The permission list is the contract. Everything after it runs on trust.

Why the token is the thing attackers want

In June 2026, the competitive intelligence vendor Klue found an intruder inside the infrastructure that ran its integrations. The way in was a credential handed to a third party in 2022 for a pilot and never switched off. With it, the attacker pulled the tokens Klue held for its customers' Salesforce, HubSpot, Slack, and Google Drive connections, and used them to reach the data of nearly two hundred organisations.

Klue deactivated every customer's tokens the next day. Salesforce disabled the integration.

Nobody at those two hundred businesses did anything wrong. They connected a tool, and the tool was breached. The tokens did the rest.

That is the model to hold in your head for social media tools too. A scheduling tool that holds tokens for thousands of Instagram and Facebook accounts is holding thousands of keys. If it is compromised, every connected account is exposed at once, and the attacker can post as any of them.

The lesson is not to avoid connecting anything. It is that a connection is a decision about the vendor, not just the feature.

We covered the wider cyber picture for small businesses in what AI-driven cyber attacks mean for small business websites.

What Instagram will and will not let a tool do

Meta's rules for publishing through a tool are specific, and a lot of "my scheduler stopped working" tickets come down to them.

Only an Instagram professional account can publish through Meta's API. A personal account cannot, regardless of the tool. If your business posts from a personal profile, the first step is switching it to a professional account in Instagram's settings.

Under the Facebook Login route most business tools use, the Instagram account also has to be connected to a Facebook Page. That link is what lets the tool prove it is acting for your business rather than for you as a person.

Meta caps API publishing at 100 posts per account in any rolling 24-hour period. That is a lot for a small business, but a tool that fires a backlog at once can hit it.

Images have to be JPEG. Shopping tags are not supported through the API. Filters are not supported. Publishing is a two-step process where the tool uploads a container and then publishes it, which is why a scheduled post can occasionally show as pending.

And Instagram does not schedule anything itself. When a tool says "scheduled for Tuesday at 9am", the tool is holding your post and will call Meta at that moment. If the tool is down at 9am on Tuesday, or your token expired on Monday, nothing goes out.

The practical implication: check the tool's own reliability and its expiry warnings, not just its calendar view.

Why serious tools take months to connect properly

If a tool tells you a platform is "coming soon" or that it only offers copy-and-paste for a channel, that is not always a sign of an immature product. It may be a sign of an honest one.

To let the general public connect their accounts, a Meta app needs Advanced Access, which requires App Review for each permission and Business Verification of the company behind the app. In our experience each review round takes two to four weeks, and a request for changes restarts the clock. Meta asks for a screen recording of the flow as part of the submission.

LinkedIn is similar. A new app starts on a Development tier with tight limits, and must reach Standard tier within twelve months by submitting a screencast that shows a member approving access and posting.

None of this is visible to the business owner. All of it stands between a tool and a working Connect button. A vendor that has done the work has been verified as a real company and shown its flow to a reviewer. A vendor that skipped it either has a small trusted user list or is doing something it should not.

Ask which one.

Manual posting is still a valid channel

There is no rule that a tool must publish for you.

Some of the most reliable small business marketing workflows we see run on a tool preparing everything, including the copy, the image at the right dimensions, the hashtags, and a tracking link, with a person spending ten minutes pasting it in on a Monday morning. That workflow cannot leak a token, does not care about a 60-day expiry, and never posts at 3am because of a timezone bug.

We wrote about why we built Figlix that way first in AI can write your marketing. Approval is what makes it publishable. The same reasoning applies here: automate the preparation, and be deliberate about automating the button.

If you do connect, connect for a reason, and know what you gained.

Whose account is it, anyway?

The most common problem we see is not technical.

A staff member set up the Facebook Page in 2019 using their personal login. They connected the scheduler with that login. They left in 2024. The Page still works, the scheduler still posts, and nobody in the business can change either.

Before connecting anything:

  • Check who is an admin on the Facebook Page and the Instagram account. It should include an owner or a business-controlled login, not only an individual's personal account.
  • Use a business-owned identity to authorise tools, where the platform allows it, so the connection survives staff changes.
  • Keep two-factor authentication on for every account with admin access.
  • When someone with access leaves, reconnect the tools under a remaining admin and remove the old one. Do not assume the token stops working when their employment does.

What to ask a vendor before you click Connect

Most tools will not volunteer this. Most will answer if asked.

  1. Are tokens encrypted at rest, separately from the rest of the database?
  2. What exactly does the tool do with the connection? Publishing only, or reading followers, messages, insights?
  3. What happens when a token expires? Do I get warned before scheduled posts fail?
  4. Can I disconnect from inside the tool, and does that revoke the token on the platform side, not just hide it?
  5. Has the tool completed the platform's review and business verification, or is my account on a trusted-tester list?
  6. Has the vendor had a security incident, and how did they tell customers?
  7. Can I see which of my staff connected which account, and when?

A vendor that answers these clearly is a vendor that has thought about it.

What to do this month

If your business uses any tool that posts on its behalf:

  1. Open Instagram and Facebook's connected apps settings and remove anything you do not recognise or no longer use.
  2. Confirm the Instagram account is a professional account linked to a Facebook Page.
  3. Write down who holds admin access on each account and each tool.
  4. Reconnect any tool that was set up under a former staff member's login.
  5. Read the permission list your main tool holds, and ask them to reduce it if it is broader than what you use.
  6. Note when tokens expire, and who gets the warning email.
  7. Decide, per channel, whether automated publishing is worth having, or whether prepared-and-pasted is enough.

The takeaway

Connecting a social account to a marketing tool is a small action with a long tail. The tool ends up holding a key that lets it act as your business, and the platforms are steadily tightening the rules about who gets that key and what they may do with it.

Choose tools that have done the verification work, keep the permissions narrow, keep admin access with the business, and remember that a well-prepared post pasted in by a person is a perfectly good publishing method.

Read more about AI text scams and fake websites, where AI automation saves time before hiring more admin, or contact Vritul if you want your marketing tools, account access, and posting workflow reviewed.

Sources: Meta on Instagram content publishing, Meta on app access levels, Meta on Business Verification, LinkedIn on increasing API access tiers, The Hacker News on the Klue OAuth token breach.