Instagram API Error 190

OAuthException code 190 is not one error. It is at least five, each with a different fix — and the famous 60-day expiry is the rarest of them. Find your exact message below.

The short answer

Code 190 means your Instagram access token is no longer usable, and the message text — not the code — tells you why. Meta documents error subcodes for distinguishing these, but in our production logs graph.instagram.com returns error_subcode: 0 for every single one. The string is all you get:

{
  "error": {
    "message": "Error validating access token: The session has been invalidated because the user changed their password or Facebook has changed the session for security reasons.",
    "type": "OAuthException",
    "code": 190,
    "error_subcode": 0
  }
}

Three of the five variants are permanent and need the account owner to log in again. One needs the owner to clear a prompt on instagram.com, during which a reconnect button cannot work. One is a transient blip you should simply retry. Sending the wrong message to the wrong user is how integrations lose trust.

How often each one actually happens

Most guides rank these by how easy they are to explain. This is how they ranked in Feedframer's own logs on 4 October 2026, across the 43 connected Instagram accounts we then had in a dead-token state. Counts are failed API calls, not a clean split of the 43 — one account can fail more than once — so read the ranking, not the totals.

Of those 43 accounts, 42 broke before their token's recorded expiry date, and 7 were still holding a token that was in date that day. If your error handling only covers expiry, it covers the one case in forty.

Find your error message

"The session has been invalidated because the user changed their password"

Error validating access token: The session has been invalidated because the user changed their password or Facebook has changed the session for security reasons.

How often: 20 failures on 4 October 2026 — the most common cause we see.

What it means: The Instagram account owner changed their password, or Meta reset their sessions after a security event. Every access token issued before that moment is dead — including tokens with weeks left on the 60-day clock. Nothing about your code caused it, and nothing in your code can prevent it.

Fix: The owner has to log in through your app again. Calling refresh_access_token will keep returning the same error, because the refresh endpoint needs a token that is still valid. Store the failure, stop retrying, and prompt the owner to reconnect.

"The user has not authorized application"

Error validating access token: The user has not authorized application {your-app-id}.

How often: 16 failures on 4 October 2026 — the second most common.

What it means: The account owner removed your app, almost always from Instagram → Settings → Apps and websites, or by removing the Instagram account from the connected Facebook Page. Your app ID appears in the message, which is a useful way to confirm it is your integration that was revoked and not a different one.

Fix: The owner has to log in through your app again and approve the permissions. Refreshing cannot fix it. If this happens often, check that your connect flow explains which permissions you need and why — owners revoke what they do not recognise.

"You cannot access the app till you log in to www.instagram.com"

Error validating access token: You cannot access the app till you log in to www.instagram.com and follow the instructions given.

How often: 4 failures on 4 October 2026 — the one most people get wrong.

What it means: Instagram has flagged the account — usually after a suspicious login — and is holding it behind a checkpoint. No app can read the account until the owner clears that prompt. You may also see the wording "This Instagram account needs to complete a checkpoint before it can access this app."

Fix: Do not send a reconnect link. The OAuth login itself is blocked, so the owner will click your button, fail, and conclude your product is broken. Tell them to log in at instagram.com first and follow the instructions there. Once the check is cleared, the token you already hold can start working again — so retry it on a backoff rather than discarding it.

"An unexpected error has occurred, with is_transient: true"

An unexpected error has occurred. Please retry your request later. (is_transient: true)

How often: 4 failures on 4 October 2026 — safe to retry.

What it means: Meta is telling you the request failed on their side and the token is probably fine. This is the one code 190 variant that carries a machine-readable signal: the error object has is_transient set to true.

Fix: Retry the same token on an exponential backoff. Do not mark the connection broken and do not email anyone on the first failure — you will scare users over a blip. Only escalate if it keeps failing past your retry budget.

"Session has expired"

Error validating access token: Session has expired on {date}. The current time is {date}.

How often: 1 failures on 4 October 2026 — the rarest, despite being the famous one.

What it means: The long-lived token passed its 60-day life without being refreshed. This is the failure every tutorial warns you about, and in our data it is the least common one by a wide margin: 1 failure, against 36 caused by password changes and revoked apps.

Fix: Nothing recovers an expired token — the owner logs in again. To prevent the next one, refresh on a schedule rather than on error. The token must be at least 24 hours old and not yet expired for refresh_access_token to work, so leave a margin: we refresh anything due within 7 days.

Telling them apart in code

Because the subcode is useless on graph.instagram.com, classification comes down to the message text plus the is_transient flag. This is the shape we use:

function classify190(body) {
  const error = body?.error;
  if (error?.code !== 190) return 'not-a-token-problem';

  const message = error.message ?? '';

  // Instagram is holding the account. A reconnect cannot succeed yet,
  // because the OAuth login itself is blocked until the owner clears it.
  if (/checkpoint|log in to www\.instagram\.com/i.test(message)) {
    return 'blocked-retry-later';
  }

  // Meta tells you when it is worth retrying the same token.
  if (error.is_transient === true) return 'retry-with-backoff';

  // Password change, revoked app, genuine expiry: only a fresh login fixes it.
  return 'needs-reconnect';
}

Matching on English error strings is fragile, and we would rather not — but Meta gives you nothing more reliable here. Log the raw message on every failure so that when the wording changes, you find out from your own logs instead of from a customer.

One more trap: a 30-second timeout talking to Instagram is not a token error. If your HTTP client throws before it ever sees a response body, do not mark the connection broken — retry it. We got this wrong ourselves, and it inflated our own broken-account count badly enough to distort the table above until we separated the two.

Frequently asked questions

What does Instagram API error code 190 mean?

Code 190 is an OAuthException meaning your access token is no longer usable. It is not one error — it covers at least five different situations, from a changed password to an Instagram security checkpoint to a genuinely expired token, and the fix is different for each. Because graph.instagram.com returns error_subcode: 0 for all of them in our logs, the message text is the only way to tell them apart.

How do I fix Instagram error 190?

Read the message, do not just read the code. If it mentions a changed password or says the user has not authorized your application, the token is permanently dead and the account owner must log in through your app again. If it mentions logging in to www.instagram.com or a checkpoint, the owner must clear that prompt on instagram.com first — reconnecting will fail until they do. If the error has is_transient: true, retry the same token on a backoff.

Can I refresh a token that returned error 190?

Almost never. The refresh_access_token endpoint requires a token that is at least 24 hours old and still valid. Once a token has been invalidated by a password change, a revoked app or expiry, refreshing returns the same code 190. The exception is the transient variant and the checkpoint variant, where the token itself may still be good.

Does error_subcode tell me which kind of 190 I have?

Meta's error reference documents subcodes such as 460 and 463 for Facebook Login, but in Feedframer's production logs graph.instagram.com sends error_subcode: 0 for every code 190 we have recorded. If you are building on the Instagram Graph API, match on the message text and on the is_transient flag instead, and treat any subcode you do get as a bonus rather than a contract.

Is error 190 caused by the 60-day token expiry?

Usually not. On 4 October 2026, Feedframer had 43 connected Instagram accounts holding a dead token, and 42 of them broke before their token's recorded expiry date. Seven were still holding a token that was in date that day. Expiry explained exactly one. If you only guard against expiry, you have handled the rarest case.

How do I stop Instagram tokens breaking in the first place?

You cannot — a client changing their Instagram password will always kill the token, and that is the single biggest cause. What you can control is how fast you notice and how clearly you explain it. Classify the message, retry the transient and checkpoint cases automatically, and when a reconnect genuinely is needed, tell the owner which of the three things happened rather than asking them to guess.

Keep reading

Let us handle code 190

Feedframer connects to Instagram once, refreshes the token automatically, and serves the feed as REST JSON, GraphQL or RSS. We cannot stop a client changing their Instagram password — nobody can — but we check the connection on every fetch cycle and email you when it breaks, so a blank widget is not how you find out. GET /api/v1/accounts returns a status and lastFetchAt per account if you would rather watch it yourself. Free plan: 1 account, 6 posts, daily refresh, unlimited API views. Premium is $6/month for 5 accounts, 100 posts per page and hourly refresh.