All posts
API guide· 6 min·

Instagram Message Tags in 2026 — CONFIRMED_EVENT_UPDATE Is Gone, HUMAN_AGENT Is What Is Left

Meta removed the CONFIRMED_EVENT_UPDATE message tag in April 2026, and using deprecated tags now triggers restrictions. Here is which tags survive, what HUMAN_AGENT actually permits, and how to audit your integration.

Quick answer

Meta removed the CONFIRMED_EVENT_UPDATE message tag on 27 April 2026, and sending messages with deprecated tags can now trigger account restrictions. HUMAN_AGENT remains the most useful surviving tag: it permits a human-composed reply up to 7 days after the user's last message. Tags never permit promotional content outside the 24-hour window.

Message tags are the least glamorous part of Instagram automation and one of the fastest ways to get an account restricted. Meta removed CONFIRMED_EVENT_UPDATE on 27 April 2026, and using deprecated tags is now treated as a policy signal rather than a harmless integration bug.

If you maintain your own Graph API integration, this is a 20-minute audit worth doing today.

Hand holding a phone with Instagram open

What tags are for (and what they are not)

By default, you can only message an Instagram user within 24 hours of their last message to you. That is the standard messaging window.

Tags are narrow exceptions to that window for specific, non-promotional purposes. They are not a general-purpose extension, and Meta is unambiguous: no tag permits promotional content outside the window.

Two things follow:

  • A tag is a declaration about *why* you are messaging. Declaring falsely is the violation.
  • If your reason is "I want to sell them something later," no tag covers it.

The one that matters: HUMAN_AGENT

For automation tools, HUMAN_AGENT is the tag that carries real weight. It permits a human-composed reply up to 7 days after the recipient's last message.

The intent is customer support: a real person reads the query and writes back. That is a genuinely common need — someone DMs a question at 2 AM Sunday, you answer Monday morning.

The line is bright and worth stating plainly: HUMAN_AGENT means a human wrote this message. Using it to deliver bot-generated marketing misrepresents the message to Meta. That misrepresentation is precisely what enforcement systems are built to catch.

In StackPicks AutoDM, the manual reply box in your Inbox sends with HUMAN_AGENT — because you typed it. Our AI follow-up agent does not use that tag; it operates inside the standard window where no tag is needed.

Comment-triggered DMs need no tag at all

This is the most common integration mistake we see.

If someone comments on your post and you want to DM them, you do **not** need a message tag. You need the Private Reply API, which addresses the recipient by comment_id and grants a 7-day window on its own.

Reaching for a tag to send a *first* message to a commenter means you are using the wrong endpoint.

Rule of thumb:

  • First message to a commenter → Private Reply, no tag
  • Reply inside 24h of their message → standard messaging, no tag
  • Human reply up to 7 days after their message → HUMAN_AGENT
  • Anything promotional outside 24h → not permitted, full stop

Developer reviewing data on printed reports beside a phone

How to audit your integration

  1. Grep your codebase for every tag string you send
  2. Compare that list against Meta's current documented tags — delete anything missing
  3. Search your logs for HTTP 400 responses mentioning tags
  4. Confirm your comment-to-DM path sends no tag at all

Step 3 catches the sneaky case: a rarely-hit code path with a hardcoded deprecated tag that has been quietly failing for months.

Why this list will change again

Meta adjusts the tag set periodically, and the removal cadence has accelerated. Anything you read about message tags — including this post — should be checked against the official Messenger Platform documentation before you ship.

We date our posts and re-audit them for exactly this reason. This one is current as of 6 August 2026.

Frequently asked

What message tags does Instagram still support in 2026?▾
HUMAN_AGENT is the one most automation tools rely on — it allows a human-reviewed reply within 7 days of the user's last message. Account update and post-purchase style tags remain for transactional messaging where applicable. CONFIRMED_EVENT_UPDATE was removed on 27 April 2026. Because Meta adjusts this list, treat the official Messenger Platform documentation as the source of truth rather than any blog post, including this one.
What does the HUMAN_AGENT tag actually permit?▾
It permits a message composed by a human, not by a bot, sent up to 7 days after the recipient's last message. The intent is customer support: a person reads the query and writes a reply. It is not a loophole for delayed marketing. If you use HUMAN_AGENT to deliver automated promotional content, you are misrepresenting the message to Meta, which is exactly the pattern enforcement looks for.
What happens if I use a deprecated message tag?▾
The call may fail outright, and repeated use is treated as a policy signal rather than a harmless bug. Meta has been explicit that using deprecated tags after the removal date can trigger account restrictions or bans. If you maintain your own integration, audit every tag string you send — a hardcoded CONFIRMED_EVENT_UPDATE left in a code path that fires rarely is exactly the kind of thing that surfaces months later.
Do I need a message tag for comment-triggered DMs?▾
No. Comment-triggered DMs should use the Private Reply API, which addresses the recipient by comment ID and grants a 7-day window without any tag. Tags are for re-engaging an existing conversation outside the standard 24-hour window. Mixing the two up is a common integration bug — if you find yourself reaching for a tag to send a first message to a commenter, you want Private Reply instead.
How do I audit my integration for deprecated tags?▾
Grep your codebase for every tag constant you send, list them against Meta's current documented set, and remove anything not on it. Then check your logs for HTTP 400 responses mentioning tags — those are calls already failing. Finally, confirm which code paths set a tag at all: most comment-to-DM flows should send none, because Private Reply does not need one.

Sources

Stop debugging Meta's API. Start sending.

StackPicks AutoDM ships with Private Reply, follower-aware bodies, account warming, and an AI conversation agent that replies to inbound DMs in your voice. 90-second setup. No browser bots.

Connect Instagram

More from the blog

Instagram Message Tags in 2026 — CONFIRMED_EVENT_UPDATE Is Gone, HUMAN_AGENT Is What Is Left — StackPicks