The Facebook Graph API is Meta’s HTTP API for reading and writing Facebook data, like Pages, posts, comments and photos, at graph.facebook.com. Every call needs an access token.
To get one, create an app in the Meta App Dashboard, open the Graph API Explorer, click Generate Access Token, and run GET /me?fields=id,name. For Page data, you swap that user token for a Page access token.
Keep reading as I take you through the full Facebook Graph API setup first. However, you will also learn how EmbedSocial skips the setup entirely in the second half.
That’s the whole loop. The rest of this guide is about the part that trips people up: which token you need, how to keep it from expiring, and what Meta asks for before other people can use your app.
If all you want is your Page’s posts and reviews on a website, a Facebook feed widget does it without you handling a single token. If you want them in your own app, the EmbedSocial social media API reads them for you. Both are covered at the end.
How the Facebook Graph API is organized
Meta describes the Facebook Graph API in terms of nodes, edges and fields.
A node is one object with an ID, like a Page, a post or a photo. An edge is a list hanging off a node, like the posts on a Page. Fields are the properties you ask for, like a post’s message or date.
So a request for a Page’s latest posts reads like a sentence:
GET https://graph.facebook.com/v26.0/{page-id}/feed?fields=message,created_time
{page-id} is the node, feed is the edge, and message,created_time are the fields. The v26.0 at the start is the API version. More on versions below.
Make your first Facebook Graph API call
To make your first Facebook Graph API call, you need a Meta developer account and a Meta app.
Go to developers.facebook.com/apps/creation/. Give the app a name and a contact email, pick the use cases it needs, and choose a business portfolio, or select “I don’t want to connect a business portfolio yet” while you test.
Review the summary and click Go to dashboard.
A test app is fine. Nothing in this section touches your own code.
Then open the Graph API Explorer. It loads with a GET request, the latest version, and me?fields=id,name in the query field.
- Pick your app in the Meta App dropdown in the top right.
- Click Generate Access Token and confirm with Continue as.
- Click Submit.
You get JSON back with your Facebook user ID and name:
{
"id": "YOUR_USER_ID",
"name": "Your Name"
}
That token is a user access token, and it expires in about an hour. It’s fine for poking around. Anything that runs on its own needs a longer-lived token, covered below.
When a query works, the Get Code button under the response turns it into sample code.
Which Facebook access token do you need?
Meta’s Facebook Graph API access token guide lists four kinds. They are not interchangeable.
| Token | Use it for | Where you get it |
|---|---|---|
| User access token | Acting for a signed-in person, and getting their Page tokens | Facebook Login or the Graph API Explorer |
| Page access token | Reading and writing one Page’s posts, comments and ratings | GET /{user-id}/accounts with a user token |
| App access token | Reading and changing your app’s settings | oauth/access_token with your app ID and secret, on your server |
| Client token | Identifying your app in native or desktop apps | App Dashboard, Settings > Advanced > Security |
For Page posts, comments and reviews, you want a Page access token. Most Pages API endpoints require one.
Keep app tokens off the client. Meta’s rule is to never hard-code them into client-side code or app binaries, because the token exposes your app secret.
Get a Facebook Page access token that doesn’t expire
Tokens from the Facebook Graph API Explorer are short-lived. A long-lived user token lasts about 60 days.
A Page token you get from a long-lived user token has no expiration date at all. No expiration date doesn’t mean permanent. The token stops working if the user changes their password, loses their role on the Page, or removes your app. That’s the one to store.
Getting there takes two calls, both from your server.
First, swap the short-lived user token for a long-lived one:
GET https://graph.facebook.com/v26.0/oauth/access_token?grant_type=fb_exchange_token&client_id=APP_ID&client_secret=APP_SECRET&fb_exchange_token=SHORT_LIVED_USER_TOKEN
The response has the new token and expires_in, the seconds until it expires. This call carries your app secret, so Meta says to never make it client-side.
If you’d rather not handle this yourself, EmbedSocial handles the Facebook side. See how to skip the Facebook Graph API setup.
Then ask for the Pages that user manages:
GET https://graph.facebook.com/v26.0/{app-scoped-user-id}/accounts?access_token=LONG_LIVED_USER_TOKEN
Each Page in the list comes with its own access_token. Those Page tokens have no expiration date.
No expiration date isn’t forever. Meta says they can still be invalidated under certain conditions, and warns not to depend on any token lifetime staying the same. Store the token, but handle error 190 by getting a new one.
Check the Facebook access token first, then the error code
When a Facebook Graph API call fails, check the token before anything else.
In the Explorer, click the info icon next to the token. It shows the app the token belongs to and the permissions it carries. From code, call debug_token with an app token:
GET https://graph.facebook.com/v26.0/debug_token?input_token=TOKEN_TO_CHECK&access_token=APP_TOKEN
It returns is_valid, expires_at, scopes (the permissions granted) and the app and user IDs. If is_valid is false or a permission you need is missing from scopes, you’ve found your bug.
If the token checks out, the error code tells you the rest:
| Error | What it means | Fix |
|---|---|---|
| 190 (OAuthException) | The token expired or is invalid | Get a new token. Subcode 460 means the password changed; 463 and 467 mean an expired or invalid token; 492 means the user no longer has a role on the Page |
| 10, or 200 to 299 | A permission isn’t granted, or was removed | Request the permission again, and check its access level |
| 4, 17, 32 or 613 | A rate limit was hit (app, user, Pages or custom) | Wait, then slow down. Read the usage headers |
| 368 | Temporarily blocked for a policy reason | Wait, and review what triggered it |
Facebook API permissions, App Review and business verification
A Facebook Graph API token only reaches what its permissions allow. To read your own Page’s posts, Meta lists two:
pages_read_engagementreads content posted by the Page and follower data.pages_read_user_contentreads what other people post on the Page, including comments and ratings.
Add pages_show_list so your app can see the list of Pages a person manages. In the Explorer, add all three from the permissions dropdown before you generate the token.
When an app asks for Page access, Facebook shows the Page admin a screen like this one, from EmbedSocial’s own connection flow:
While you build, your app has Standard access. Permissions with Standard access can only be requested from people who have a role on your app, like admins, developers and testers. That’s why an app can work for you and fail for your first customer.
To let anyone use it, each permission needs Advanced access. Advanced access is approved one permission at a time through App Review, and since February 1, 2023 it also requires Business Verification.
Meta’s Pages docs say every Page permission and feature needs App Review before a live app can use it.
Page permissions cover Pages the person manages. To read public Pages you don’t manage, you need the Page Public Content Access feature, which is also approved through App Review.
If you only need your own Page’s posts and reviews, the permissions work is overhead. EmbedSocial handles the connection and gives you the data.
Two more limits on reading a Page: one request returns at most 100 feed posts with limit, and the API returns about 600 ranked, published posts per year.
Facebook API rate limits and versions
The Facebook Graph API caps calls at two levels.
The app-level limit is 200 calls per hour times your number of users. Calls with Page or system user tokens have their own Pages limit: 4,800 calls per 24 hours times the Page’s number of engaged users.
Responses carry headers that tell you how close you are: X-App-Usage for the first, X-Business-Use-Case-Usage for the second.
Go over and you get an error until your count drops back under the limit.
Versions are the other moving part. The latest is v26.0, released July 29, 2026. Meta keeps each version available for at least two years, then retires it.
Put the version in every request path, like /v26.0/me. A call without a version uses the default set in your App Dashboard under Settings > Advanced.
When a version retires, calls to it are moved to the next oldest version that still works. Check the Graph API changelog before your version’s end date.
How Facebook and Instagram share the Graph API
Facebook and Instagram run on the same Graph API platform, in one of two setups.
With the Instagram API with Facebook Login, calls go to graph.facebook.com and use Facebook user or Page tokens. The Instagram professional account must be connected to a Facebook Page.
With the Instagram API with Instagram Login, calls go to graph.instagram.com. People log in with Instagram, and no Page is needed.
So if you’ve set up a Facebook app and Page tokens, you’re most of the way to the Instagram API with Facebook Login too.
Our Instagram API page covers what EmbedSocial pulls from Instagram and the limits that come with it.
Google does it differently. YouTube’s public data needs a simple key, not a login. If YouTube is next on your list, see how to get a YouTube API key.
Skip the Facebook Graph API setup with EmbedSocial
Everything above is what it takes to read your own Page through the Facebook Graph API: a Meta app, App Review, a token exchange, error handling and a version upgrade every couple of years.
If all you want is your own Page’s posts and reviews on a website or in an app, EmbedSocial does that work for you. It connects through Facebook’s official API and syncs new posts on its own.
Connect your Facebook Page without a Graph API app
Connect a Facebook Page you manage as a source, logged in with an account that has Admin or Editor access to it.
Choose what to pull: posts, reviews, visitor posts and mentions
Pick the content type for each source:
- Page posts: what your Page publishes. Works on every plan, including Free.
- Reviews: your Facebook recommendations, ready to show as social proof. Read the Facebook reviews guide for how they work, and how to get Facebook reviews to grow the count.
- Visitor posts: what customers post on your Page.
- @Mentions: posts where other people tag your Page. See how to track Facebook mentions, or monitor them with Facebook social listening.
Reviews and visitor posts start on Pro, and mentions on Pro Plus. Compare the tiers on the pricing page.
Personal profiles and Facebook Groups aren’t supported, because of Facebook’s data policy, and Facebook’s API doesn’t offer hashtag posts.
Embed the Facebook feed on your website
Pick a template and embed the Facebook widget on WordPress, Shopify, Webflow or any other site.
Start from a layout like the Facebook feed masonry template or the Facebook Reels slider, and use moderation to choose which posts go live.
The step-by-step is in how to embed a Facebook feed, and for video there’s how to embed Facebook Reels.
For reviews, use the Facebook reviews widget with one of the Facebook review templates.
On WordPress, there’s a dedicated Facebook reviews plugin, and the full walkthrough is in how to embed Facebook reviews.
You can also show whole photo albums with the Facebook albums widget, covered in how to embed a Facebook album.
Get Facebook Graph API data through the EmbedSocial API
In your own app, the EmbedSocial API gives your code one API key, sent as a Bearer token, for every source connected to your account: Facebook, Instagram, TikTok, YouTube, LinkedIn and more.
Read a widget’s Facebook posts with GET /v2/api/social-feed/hashtag-album/media, and Facebook reviews with GET /v2/api/reviews/reviews-filtered.
It’s available on the Premium and Enterprise plans, and there’s a free trial. The endpoints return what the source has synced: a new Facebook source is seeded with its latest 50 posts, and Facebook reviews refresh every 24 hours.
The API doesn’t publish to Facebook. If you’re weighing this against scraping, read web scraping vs. API for social media.
For no-code workflows, EmbedSocial connects to Zapier.
Facebook Graph API vs. EmbedSocial: which one fits your project
Build on the Facebook Graph API yourself if:
- You’re making a product that works with other people’s Pages.
- You need to publish, reply or moderate as the Page.
- You need Page Insights or ads data.
Plan for App Review, business verification, token handling and a version upgrade every couple of years. The same trade-off applies to other platforms, like the Google Business Profile API and the YouTube API.
Use EmbedSocial if:
- You need your own Page’s posts, reviews or mentions on a website.
- You want that data inside your app or dashboard without maintaining a Meta app.
- You want Facebook, Instagram, TikTok, YouTube, LinkedIn and more behind one API key. See how a unified social listening API works.
For that second group, the Facebook API token work, permissions and version upgrades are overhead with no payoff.
Conclusion
The Facebook Graph API comes down to one thing: the right access token. Get a short-lived user token from the Explorer, exchange it on your server for a long-lived one, and use that to get a Page access token with no expiration date.
Then handle error 190, respect the rate limits and upgrade before your version retires.
If you’re building for other people’s Pages, that work is the job. If you only need your own Page’s posts and reviews, EmbedSocial handles the connection and gives you the data.
Start a free trial and connect your Page.