Overview
ScaleDM is an Instagram comment-to-DM connector for AI apps such as Muse and ChatGPT. When someone comments on a chosen post or Reel, ScaleDM can send them a private DM and post a public reply to their comment. You create and manage these automations by chatting with your AI app, and you can also read your posts, comments, and insights.
- Who it's for: creators and businesses with an Instagram Business or Creator account. Personal accounts are not supported by Instagram's messaging API.
- Platform: Instagram only. No Facebook Page is needed.
- Automations: feed posts and Reels. Stories can be read but not automated.
- Price: free during early access.
- Operator: Ascendant Labs Pte. Ltd., Singapore.
Setup
ScaleDM is a remote MCP server using streamable HTTP. Add this URL as a connector in your AI app:
https://scaledm.io/mcp
Sign-in steps
- Your AI app opens the ScaleDM sign-in page.
- Choose an access level: Read and manage automations or Read only. See Access levels.
- Sign in with Instagram and approve the requested permissions. ScaleDM never sees your password.
- You return to your AI app, connected.
Instagram permissions
ScaleDM uses Instagram Business Login and requests instagram_business_basic, instagram_business_manage_insights, instagram_business_manage_comments, and instagram_business_manage_messages. Instagram shows the same permissions for both access levels. ScaleDM enforces read-only access itself.
Authorization details
- OAuth 2.1 authorization code flow with PKCE (
S256) and dynamic client registration. - Metadata:
/.well-known/oauth-authorization-serverand/.well-known/oauth-protected-resource/mcp. - Endpoints:
/oauth/register,/oauth/authorize,/oauth/token. - Access tokens last 60 days. There are no refresh tokens, so after 60 days your AI app asks you to sign in again.
- ScaleDM refreshes the stored Instagram token when it is used within 7 days of expiry.
Access levels
You pick the access level on the ScaleDM sign-in page. It controls the OAuth scopes in your token.
| Choice | Scopes | What the AI app can do |
|---|---|---|
| Read only | instagram:read |
Read your profile, posts, comments, insights, and automations. Cannot create, change, or delete automations. |
| Read and manage automations | instagram:read instagram:write |
Everything above, plus create, update, and delete automations. |
To switch from read-only to manage, disconnect and reconnect ScaleDM in your AI app and pick Read and manage automations.
Tools
Read tools change nothing. Sensitive writes control messages sent to other people, so the AI app should show you exactly what will happen and act only after you approve it.
| Tool | Type | Scope | Side effects |
|---|---|---|---|
get_instagram_account |
Read | instagram:read |
None |
list_instagram_media |
Read | instagram:read |
None |
get_instagram_media |
Read | instagram:read |
None |
list_instagram_media_comments |
Read | instagram:read |
None |
list_instagram_account_insights |
Read | instagram:read |
None |
get_instagram_media_insights |
Read | instagram:read |
None |
list_automations |
Read | instagram:read |
None |
get_automation |
Read | instagram:read |
None |
create_automation |
Sensitive write | instagram:write |
When active, sends DMs and public replies to people who comment on the chosen posts |
update_automation |
Sensitive write | instagram:write |
Changes who gets messages and what they say; pauses or resumes sending; can reset counters |
delete_automation |
Sensitive write | instagram:write |
Permanently deletes the automation and its counters and stops its messages. Cannot be undone |
ScaleDM never sends a DM to someone who did not comment, never posts to your feed, and never deletes or hides comments.
Tool reference
All tools return structured JSON. Tools marked with an image preview also return an inline image for apps that support it.
get_instagram_accountReadThe connected account's profile.
- Inputs
- None
- Returns
account_id,username, name, bio, website, follower, following, and post counts, and a profile photo preview.
list_instagram_mediaReadFeed posts and Reels, or active stories.
- Inputs
kind:feed(default) orstories.limit: 1 to 50, feed only.after: cursor frompagination.next_cursor, feed only.- Returns
- Media IDs, captions, media types, permalinks, timestamps, and pagination.
get_instagram_mediaReadOne post, including carousel items, with an image preview.
- Inputs
media_id(required).- Returns
- The post's caption, type, permalink, timestamp, and preview.
list_instagram_media_commentsReadTop-level comments on one post.
- Inputs
media_id(required).limit: 1 to 50, default 50.after: pagination cursor.- Returns
- Comment ID, text, timestamp, username, like count, and hidden state, plus pagination.
list_instagram_account_insightsReadAccount-level metrics.
- Inputs
days: 1 to 30, default 7.- Returns
- The period and a list of metrics such as reach, views, and interactions, as reported by Instagram.
get_instagram_media_insightsReadMetrics for one post, Reel, or story.
- Inputs
media_id(required).- Returns
- Media type, permalink, timestamp, and a list of metrics as reported by Instagram.
list_automationsReadThe account's automations, newest first.
- Inputs
- All optional:
is_active,media_id,name_contains,trigger_keyword,limit. - Returns
- A count and each automation's settings and counters (
sent_count,comment_count,total_clicks).
get_automationReadOne automation, with an image preview for image DMs.
- Inputs
automation_id(required).- Returns
- The automation's settings and counters.
create_automationSensitive writeCreates a comment-to-DM automation. It starts right away unless is_active is false.
- Inputs
-
media_ids(required): post or Reel IDs, or["*"]for every post.confirmed(required): must betrue, set only after you approve.match_mode:keywords(default) orall.trigger_keywords: required forkeywords; case-insensitive text match.dm:typetextwith amessage, orimagewith atitleand an image, plus up to 3 linkbuttons.comment_reply:enabledand a list ofreplies; one is picked at random.dm_imageorimage_url: the image for image DMs.name,is_active: optional. At least one ofdmorcomment_replyis required. - Returns
- The created automation, including its
id. - Rejects
- Calls without
confirmed=true, and exact duplicates of an existing automation (same posts, keywords, and match mode).
update_automationSensitive writeChanges one automation. Only the fields you pass change.
- Inputs
-
automation_id(required). Any of:name,media_ids,add_media_ids,remove_media_ids,trigger_keywords,add_trigger_keywords,remove_trigger_keywords,match_mode,is_active,dm(ornullto remove),comment_reply(ornullto remove),dm_image,image_url,reset_counters. - Returns
- The updated automation.
delete_automationSensitive writePermanently deletes one automation and its counters.
- Inputs
automation_id(required).- Returns
automation_idanddeleted: true.
What automations do
An active automation runs on ScaleDM's servers, even when your AI app is closed. For each new top-level comment on a matching post:
- ScaleDM checks the comment against your active automations. The first matching automation handles it; one comment never triggers more than one automation.
- If a DM is set up, ScaleDM sends it as an Instagram private reply to that comment.
- If a public reply is set up, ScaleDM posts it under the comment, tagging the commenter. When a DM is also set up, the public reply is only posted after the DM is delivered.
- The automation's counters go up.
Never triggered by
- Replies to comments, or comments by your own account.
- Comments older than 7 days, for the DM. Instagram only allows a private reply within 7 days of the comment, once per comment.
- Paused automations (
is_active: false).
Link buttons
Links in DM buttons go through a scaledm.io/track/… link that counts the click and redirects to your URL. ScaleDM counts clicks per button, not who clicked. Links typed into the DM text are not tracked. Buttons in DMs that were already sent keep working after an automation is deleted, until the Instagram account is disconnected.
Images
Images uploaded for image DMs are hosted for 30 days. After that, the automation stops sending the DM until you replace the image; a public reply, if set up, keeps working.
Errors and retries
Errors come back as a tool result with isError: true and a message that says what went wrong. ScaleDM does not silently fall back or substitute a different action.
| Situation | What you see | What to do |
|---|---|---|
| Invalid input | The reason, for example trigger_keywords must contain at least one keyword | Fix the input and call again |
| Not approved | Not created: confirmed must be true | Show the user the automation, then call again with confirmed=true once they approve |
| Duplicate | The ID and name of the existing automation | Use update_automation on the existing one |
| Read-only connection | insufficient_scope, and the app is asked to re-authorize |
Reconnect and choose Read and manage automations |
| Sign-in expired or revoked | invalid_token, and the app is asked to re-authorize |
Sign in again |
| Instagram rejected the request | Instagram's error message | Follow the message; retrying unchanged usually fails again |
| Server error on a write | The change may or may not have been saved | Call list_automations to check, then retry only if the change is missing |
create_automation, check list_automations. An exact duplicate is rejected, so a blind retry cannot create two identical automations.Limits
Comment processing
To stay within Instagram's limits, ScaleDM processes matching comments for each Instagram account at most:
| Window | Max comments |
|---|---|
| 1 second | 1 |
| 30 seconds | 3 |
| 1 minute | 4 |
| 1 hour | 120 |
| 24 hours | 500 |
Comments beyond these limits are queued and processed in order when a slot opens, not dropped. A queued comment whose 7-day private-reply window passes before its turn does not get a DM.
Automation settings
- Up to 3 link buttons per DM, each with an
https://URL. - Image DMs need a title and an
https://image. - Read tools return at most 50 items per page.
Data and retention
What ScaleDM stores
- The connected Instagram account: ID, username, name, profile photo URL, account type, and the Instagram access token.
- Your automations: settings, messages, and counters.
- Link click counts per button, without who clicked.
- Images you upload for image DMs, for 30 days.
- Request logs, for 30 days.
What ScaleDM does not store
- Posts, comments, and insights. They are fetched live for each request.
- Comment text and commenter details from webhooks. They are used to decide whether to reply, then discarded.
- Incoming DMs.
Deleting your data
Removing the connector in your AI app ends that app's access but keeps your automations running. To delete everything, remove ScaleDM in Instagram (Settings, then Website permissions, then Apps and websites). That deletes the account, its token, its automations, link click records, and hosted images. You can also follow the data deletion steps or email support@ascendantlabs.co.
ScaleDM does not run an AI model, sell data, or use it for advertising or training. See the privacy policy and terms.
Support
ScaleDM is built and supported by Ascendant Labs. Email support@ascendantlabs.co with your Instagram username and what happened.