NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Fast and effective Instagram Private API wrapper
Last release today
04 Oct 2026
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
430 releases · first in 2020
One column per quarter.
Use native Android 449 profile and preserve CAA login context by @subzeroid in #2855
Full Changelog: 3.0.19...3.0.20
fix: clear stale account headers when resetting authorization by @subzeroid in #2851
Full Changelog: 3.0.18...3.0.19
fix: pair CAA two-step context with its parameter key by @subzeroid in #2849
Full Changelog: 3.0.17...3.0.18
two_step_verification_context with its matching parameter value when CAA fields are reordered, preserving scalar positions and reading nested static server_params. Require exact quoted app references and retain the existing JSON fallback and action-only two-step scope (#2849).fix: preserve per-attempt CAA login diagnostics by @subzeroid in #2846
Full Changelog: 3.0.16...3.0.17
ClientError.code for 4xx/5xx responses while keeping response payloads and report-flow errors intact (#2847).test: keep password encryption regression offline by @subzeroid in #2843
Full Changelog: 3.0.15...3.0.16
highlight_info() validation when the top-level owner’s friendship_status omits user_id. Normalize the owner with the existing short-user extractor while preserving relationship values and story order (#2844; fixes #2837).fix: preserve nested CAA verification contexts by @subzeroid in #2841
Full Changelog: 3.0.14...3.0.15
server_params contexts during CAA profile-code verification, avoiding missing code_entry context_data for that response shape (#2841). Preserve operand positions and ignore non-literal or unrelated contexts. This does not establish a general fix for needs_upgrade or other challenge routes.build: bump github/codeql-action from 4.38.0 to 4.38.1 by @dependabot [bot] in #2830
Full Changelog: 3.0.13...3.0.14
media_info_gql() for the optional public_transport="curl" path using the current PostRoot document, fb_dtsg token, and browser headers (#2835). The default requests transport still received HTML for the sampled GraphQL call; private media lookup is unchanged.needs_upgrade type and known outdated-app message category in the sanitized examples/diagnose_login.py report (#2834). This diagnostic change does not alter login behavior or resolve #2807.user_medias*_gql() uses app GraphQL first and public GraphQL as a fallback (#2833).fix: normalize carousel resource IDs in profile GraphQL responses by @subzeroid in #2831
Full Changelog: 3.0.12...3.0.13
user_medias_gql() accepts children with a composite id and no pk (#2831). Explicit resource IDs and validation of identifier-free children are preserved.fix: require curl-adapter 1.2.3 for public transport by @subzeroid in #2827
Full Changelog: 3.0.11...3.0.12
public_transport="curl" response-body reads with urllib3 2.8 by requiring curl-adapter>=1.2.3. This also fixes password-encryption key fetching through that transport (#2827; thanks to @marnelle1 for the report).fix: reuse saved sessions for related profile queries by @subzeroid in #2824
Full Changelog: 3.0.10...3.0.11
user_related_profiles_gql() request, so related-profile lookup no longer depends on an earlier public lookup having copied the session (#2824).user_short_gql() and user_info_v2_gql() lookups with the current shared web profile query and complete Relay variables. Remove the short-profile friendly-name override that caused HTML responses in verified requests (#2825).fix: preserve errors from CAA login fallback by @subzeroid in #2819
Full Changelog: 3.0.9...3.0.10
needs_upgrade or BadPassword. Keep the original legacy error when the CAA endpoint is unavailable or returns no session.crosspost: null or coauthor_producers: null as empty lists, avoiding validation and extraction errors while preserving valid values and rejecting malformed values (#2821, #2822).This patch separates HTTP timeouts from request pacing in download, share-link, public HEAD and legacy DTSG helpers.
This patch separates HTTP timeouts from request pacing in download, share-link, public HEAD and legacy DTSG helpers.
request_timeout keeps its existing delay behavior. Configure the affected HTTP waits independently with the new runtime attribute read_timeout, which defaults to 25 seconds:
client = Client(request_timeout=0)
client.read_timeout = 30read_timeout is assigned on the client; it is not a constructor option or a saved setting. The usage guide lists its exact scope.
The login guides also clarify the existing CAA-to-legacy transition: it follows an explicit fallback instruction from Instagram.
Thanks to @marnelle1 for reporting the timeout ambiguity in aiograpi #455. Fixed in #2817.
request_timeout pacing delay in download, share-link, public HEAD, and legacy DTSG helpers. Their read_timeout defaults to 25 seconds and can be changed independently of request pacing (#2817, thanks to @marnelle1 for the report).fix: isolate caches between Client instances by @subzeroid in #2813
Full Changelog: 3.0.7...3.0.8
Client, so one client cannot reuse or clear another client's cached data (#2813).user_highlights() and user_highlights_v1() respect positive amount limits before parsing the returned tray. amount=0 continues to return all Highlights (#2814).feat: default to the current Android 448 app profile by @subzeroid in #2812
Full Changelog: 3.0.6...3.0.7
448.0.0.0.20 (version_code 1065560286, captured bloks_versioning_id). New clients present the current app version by default, avoiding the server-side "Your version of Instagram is out of date" login gate reported in #2807. Saved 446 sessions keep resolving; the 446 profile remains explicitly selectable via set_app("446.0.0.49.77") (#2812).fix: align clip configure payload with current app shape by @subzeroid in #2808
Full Changelog: 3.0.5...3.0.6
clip_configure) with the current Android app: send clips_segments_metadata, clips_audio_metadata, additional_audio_info, nested edits, and the current capture metadata fields; drop media_folder and date_time_original the app no longer sends (#2808).rich_text_format_types: ["modern_refreshed_v2"] and matching text_metadata fields (#2809).media_upload_status(post_client_id) polls media/get_upload_status_REST/ for asynchronous clip/story publishing until COMPLETED, and video_refresh_resources(media_id) returns a fresh video_versions list when previously returned video URLs have expired (#2810).fix: refresh follow-list GraphQL doc_ids by @subzeroid in #2806
Full Changelog: 3.0.4...3.0.5
FollowersList/FollowingList doc ids to the ones the current Android app sends (284797047911918316998205836755, 16104639286363954576550227636); the previous ids still resolve but are one generation behind (#2798).fix: preserve fbns_auth in get_settings and dump_settings by @subzeroid in #2804
Full Changelog: 3.0.3...3.0.4
get_settings() now returns fbns_auth from the live FBNS auth object when present (falling back to previously saved values), so dump_settings()/load_settings() preserve the FBNS device auth across a settings round trip. Mirror of the aiograpi 2.0.4 fix.feat: expose instagrapi. version from package metadata by @subzeroid in #2796
Full Changelog: 3.0.2...3.0.3
login() now follows Instagram's CAA fallback instruction (CAA_LOGIN_FALLBACK:fallback_triggered) and completes the legacy accounts flow, so typed failure reasons such as PleaseWaitFewMinutes or BadPassword surface instead of the generic "CAA login did not return a session" error (#2800).ClientError raised by CAA login now carries the observed CAA step markers as caa_actions (for example CAA_LOGIN_FORM:account_list) for diagnostics.This patch release fixes Reels feed parsing and pagination in reels() , explore_reels() and friends_reels() .
This patch release fixes Reels feed parsing and pagination in reels(), explore_reels() and friends_reels().
items_with_ads media responses when legacy items is empty or absent (#2784).amount, including on the final page (#2785).last_media_pk when media IDs arrive as strings, stopping before the matching media (#2787).The fixes were checked individually and together, including regression tests and offline replay of previously captured responses. No new live login or upload was performed for this release.
Install with pip install -U instagrapi.
items_with_ads responses when legacy items is empty or absent, avoiding empty results and unnecessary pagination. Existing feed ordering and cursor behavior are preserved.Fix a qe/expose/ 404 that could raise an error after Instagram had already successfully configured an upload.
Fix a qe/expose/ 404 that could raise an error after Instagram had already successfully configured an upload.
expose() API remains available.Thanks to @brianlaihkhk for reporting the issue and providing the traceback in #2790.
Included in #2794. Install with pip install -U instagrapi.
qe/expose/ request, preventing an exposure endpoint error from hiding a successful upload (#2790).Breaking: Make login() use CAA directly; retain the previous login flow and arguments as login_legacy(). Default login does not automatically fall bac
Breaking: Make login() use CAA directly; retain the previous login flow and arguments as login_legacy(). Default login does not automatically fall back to legacy login.
Reject CAA login with a clear error before preflight when saved app settings lack the required Bloks hash; document explicit app-profile migration.
Breaking: Use curl_cffi and private HTTP/2 by default and install curl_cffi as a runtime dependency. Preserve explicit saved transport choices and the private_transport="requests" compatibility option.
Update the default Android app profile to Instagram 446.0.0.49.77 while retaining the previous 428.0.0.47.67 profile for saved settings and explicit selection.
Try the existing CAA login flow when login_legacy() returns needs_upgrade, preserving the original error if no session or supported two-factor flow is available.
The optional private curl transport now advertises the hybrid X25519MLKEM768 TLS group alongside X25519 , P-256 and P-384 . This addresses TLS connect
The optional private curl transport now advertises the hybrid X25519MLKEM768 TLS group alongside X25519, P-256 and P-384. This addresses TLS connection failures on proxy paths that reject a classical-only ClientHello. The transport continues to offer only h2 through ALPN.
Install or upgrade with:
pip install -U "instagrapi[curl]==2.18.20"Enable the transport with Client(private_transport="curl"). Authentication handling and the default transport are unchanged.
Includes #2788.
X25519MLKEM768 TLS group in the optional private curl transport to address connection failures on proxy paths that reject a classical-only ClientHello. Preserve classical groups and h2-only ALPN; this changes TLS reachability, not authentication handling.v2.18.18 docs: capture login errors before CAA fallback overwrites them by @subzeroid in #2781
Full Changelog: 2.18.18...2.18.19
Client(private_transport="curl") and the curl extra. TLS offers only h2; private requests retain mobile headers, proxy configuration, cookies and saved device settings. The default transport and login routing remain unchanged. See the private transport guide.The transport change addresses a verified transport-sensitive CAA failure mode. It does not remove account restrictions or guarantee successful login. Follow issue #2778 for the remaining investigation.
build: bump ruff from 0.16.3 to 0.16.4 by @dependabot [bot] in #2775
Full Changelog: 2.18.17...2.18.18
build: bump ruff from 0.16.2 to 0.16.3 by @dependabot [bot] in #2771
Full Changelog: 2.18.16...2.18.17
fix: restore direct CAA login preparation by @subzeroid in #2769
Full Changelog: 2.18.15...2.18.16
build: bump pre-commit from 4.6.1 to 4.6.2 by @dependabot [bot] in #2767
Full Changelog: 2.18.14...2.18.15
fix: retry current CAA login after legacy bad password by @subzeroid in #2766
Full Changelog: 2.18.13...2.18.14
build: bump github/codeql-action from 4 to 4.37.3 by @dependabot [bot] in #2756
Full Changelog: 2.18.12...2.18.13
Fix saved session validation during login by @subzeroid in #2753
Full Changelog: 2.18.11...2.18.12
feat: add Facebook and Threads crossposting by @subzeroid in #2750
Full Changelog: 2.18.10...2.18.11
build: bump pre-commit from 4.6.0 to 4.6.1 by @dependabot [bot] in #2745
Full Changelog: 2.18.9...2.18.10
Add Client.account_set_ai_info(enabled) to manage the account-level AI-generated disclosure label.
docs: explain incoming quicksnaps in Direct by @subzeroid in #2735
Full Changelog: 2.18.7...2.18.8
build: bump mkdocstrings from 1.0.4 to 1.0.5 by @dependabot[bot] in https://github.com/subzeroid/instagrapi/pull/2729
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.18.6...2.18.7
feat: add QuickSnap support by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2731
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.18.5...2.18.6
fix: wrap unavailable CAA Bloks login endpoint by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2728
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.18.4...2.18.5
fix: preserve recovery bad password during login by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2726
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.18.3...2.18.4
fix: fail fast for native challenge checkpoints by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2720
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.18.2...2.18.3
fix: unblock realtime socket reads on disconnect by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2719
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.18.1...2.18.2
Keep FBNS connected on read timeout by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2717
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.18.0...2.18.1
Expose Threads badge user fields by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2716
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.17.2...2.18.0
Fix FBNS cleanup after socket failures by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2715
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.17.1...2.17.2
Fix media extraction when video_versions is null by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2714
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.17.0...2.17.1
feat: support linked reels by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2712
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.26...2.17.0
build: bump ruff from 0.15.18 to 0.15.20 by @dependabot[bot] in https://github.com/subzeroid/instagrapi/pull/2707
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.25...2.16.26
Fix sponsor tag friendship status normalization by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2702
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.24...2.16.25
docs: expose user report reason literal by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2700
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.23...2.16.24
types: use enum for note audience by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2699
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.22...2.16.23
docs: expose notification setting value literal by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2698
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.21...2.16.22
docs: expose followers order literal by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2697
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.20...2.16.21
docs: expose user block surface literal by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2696
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.19...2.16.20
docs: expose direct media type literal by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2695
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.18...2.16.19
docs: expose music product literal by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2694
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.17...2.16.18
docs: expose insights literal aliases by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2693
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.16...2.16.17
Type Direct media share send attribute by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2692
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.15...2.16.16
Type notification content settings by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2691
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.14...2.16.15
Type public option literals by @subzeroid in https://github.com/subzeroid/instagrapi/pull/2690
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.13...2.16.14
build: bump pytest from 9.1.0 to 9.1.1 by @dependabot[bot] in https://github.com/subzeroid/instagrapi/pull/2688
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.12...2.16.13
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.11...2.16.12
Full Changelog: https://github.com/subzeroid/instagrapi/compare/2.16.11...2.16.12
Your coding agent can read these notes before it upgrades. Set up the MCP server →