Comment-to-DM automation sends a direct message when someone comments a keyword on your Instagram post, Reel, or Story. For a brand, it means the Reel about one product can send that product’s page directly, instead of pointing everyone at a link in bio. You connect a Business or Creator account through Meta’s login, pick a trigger word, and write the DM. Setup takes under five minutes.
Disclosure: CreatorFlow is used as the example throughout because it shares a founder with DesignerBox, so its numbers can be stated exactly rather than guessed. The API rules below are Meta’s, not any vendor’s, and are linked at the bottom.
Key Takeaways
- Setup is three steps: connect the account, pick a keyword, write the DM. The tooling is not the hard part.
- The keyword decides whether it works. A per-campaign keyword like
DROP24fires only when someone follows your instruction.INFOfires on ambient comments and burns your allowance. - Meta’s documented ceiling is 750 private replies per hour per Instagram professional account, for comments on posts and reels (developers.facebook.com, July 2026).
- The 24-hour window is the constraint that bites. It also rules out restock alerts entirely, because One-time Notification is not available on Instagram’s API.
- Personal accounts cannot do this. The messaging API requires Business or Creator. Switching is free.
- Meta recommends telling people it is automated. Its policy says to do it even where no law requires it.
- The comment is the bottleneck, not the DM. If nothing triggers the automation, the automation is not the problem.
How comment-to-DM works under the hood
Three things happen, in order.
1. Meta sends your tool a webhook. When someone comments on your post, Meta notifies the connected app. The app checks the comment text against your keyword.
2. The app calls the Private Replies API. If the keyword matches, the app sends a private reply, which is a DM tied to that specific comment. This is a distinct API from normal messaging, and it exists so businesses can answer a public comment privately.
3. The DM lands in the commenter’s inbox. From there it is a normal conversation thread, governed by Meta’s standard messaging rules.
The important detail: the comment is what grants permission. It is an eligible action, so it opens a 24-hour window in which you may message that person. No comment, no permission. You cannot DM a customer who never engaged.
Set it up in five minutes
Step 1: Switch to a Business or Creator account
Meta’s messaging API does not work on personal accounts. In Instagram, go to Settings, then Account type and tools, then Switch to professional account. It is free and takes about two minutes. Both Business and Creator work. Most brand accounts are already Business.
Step 2: Connect through Meta’s login
A registered Meta provider connects with one click through Meta’s OAuth screen. You approve the permissions on Meta’s own page.
Never type your Instagram password into an automation tool, and never install a browser extension that acts as you. Both work against the platform instead of through it, and the account at risk is your brand’s. CreatorFlow is a Tech and Business Approved Meta Provider and has been since January 2026, which is the status worth checking on anything you evaluate (creatorflow.so, July 2026).
Step 3: Pick a keyword
This step decides whether the automation works, and most people rush it.
A good keyword is one nobody types by accident:
| Keyword | Fires on | Verdict |
|---|---|---|
INFO | ”any info on this?”, “more info please” | Too common, fires constantly |
LINK | ”drop the link”, “link?”, “send link” | Fires on natural comments, which can be fine or noisy |
SHOP | Ambient shopping comments | Workable, still leaky |
DROP24 | Nothing except your prompt | Precise |
For a brand, use one keyword per campaign, not one keyword forever. DROP24 on the spring launch and DROP25 on the next one keeps the reporting clean: link click tracking then tells you which drop drove which clicks, instead of merging them into one number you cannot act on.
Two rules. Say the keyword out loud in the caption and in the video, because people follow instructions they were given. And keep it short, because they type it on a phone.
Step 4: Write the DM
One message, one job. The link, and the reason they asked for it.
Lead with the payload. They commented because you promised something specific. Deliver it in the first line, not the third, after a greeting and a brand story.
Meta’s policy states that even where not legally required, businesses should inform users when they are interacting with an automated chat (developers.facebook.com, July 2026). A short line does it and costs nothing in conversion.
Step 5: Test it before the drop
Comment your keyword from a second account. If the DM does not arrive in a few seconds, the trigger word or the connection is wrong.
Find that out now, not at 9am on launch day with a Reel climbing.
The limits Meta actually publishes
Most articles in this category quote a limit that Meta does not document. Here is what the docs say.
| What | Documented limit | Source |
|---|---|---|
| Private replies to comments on posts and reels | 750 calls/hour per IG professional account | Meta Graph API rate limits |
| Private replies to Instagram Live comments | 100 calls/second per IG professional account | Meta Graph API rate limits |
| Send API, text/links/reactions/stickers | 300 calls/second per IG professional account | Meta Graph API rate limits |
| Send API, audio or video | 10 calls/second per IG professional account | Meta Graph API rate limits |
| Conversations API | 2 calls/second per IG professional account | Meta Graph API rate limits |
| Standard messaging window | 24 hours after an eligible user action | Meta messaging policy |
| Human Agent tag | Manual reply up to 7 days | Meta messaging policy |
| One-time Notification | Not available on IG Messaging API | Meta messaging policy |
All accessed July 2026.
On “200 DMs per hour”: this figure is repeated across the category and attributed to Instagram. It is not in Meta’s published limits. Automation tools pace below the documented ceiling deliberately, which is good engineering, and calling that pacing an Instagram rule is not accurate. Plan against 750 and expect your tool to run slower.
On the 24-hour window: this is the constraint that bites in practice. Meta gives a business up to 24 hours to respond after an eligible user action, and messages inside that window may contain promotional content (developers.facebook.com, July 2026). Outside it you need an approved message tag.
This rules out restock alerts. The tag built for “message me when it’s back” is One-time Notification, and Meta’s policy states it is not available for the IG Messaging API. A comment today cannot become a DM next week when stock lands. If that was the plan, use an email gate: capture the address inside the 24-hour window and send the restock note by email, on a channel you own.
Four things that break it
1. The account type. Personal accounts silently do nothing. Check this first.
2. The keyword is too common. If your trigger is INFO, every ambient comment fires it, you burn your DM allowance on people who did not ask, and the automation looks broken when it is working exactly as configured.
3. The cap, on drop day. Every plan has a ceiling, and you find it when a launch performs. On CreatorFlow, hitting the monthly DM limit pauses automations until the cycle resets, with a warning first and no messages lost. Pro and Growth can buy top-up packs of 1,000 to 5,000 DMs that never expire and activate automatically when the monthly allowance runs out (creatorflow.so/pricing, July 2026). Know the behaviour before a good launch finds the ceiling for you.
4. Nobody commented. This is the real one, and no tool fixes it.
The part automation cannot do
The trigger is a comment. If the post does not earn one, there is nothing to automate.
That is not a small caveat, it is the whole first half. The Reel has to be good enough that someone stops, watches, and types a word. That is a creative problem, and it is where the budget actually goes.
Each use case needs its own creative before it needs a keyword:
| The automation | The creative behind it | Where it comes from |
|---|---|---|
DROP24 on a launch Reel | Product video from one photo | Product Ad Generator |
| A SKU keyword on a product Reel | A PDP set worth landing on | Photo Angles |
LOOKBOOK on a fashion post | Styled scenes and flat lays | Flat Lay Studio |
FIT on an apparel Reel | On-model shots from a flat garment | Outfit to Image |
DesignerBox makes that half: one product photo becomes packshots, on-model shots, styled scenes, video, and social creative, built from your real product and on brand. An image is 5 credits.
Two gates worth knowing: a commercial license starts at Pro ($35/month), which is what selling from these assets requires, and try-on plus AI video start at Premium ($75/month).
If the comments are not coming, the fix is upstream. Scaling creative production and scaling ad campaigns cover producing enough variants to find the post that works. Brand consistency covers keeping them all looking like one brand.
What it costs
CreatorFlow’s Free plan runs comment-to-DM with 500 DMs a month, one Instagram account, Story reply automation, and unlimited keyword triggers, with no card and no expiry. Pro is $15/month for 5,000 DMs, two accounts, and the email gate. Growth is $30/month for 10,000 DMs, five accounts, and five team seats (creatorflow.so/pricing, July 2026).
Free is enough to answer the only question that matters at the start: will your audience actually type the word?
For the full comparison, see Instagram DM automation tools for brands. For the whole funnel and its arithmetic, see the Instagram DM funnel.
FAQ
How do I set up comment to DM on Instagram?
Switch to a Business or Creator account, connect it to a Meta-approved automation tool through Meta’s OAuth login, pick a trigger keyword, and write the DM. Test it by commenting the keyword from a second account. The whole process takes under five minutes on a tool like CreatorFlow, whose Free plan supports comment-to-DM at 500 DMs a month.
What is the Private Replies API?
It is Meta’s API for replying privately to a public comment, and it is what comment-to-DM automation runs on. Meta documents 750 calls per hour per Instagram professional account for private replies to comments on posts and reels, and 100 calls per second for private replies to Instagram Live comments (developers.facebook.com, July 2026).
What keyword should I use for a product drop?
One nobody types by accident, and a new one per campaign. DROP24 fires only when someone follows your instruction, and it keeps click tracking per-campaign instead of merging every launch into one number. Avoid INFO and SHOP, which fire on ambient comments and waste your DM allowance. Say the keyword in the caption and in the video.
How long do I have to reply to someone on Instagram?
24 hours from an eligible user action, under Meta’s standard messaging policy. Messages inside that window may include promotional content. Past 24 hours you need an approved message tag, such as the Human Agent tag, which allows a manual reply for up to 7 days (developers.facebook.com, July 2026).
Can I automate a restock alert with comment to DM?
No. The 24-hour window closes long before most restocks land, and One-time Notification, the tag designed for follow-up outside the window, is not available on the Instagram Messaging API (developers.facebook.com, July 2026). Use an email gate to capture the address inside the window, then send the restock note by email.
Will comment to DM automation get my account banned?
Not when it runs on Meta’s official API through a registered provider. Meta publishes rate limits and a messaging policy for exactly this use case. The risk comes from tools using browser extensions or asking for your password, which operate against the platform rather than through it.
Sources
- Instagram Private Replies API, Send API, and Conversations API rate limits: Meta Graph API Rate Limits (accessed July 2026)
- 24-hour standard messaging window, message tags, One-time Notification unavailability on IG, Human Agent tag, and automation disclosure guidance: Messenger Platform and IG Messaging API policy (accessed July 2026)
- CreatorFlow Meta provider status and feature list: creatorflow.so (accessed July 2026)
- CreatorFlow pricing, DM limits, cap behaviour, and top-up packs: creatorflow.so/pricing (accessed July 2026)
- DesignerBox pricing, credit costs, and feature gating: designerbox.ai/pricing