BlogTutorialsFacebook

Facebook Graph API: How to Get an Access Token and Use It

What the Facebook Graph API is, how to get an access token in the Graph API Explorer, and how to turn it into a Page token that doesn't expire.

Dushko Talevski
View as Markdown
Facebook Graph API access token details: a valid Page token with no expiration date and three Page permissions

Dushko Talevski

EmbedSocial Team

The Facebook Graph API is Meta’s HTTP API for reading and writing Facebook data, like Pages, posts, comments and photos, at graph.facebook.com. Every call needs an access token.

To get one, create an app in the Meta App Dashboard, open the Graph API Explorer, click Generate Access Token, and run GET /me?fields=id,name. For Page data, you swap that user token for a Page access token.

Keep reading as I take you through the full Facebook Graph API setup first. However, you will also learn how EmbedSocial skips the setup entirely in the second half.

That’s the whole loop. The rest of this guide is about the part that trips people up: which token you need, how to keep it from expiring, and what Meta asks for before other people can use your app.

If all you want is your Page’s posts and reviews on a website, a Facebook feed widget does it without you handling a single token. If you want them in your own app, the EmbedSocial social media API reads them for you. Both are covered at the end.

How the Facebook Graph API is organized

Meta describes the Facebook Graph API in terms of nodes, edges and fields.

A node is one object with an ID, like a Page, a post or a photo. An edge is a list hanging off a node, like the posts on a Page. Fields are the properties you ask for, like a post’s message or date.

So a request for a Page’s latest posts reads like a sentence:

GET https://graph.facebook.com/v26.0/{page-id}/feed?fields=message,created_time

{page-id} is the node, feed is the edge, and message,created_time are the fields. The v26.0 at the start is the API version. More on versions below.

Make your first Facebook Graph API call

To make your first Facebook Graph API call, you need a Meta developer account and a Meta app.

Go to developers.facebook.com/apps/creation/. Give the app a name and a contact email, pick the use cases it needs, and choose a business portfolio, or select “I don’t want to connect a business portfolio yet” while you test.

Review the summary and click Go to dashboard.

A test app is fine. Nothing in this section touches your own code.

Then open the Graph API Explorer. It loads with a GET request, the latest version, and me?fields=id,name in the query field.

  1. Pick your app in the Meta App dropdown in the top right.
  2. Click Generate Access Token and confirm with Continue as.
  3. Click Submit.

You get JSON back with your Facebook user ID and name:

{
  "id": "YOUR_USER_ID",
  "name": "Your Name"
}

That token is a user access token, and it expires in about an hour. It’s fine for poking around. Anything that runs on its own needs a longer-lived token, covered below.

When a query works, the Get Code button under the response turns it into sample code.

Which Facebook access token do you need?

Meta’s Facebook Graph API access token guide lists four kinds. They are not interchangeable.

Token Use it for Where you get it
User access token Acting for a signed-in person, and getting their Page tokens Facebook Login or the Graph API Explorer
Page access token Reading and writing one Page’s posts, comments and ratings GET /{user-id}/accounts with a user token
App access token Reading and changing your app’s settings oauth/access_token with your app ID and secret, on your server
Client token Identifying your app in native or desktop apps App Dashboard, Settings > Advanced > Security

For Page posts, comments and reviews, you want a Page access token. Most Pages API endpoints require one.

Keep app tokens off the client. Meta’s rule is to never hard-code them into client-side code or app binaries, because the token exposes your app secret.

Get a Facebook Page access token that doesn’t expire

Tokens from the Facebook Graph API Explorer are short-lived. A long-lived user token lasts about 60 days.

A Page token you get from a long-lived user token has no expiration date at all. No expiration date doesn’t mean permanent. The token stops working if the user changes their password, loses their role on the Page, or removes your app. That’s the one to store.

Facebook access token lifetimes: a short-lived user token lasts about 1 to 2 hours, a long-lived user token about 60 days, and a Page token from it has no expiration date

Getting there takes two calls, both from your server.

First, swap the short-lived user token for a long-lived one:

GET https://graph.facebook.com/v26.0/oauth/access_token?grant_type=fb_exchange_token&client_id=APP_ID&client_secret=APP_SECRET&fb_exchange_token=SHORT_LIVED_USER_TOKEN

The response has the new token and expires_in, the seconds until it expires. This call carries your app secret, so Meta says to never make it client-side.

If you’d rather not handle this yourself, EmbedSocial handles the Facebook side. See how to skip the Facebook Graph API setup.

Then ask for the Pages that user manages:

GET https://graph.facebook.com/v26.0/{app-scoped-user-id}/accounts?access_token=LONG_LIVED_USER_TOKEN

Each Page in the list comes with its own access_token. Those Page tokens have no expiration date.

No expiration date isn’t forever. Meta says they can still be invalidated under certain conditions, and warns not to depend on any token lifetime staying the same. Store the token, but handle error 190 by getting a new one.

Check the Facebook access token first, then the error code

When a Facebook Graph API call fails, check the token before anything else.

In the Explorer, click the info icon next to the token. It shows the app the token belongs to and the permissions it carries. From code, call debug_token with an app token:

GET https://graph.facebook.com/v26.0/debug_token?input_token=TOKEN_TO_CHECK&access_token=APP_TOKEN

It returns is_valid, expires_at, scopes (the permissions granted) and the app and user IDs. If is_valid is false or a permission you need is missing from scopes, you’ve found your bug.

If the token checks out, the error code tells you the rest:

Error What it means Fix
190 (OAuthException) The token expired or is invalid Get a new token. Subcode 460 means the password changed; 463 and 467 mean an expired or invalid token; 492 means the user no longer has a role on the Page
10, or 200 to 299 A permission isn’t granted, or was removed Request the permission again, and check its access level
4, 17, 32 or 613 A rate limit was hit (app, user, Pages or custom) Wait, then slow down. Read the usage headers
368 Temporarily blocked for a policy reason Wait, and review what triggered it

Facebook API permissions, App Review and business verification

A Facebook Graph API token only reaches what its permissions allow. To read your own Page’s posts, Meta lists two:

Add pages_show_list so your app can see the list of Pages a person manages. In the Explorer, add all three from the permissions dropdown before you generate the token.

When an app asks for Page access, Facebook shows the Page admin a screen like this one, from EmbedSocial’s own connection flow:

Facebook permission screen for Page access with read content, manage accounts, read user content and show Pages options turned on

While you build, your app has Standard access. Permissions with Standard access can only be requested from people who have a role on your app, like admins, developers and testers. That’s why an app can work for you and fail for your first customer.

To let anyone use it, each permission needs Advanced access. Advanced access is approved one permission at a time through App Review, and since February 1, 2023 it also requires Business Verification.

Meta’s Pages docs say every Page permission and feature needs App Review before a live app can use it.

Page permissions cover Pages the person manages. To read public Pages you don’t manage, you need the Page Public Content Access feature, which is also approved through App Review.

If you only need your own Page’s posts and reviews, the permissions work is overhead. EmbedSocial handles the connection and gives you the data.

Two more limits on reading a Page: one request returns at most 100 feed posts with limit, and the API returns about 600 ranked, published posts per year.

Facebook API rate limits and versions

The Facebook Graph API caps calls at two levels.

The app-level limit is 200 calls per hour times your number of users. Calls with Page or system user tokens have their own Pages limit: 4,800 calls per 24 hours times the Page’s number of engaged users.

Responses carry headers that tell you how close you are: X-App-Usage for the first, X-Business-Use-Case-Usage for the second.

Go over and you get an error until your count drops back under the limit.

Versions are the other moving part. The latest is v26.0, released July 29, 2026. Meta keeps each version available for at least two years, then retires it.

Facebook Graph API versions: v23.0 available until Oct 8, 2027, v24.0 until Feb 18, 2028, v25.0 until Jul 29, 2028, and v26.0 is the latest

Put the version in every request path, like /v26.0/me. A call without a version uses the default set in your App Dashboard under Settings > Advanced.

When a version retires, calls to it are moved to the next oldest version that still works. Check the Graph API changelog before your version’s end date.

How Facebook and Instagram share the Graph API

Facebook and Instagram run on the same Graph API platform, in one of two setups.

With the Instagram API with Facebook Login, calls go to graph.facebook.com and use Facebook user or Page tokens. The Instagram professional account must be connected to a Facebook Page.

With the Instagram API with Instagram Login, calls go to graph.instagram.com. People log in with Instagram, and no Page is needed.

So if you’ve set up a Facebook app and Page tokens, you’re most of the way to the Instagram API with Facebook Login too.

Our Instagram API page covers what EmbedSocial pulls from Instagram and the limits that come with it.

Google does it differently. YouTube’s public data needs a simple key, not a login. If YouTube is next on your list, see how to get a YouTube API key.

Skip the Facebook Graph API setup with EmbedSocial

Everything above is what it takes to read your own Page through the Facebook Graph API: a Meta app, App Review, a token exchange, error handling and a version upgrade every couple of years.

If all you want is your own Page’s posts and reviews on a website or in an app, EmbedSocial does that work for you. It connects through Facebook’s official API and syncs new posts on its own.

Connect your Facebook Page without a Graph API app

Connect a Facebook Page you manage as a source, logged in with an account that has Admin or Editor access to it.

EmbedSocial Choose source type screen for Facebook with Page posts, Mentions and Visitor posts

Official tutorial: Connect a Facebook source →

Choose what to pull: posts, reviews, visitor posts and mentions

Pick the content type for each source:

Reviews and visitor posts start on Pro, and mentions on Pro Plus. Compare the tiers on the pricing page.

Personal profiles and Facebook Groups aren’t supported, because of Facebook’s data policy, and Facebook’s API doesn’t offer hashtag posts.

Embed the Facebook feed on your website

Pick a template and embed the Facebook widget on WordPress, Shopify, Webflow or any other site.

Start from a layout like the Facebook feed masonry template or the Facebook Reels slider, and use moderation to choose which posts go live.

The step-by-step is in how to embed a Facebook feed, and for video there’s how to embed Facebook Reels.

For reviews, use the Facebook reviews widget with one of the Facebook review templates.

On WordPress, there’s a dedicated Facebook reviews plugin, and the full walkthrough is in how to embed Facebook reviews.

You can also show whole photo albums with the Facebook albums widget, covered in how to embed a Facebook album.

Get Facebook Graph API data through the EmbedSocial API

In your own app, the EmbedSocial API gives your code one API key, sent as a Bearer token, for every source connected to your account: Facebook, Instagram, TikTok, YouTube, LinkedIn and more.

Read a widget’s Facebook posts with GET /v2/api/social-feed/hashtag-album/media, and Facebook reviews with GET /v2/api/reviews/reviews-filtered.

It’s available on the Premium and Enterprise plans, and there’s a free trial. The endpoints return what the source has synced: a new Facebook source is seeded with its latest 50 posts, and Facebook reviews refresh every 24 hours.

The API doesn’t publish to Facebook. If you’re weighing this against scraping, read web scraping vs. API for social media.

For no-code workflows, EmbedSocial connects to Zapier.

Official tutorial: EmbedSocial API key and docs →

Facebook Graph API vs. EmbedSocial: which one fits your project

Build on the Facebook Graph API yourself if:

Plan for App Review, business verification, token handling and a version upgrade every couple of years. The same trade-off applies to other platforms, like the Google Business Profile API and the YouTube API.

Use EmbedSocial if:

For that second group, the Facebook API token work, permissions and version upgrades are overhead with no payoff.

Conclusion

The Facebook Graph API comes down to one thing: the right access token. Get a short-lived user token from the Explorer, exchange it on your server for a long-lived one, and use that to get a Page access token with no expiration date.

Then handle error 190, respect the rate limits and upgrade before your version retires.

If you’re building for other people’s Pages, that work is the job. If you only need your own Page’s posts and reviews, EmbedSocial handles the connection and gives you the data.

Start a free trial and connect your Page.

Frequently Asked Questions

Is the Facebook Graph API free?

Meta doesn’t publish a price for Graph API calls. The costs are rate limits, App Review and business verification before others can use your app, and the upkeep when versions retire.

How do I get a Facebook Graph API access token?

Create a Meta app, open the Graph API Explorer, pick your app, and click Generate Access Token. That gives you a user token that expires in about an hour. For Page data, exchange it for a long-lived user token on your server, then get a Page token from /{user-id}/accounts.

Does a Facebook Page access token expire?

A Page token you get from a long-lived user token has no expiration date. It can still be invalidated if the user changes their password, loses their Page role, or removes your app, so handle error 190 and get a new token when it happens.

Is the Facebook Graph API being deprecated?

No. Meta released v26.0 on July 29, 2026. Individual versions retire after at least two years, so pin a version in your calls and upgrade before it expires.

Can I read any public Facebook Page with the Graph API?

Not with Page permissions alone. They cover Pages the person manages. Reading public Pages you don’t manage needs the Page Public Content Access feature, which goes through App Review.

Nick Poggi, TrovaTrip Ryan Hazlewood Zanna Ollove, Boston College Brooks Hitzfield, Seven Sons
Loved by 400,000+ brands

Social Media API for AI Agents and Your Own Apps

Available in Premium plans. Official and approved API integration.

Start free trial

Cancel anytime. All features included.

Related posts

View all posts