An API token is the key that lets your code or an AI assistant act on one Inrō account through the public API and MCP server. You either copy a private token or approve an app through OAuth.
An API token is the key that lets your script or AI assistant use Inrō's Instagram automation API on one account. It travels in the Authorization: Bearer header of each request. Inrō accepts two kinds, a private token you copy and an OAuth token an app receives when you sign in.
Open the account menu, go to API & MCP and find the Private API card. Inrō creates the token with your account, so there is nothing to generate. Copy it into your script and send it with each call to the Inrō API for developers.
If the token leaks, click Regenerate. The old token stops working immediately, and every tool that used it needs the new one.
With OAuth you never copy a token. The app sends you to an Inrō sign-in screen, you choose which account to authorize, and Inrō gives the app its own token for that account. Claude and ChatGPT connect to the Inrō MCP server for AI assistants this way.
Pick by who should hold the key:
Each token acts on one Inrō account, through the public API and the MCP server. Treat both like a password, and only approve apps you trust.
Neither token reaches a second account. A request that names another account is refused.
For what an assistant does once connected, see MCP server. For the events Instagram sends to Inrō on its own, see Instagram webhook. Other terms are in the Inrō automation glossary, and the tools Inrō connects to are on Inrō integrations.
Attract more leads, target them with DM marketing, and automate all your interactions on Instagram!

