The permissions dmrabbit asks for
Four permissions, all required, and what each one is actually used for.
When you connect, Instagram asks you to approve four permissions. All four are required. Instagram's own screen lets you switch them off one by one, and if any is missing the connection is refused.
What each one does
| Permission | Used for |
|---|---|
| Profile information | Your username, name, profile picture and account type, so dmrabbit can show you which account it is acting as. |
| Comments | Reading comments on your posts, replying to them, and hiding or deleting them from your inbox. |
| Messages | Receiving and sending direct messages, including story replies and story mentions. |
| Media and insights | Listing your posts and reels so you can point automations at them, and showing your analytics. |
Why all four
Every one of them backs something dmrabbit does. Without comments it cannot reply to a comment; without messages it cannot send a DM; without media it cannot show you which post to automate. A partial connection would appear to work and then fail silently later, so it is refused up front instead.
The technical names
If you are checking these against Instagram's own documentation, they are instagram_business_basic, instagram_business_manage_comments, instagram_business_manage_messages and instagram_business_manage_insights.
What dmrabbit never asks for
There is no permission to post, schedule or delete your content, and dmrabbit does not request one.