All posts
API guide· 7 min·

Instagram's 24-Hour Window vs the 7-Day Private Reply Window

Two different messaging windows govern Instagram automation, and confusing them is why most auto-DM setups fail on non-followers. What each one covers, when each starts, and which API opens which.

Quick answer

Instagram has two messaging windows. The standard 24-hour window opens when someone DMs your business and lets you reply freely for 24 hours. The Private Reply window is separate: replying to a comment by comment ID opens 7 days. Comment-to-DM works on non-followers because it uses the second one, not the first.

Short version: Instagram runs two separate messaging windows. The 24-hour window opens only when someone DMs you first. The Private Reply window opens when you reply to a comment by its comment ID, lasts 7 days, and works on people who do not follow you. Nearly every "my auto-DM will not send" problem is the first being used where the second was needed.

Meta's Private Replies documentation, describing the 7-day window and Inbox versus Requests delivery

The two windows, side by side

Standard messagingPrivate Reply
Opens whenSomeone DMs your accountYou reply to their comment
Addressed byuser idcomment id
Duration24 hours7 days
Works on non-followersNoYes
Live broadcastsn/aDuring the broadcast only

Why this trips people up

The 24-hour rule is the one everyone reads about first, because it is the headline policy in most Instagram messaging guides. So when a comment-to-DM setup fails, the natural conclusion is "the window closed."

It usually did not close. It never opened. A person who commented on your reel has not sent you a DM, so there is no 24-hour window in the first place. The standard messaging endpoint has nothing to work with and returns *This message is sent outside of allowed window.*

The fix is the addressing, not the timing

The same message, addressed differently, succeeds:

POST /<ig-business-id>/messages
{ "recipient": { "comment_id": "<comment-id>" }, "message": { ... } }

Because the recipient is identified by `comment_id`, Meta treats the comment as the qualifying interaction and grants a 7-day window. Per Meta's own documentation, the reply lands in the Inbox folder for followers and in Requests for non-followers.

The AutoDM rule builder, where the public comment reply and the private DM are configured as separate steps

The Live exception worth knowing

Everything above holds for posts, reels and stories with a clean 7 days. Instagram Live is the exception: the private reply must go out while the broadcast is still live. This is not a rate limit or a policy nuance, it is a hard constraint in the API, and it means Live automation has to fire in real time rather than batch afterwards.

What this means practically

If you are building this yourself, the checklist is short: address by comment id, handle the Live constraint separately, and expect non-follower replies to sit in Requests rather than Inbox. If you would rather not maintain that, AutoDM does it on the official API.

Frequently asked

What is the Instagram 24-hour messaging window?▾
When someone sends your business account a DM, Meta opens a 24-hour window in which you can reply freely with any message type. After it closes you cannot send a standard message; you need an approved template or another qualifying interaction. This window only ever opens from an inbound DM, which is why it does not help with comment-based automation.
How is the Private Reply window different?▾
A private reply is addressed by comment ID rather than user ID. Sending one opens a 7-day messaging window with that person, and it works whether or not they follow you. This is the mechanism behind comment-to-DM: the comment itself is the qualifying interaction, so no prior DM is needed.
Why do my auto-DMs fail on people who do not follow me?▾
Almost always because the send is going through the standard messaging API, which requires an open 24-hour window that a non-follower has never opened. The error reads "This message is sent outside of allowed window." Addressing the recipient by comment_id instead of user_id routes it through Private Replies and the send succeeds.
Does the Private Reply window work during Instagram Live?▾
Yes, with one constraint that catches people out: for a Live broadcast the private reply must be sent while the broadcast is still running. Once the Live ends, the opportunity closes. For ordinary posts and reels you have the full 7 days from the comment.
Does a follower get treated differently from a non-follower?▾
The window is the same 7 days either way, but delivery differs. A private reply to someone who follows you lands in their main Inbox. For a non-follower it lands in Requests. Both are delivered; the follower simply sees it sooner. This is per Meta's Private Replies documentation.
Can I send more than one message in the 7-day window?▾
The private reply itself is a single message per comment. What it buys you is an open conversation for 7 days, so any follow-up runs as normal messaging inside that window. That is how a follow-up sequence works without needing another comment from the user.

Sources

Stop debugging Meta's API. Start sending.

StackPicks AutoDM ships with Private Reply, follower-aware bodies, account warming, and an AI conversation agent that replies to inbound DMs in your voice. 90-second setup. No browser bots.

Connect Instagram

More from the blog

Instagram's 24-Hour Window vs the 7-Day Private Reply Window — StackPicks