The permissions dmrabbit asks for

Four permissions, all required, and what each one is actually used for.

When you connect, Instagram asks you to approve four permissions. All four are required. Instagram's own screen lets you switch them off one by one, and if any is missing the connection is refused.

What each one does

PermissionUsed for
Profile informationYour username, name, profile picture and account type, so dmrabbit can show you which account it is acting as.
CommentsReading comments on your posts, replying to them, and hiding or deleting them from your inbox.
MessagesReceiving and sending direct messages, including story replies and story mentions.
Media and insightsListing your posts and reels so you can point automations at them, and showing your analytics.

Why all four

Every one of them backs something dmrabbit does. Without comments it cannot reply to a comment; without messages it cannot send a DM; without media it cannot show you which post to automate. A partial connection would appear to work and then fail silently later, so it is refused up front instead.

The technical names

If you are checking these against Instagram's own documentation, they are instagram_business_basic, instagram_business_manage_comments, instagram_business_manage_messages and instagram_business_manage_insights.

What dmrabbit never asks for

There is no permission to post, schedule or delete your content, and dmrabbit does not request one.