Connect Instagram to Claude: running your DM automation from an AI client
You connect your Instagram automation to Claude by creating a token inside HookSend, then adding one web address and that token to Claude's connector settings. From then on you type what you want in an ordinary chat and it happens: a campaign set up on your latest reel, a DM flow built from a description, an answer to which post actually got the reach. The same address works in Codex, Antigravity and anything else that speaks the Model Context Protocol. It is included in the free trial and on every paid plan, and it is not part of the Free plan.
HookSend publishes 60 tools over the Model Context Protocol, so an AI client you already pay for can run your Instagram automation by being asked in plain words. Your AI never touches Instagram and never sees your password: it asks HookSend, which already holds the permission.
What MCP is, without the jargon
MCP stands for Model Context Protocol. It is an agreed way for a piece of software to describe what it is able to do, in writing, so that an AI can read the description and use it. Before it existed, every AI needed custom code written for every app it wanted to operate, which is why so few of them could do anything outside their own window. Now HookSend publishes a list of the things it can do at one address, each with a plain-English explanation of what it changes and what it costs. Your AI reads that list, works out which entry your sentence meant, fills in the details and asks HookSend to carry it out. HookSend does the work, because HookSend is the one Instagram gave permission to.
The practical consequence is worth spelling out. Your AI is not logging in to Instagram, is not scraping anything and never has your password. It is holding a conversation with HookSend, in the same way your browser does when you use the dashboard. Everything Meta allows and forbids is unchanged, because the same code does the sending either way.
What this lets you do that the dashboard does not
A dashboard is faster than a conversation for anything you already know how to do. The connector earns its place on the four things a dashboard is structurally bad at.
- Describing instead of navigating. A campaign with a keyword, a follow gate, an email question and a follow-up message is a dozen fields across two steps of a builder. It is also one sentence. You can say the sentence and check the result, which is a different order of work from filling in the form and hoping you remembered the toggle.
- Asking a question that spans several screens. Which of my last ten reels got the most saves, and did the campaign on that one actually send anything. In the dashboard that is insights, then campaigns, then the delivery log, and a bit of mental arithmetic. Here it is one question, because the tools that read your posts, your sends and your leads are all in the same list.
- Bringing your own material into it. Paste your price list into the chat and ask for a knowledge base built from it, and the document is added and indexed. You are not exporting from one place and importing into another.
- Working where you already are. If you write your captions in a chat window, the automation for the post can be set up in the same conversation as the caption, without changing context. That sounds minor and is the reason people actually use it.
The 60 tools cover roughly what the dashboard does. Campaigns are the biggest group at 15, then the moderation, storefront and knowledge tools at 23 between them, the reading tools at 10, DM flows at 8, and the inbox and brand collaborations at 4.
Connecting it
Create a token first. It is in HookSend under Settings, and it is shown to you exactly once, because only a fingerprint of it is stored. Nobody at HookSend can read it back to you afterwards, which also means nobody at HookSend can be talked into revealing it. If you lose it, revoke it and make another.
The address is the same whichever client you use. In Claude, open Settings, then Connectors, then Add custom connector. Name it HookSend, paste the address, and set Authentication to No sign-in. Claude tends to tick Sign in now by itself, so change it: this connector uses a token, not a sign-in. Then add a request header called Authorization whose value is the word Bearer, a space, and your token. Save it, start a new chat, and ask what campaigns you have.
In Claude Code it is one command, with your token in place of the placeholder, followed by a restart.
claude mcp add --transport http hooksend https://hooksend.in/api/mcp \
--header "Authorization: Bearer YOUR_TOKEN"Every other client keeps its list of servers somewhere of its own, some in a settings screen and some in a configuration file, and the menu names move between releases. What does not change is the three things any MCP client needs: the address, HTTP as the transport, and your token sent as an Authorization header. Find where yours keeps those and you are connected.
What it refuses to do
Handing an AI the keys to an account that messages real people is only reasonable if the boundaries are enforced by the software rather than by asking the model politely. Five of them are worth knowing before you connect anything.
The first is that nothing gets deleted. No tool deletes a campaign, a DM flow or a knowledge base. Where the dashboard offers a delete, the connector offers pause or archive instead, so whatever your AI misunderstands can be undone by you afterwards.
The second is that the genuinely irreversible handful will not run when they are first asked. There are nine of them. Each one refuses the first request with a sentence telling the AI to state plainly what it is about to change, and only runs if the same call is repeated with a confirmation. That turns a vague instruction like tidy up my old comments into a question you get to answer before anything happens.
| Action | What it does | Why it cannot be taken back |
|---|---|---|
| Send a DM reply from the inbox | Replies in a real conversation | The message has arrived on somebody's phone |
| Clean up comments on a post | Hides or deletes up to 500 existing comments at once | A deleted comment is gone from Instagram for good |
| Switch a Comment Guard rule on | Applies it to every new comment from then on | A rule set to delete removes real comments permanently |
| Change a Comment Guard rule | Rewrites what it looks for and what it does | Pointing a live rule at delete starts removing comments |
| Delete a Comment Guard rule | Removes the rule | The rule and its wording are gone |
| Replace a DM flow's steps | Writes the whole conversation in one call | Every step left out of the call is deleted |
| Set a campaign's link buttons | Changes the tracked links the DM carries | Removing one deletes every click ever recorded on it |
| Set a campaign's product carousel | Replaces the swipeable cards, up to eight | The previous cards are not kept |
| Remove a bio link from the storefront | Deletes one link button | Its title, address and tap count all go with it |
The third boundary is money and people. Buying a plan, changing how you pay, editing your workspace settings, inviting a colleague and managing these tokens all refuse an AI client outright, with one sentence saying so. Those stay with a person who is signed in, which means a connector that has been given a bad instruction cannot spend anything or let anybody else in.
The fourth is that your plan still applies. Every tool works by calling the same internal route the dashboard calls, authenticated as your workspace, so the campaign limits, the paid-feature checks, the monthly DM allowance and the AI credits are the ones you already have. There is no separate set of rules for AI callers to find a gap in, and a limit tightened in the dashboard tightens here the same day. When something is refused, the refusal explains what your plan allows rather than looking like a fault to retry.
The fifth is that you can cut it off. Revoking a token stops it working on the next request, with no cache to wait out, and every call an AI made is written down, refusals included, with anything whose field name reads like a secret blanked before the record is saved. A token does not expire on its own, so a client you stop using is a token worth revoking.
The safeguard people misread
New things mostly arrive switched off. A DM flow created through the connector is saved unpublished, so nothing reaches anybody until you publish it. A new Comment Guard rule is saved switched off, so writing a rule touches nothing and switching it on is the separate, confirmed step. Flow steps are checked before they are saved, and a flow that could not actually run is refused whole, with the problem named, rather than half saved.
One thing does not follow that pattern. A campaign created through the connector goes live immediately and starts messaging people, unless it is asked for as paused. If you are experimenting, say so in the instruction.
Two smaller limits are worth knowing so you do not waste a conversation on them. A knowledge base document can be pasted text or a web page HookSend fetches, but a PDF still has to be uploaded in the dashboard, because no tool sends a file. And a flow step that needs a picture, or your own webhook address, is built on the canvas rather than described.
What to ask for first
The reading tools are the safe way to find out whether the connection works and whether you trust it. None of them changes anything.
- What campaigns do I have running, and which of them sent nothing this week.
- Which of my last ten posts got the most saves and shares.
- How much of my monthly DM allowance and how many AI credits are left.
- Show me the leads captured in the last fortnight.
- Which brand collaboration offers are sitting in my DMs, and what are they offering.
Then try one change you would not mind undoing. Set up a comment-to-DM campaign on your latest reel, paused, and read it back on the dashboard before switching it live. That one round trip tells you more about whether this suits how you work than any amount of reading.
Which plans include it
The connector is included in the 15-day free trial and on every paid plan, at no extra cost. It is not part of the Free plan a workspace moves to when the trial ends, and a paid plan that has lapsed cannot use it either, in both cases with a sentence explaining why rather than a silent failure. Everything the connector does counts against the same allowances as the dashboard, so it is not a route around a plan.
The short version
Create a token, add one address to your AI client, and your Instagram automation becomes something you can ask for in a sentence. The reading tools are worth connecting for on their own. For the writing tools, the thing to hold on to is that nothing is deleted, nine actions make your AI ask you first, money and colleagues are off limits entirely, and a campaign is the one thing that starts working the moment it is created.
Questions people ask about this
- How do I connect Instagram to Claude?
- Through a tool that already holds Instagram's permission, rather than directly. In HookSend that means creating a token under Settings, then adding HookSend as a custom connector in Claude with the address https://hooksend.in/api/mcp, authentication set to no sign-in, and an Authorization header whose value is Bearer followed by your token. After that you ask Claude for what you want in ordinary language. Be wary of anything offering to connect Claude to Instagram itself, because that is not a thing Instagram permits.
- What is MCP in plain English?
- The Model Context Protocol is an agreed way for an app to describe what it can do so that an AI can use it. The app publishes a list of actions with plain explanations at one address, and any AI client that speaks the protocol can read that list and ask for one of them. It is what makes it possible to operate a product by describing what you want instead of clicking through its screens.
- Does this work with ChatGPT or Codex as well as Claude?
- Yes. The protocol is not tied to one company, so the same address and token work in Codex, Antigravity and anything else that supports MCP. Only Claude and Claude Code have click-by-click instructions on the HookSend site, because those are the two whose screens have actually been tested. Every other client needs the same three things: the address, HTTP as the transport, and the token sent as an Authorization header.
- Can the AI delete my campaigns or flows?
- No. No tool deletes a campaign, a DM flow or a knowledge base. Where the dashboard can delete, the connector offers pause or archive instead, so anything it does can be reversed by you. Nine actions genuinely cannot be undone, such as removing comments from Instagram or sending somebody a DM, and each of those refuses the first request and tells the AI to check with you before repeating it.
- Can an AI client spend money on my account?
- No. Buying a plan, changing your payment method, editing your workspace settings, inviting a colleague and managing the connector's own tokens all refuse an AI client outright and answer with a sentence saying the change has to be made while signed in to the dashboard. That is enforced on the routes themselves rather than by instructing the model.
- Which HookSend plans include the MCP connector?
- The 15-day free trial and every paid plan, at no extra cost. It is not included on the Free plan a workspace moves to once the trial ends, and a lapsed paid plan cannot use it either. In both cases the connector answers with the reason rather than failing quietly, so your AI can tell you what happened.
- Does using the connector cost AI credits?
- A tool call itself costs nothing. The model doing the thinking runs on your own AI subscription, and HookSend does not charge credits for being asked to do something. HookSend's own AI features still spend credits exactly as they do from the dashboard: answering a DM from your uploaded documents, the AI step inside a flow, and the AI rules in Comment Guard.
- Is it safe to give an AI access to my Instagram automation?
- The risk is not Instagram, because the connector cannot reach Instagram except through the same code the dashboard uses, and Meta's rules are unchanged. The risk is an AI misunderstanding an instruction, which is what the boundaries are for: nothing is deleted, irreversible actions have to be confirmed, billing and colleagues are refused outright, your plan limits still apply, and every call is recorded. Start with the reading tools and one paused campaign.
- What happens if my token leaks?
- Revoke it in HookSend under Settings and it stops working on the next request. Only a SHA-256 fingerprint of a token is stored, so it cannot be read back out of HookSend by anybody, including support, and a leaked database would not hand an attacker something they could paste into a client. Tokens do not expire on their own, so revoke the ones belonging to clients you no longer use.
- Can I see what my AI did afterwards?
- Every tool call is recorded, including the ones that were refused, with how long it took and the arguments it was given. Anything whose field name reads like a secret, such as a token or an access key, is blanked before the record is written, because people do paste API keys into chats. Alongside that, each connected Instagram account's normal HookSend logs still show every DM that went out and why.