Home
/
Glossary
/
API token

API token

Definition

An API token is the key that lets your code or an AI assistant act on one Inrō account through the public API and MCP server. You either copy a private token or approve an app through OAuth.

An API token is the key that lets your script or AI assistant use Inrō's Instagram automation API on one account. It travels in the Authorization: Bearer header of each request. Inrō accepts two kinds, a private token you copy and an OAuth token an app receives when you sign in.

Where do you find your private API token?

Open the account menu, go to API & MCP and find the Private API card. Inrō creates the token with your account, so there is nothing to generate. Copy it into your script and send it with each call to the Inrō API for developers.

If the token leaks, click Regenerate. The old token stops working immediately, and every tool that used it needs the new one.

How is OAuth different from a private token?

With OAuth you never copy a token. The app sends you to an Inrō sign-in screen, you choose which account to authorize, and Inrō gives the app its own token for that account. Claude and ChatGPT connect to the Inrō MCP server for AI assistants this way.

Pick by who should hold the key:

  • Private token: for your own scripts, and for tools that cannot sign in with OAuth. Anyone holding it can act on your account.
  • OAuth token: for apps and assistants that support sign-in. You approve each app yourself, and it only gets a token for the account you picked.

What can each token reach?

Each token acts on one Inrō account, through the public API and the MCP server. Treat both like a password, and only approve apps you trust.

Neither token reaches a second account. A request that names another account is refused.

When is a valid token still refused?

  • You are on the Free plan. The Free plan has no API access, so the server refuses the request and asks you to upgrade.
  • The account is suspended. Requests are refused whatever the token.
  • You regenerated the private token. Only the newest one works.

For what an assistant does once connected, see MCP server. For the events Instagram sends to Inrō on its own, see Instagram webhook. Other terms are in the Inrō automation glossary, and the tools Inrō connects to are on Inrō integrations.

Try Inrō and leverage the power of Instagram marketing automation

Attract more leads, target them with DM marketing, and automate all your interactions on Instagram!

Free plan available
Meta Tech Provider
Setup in 5 minutes