Access tokens
The secret key behind every connection. Why it expires, how long it lasts per channel, and how it is renewed.
Last updated: September 30, 2026
On this page
An access token is a secret string that lets {{brand.name}} talk to Meta on behalf of your account. Meta issues it while you connect, it is stored encrypted on the server, and it is used quietly on every message exchange. A rough analogy: connecting opens the door, and the token is what keeps it open — and some tokens carry an expiry date.
What it does
Every time the panel goes to Meta — reading a new message, sending a reply, hiding a comment, publishing a post, pulling insights — it attaches this token to the request. Seeing the token, Meta accepts that the request really is made on behalf of that account's owner, and answers. If the token is invalid, Meta does nothing; in the panel that shows up as the account dropping to Needs reconnecting.
The token carries only the permissions you granted while connecting. A permission you didn't grant then isn't in it, and it is never added by itself.
⚠️ You can't see the token anywhere, and you shouldn't need to. It is stored encrypted and never appears on screens, in system logs or in error messages. Never hand your token to anyone who asks for it.
Why it expires
Meta doesn't issue tokens without an end date, because a stolen token that never expires can be used forever. The expiry makes the damage end by itself if something goes wrong. Per channel:
Accounts connected with Instagram
The token is valid for 60 days. {{brand.name}} fetches a fresh one 10 days before it runs out, in the background. You see this on the connection card as:
Renews automatically · next renewal: date
Renewal only works with a token that is still valid. Once it has expired it cannot be extended; the account becomes Needs reconnecting and you must sign in by hand. Those ten days exist for exactly that reason.
If renewal fails, the account switches to the Renewal due badge 3 days before expiry.
Accounts connected through a Facebook Page
A Page token has no expiry date, so you won't see a countdown on the card. But Meta's data access permission is separate and does expire. When the remaining time can be read, the card shows:
Permission time left: N days
14 days before expiry the account switches to the Renewal due badge. The portfolio's owner and admins also get an email and an in-app notification before. On this path renewal is .
Was this article helpful?