In development

Connected.And still connected.

Connecting an Instagram account is the easy part. Knowing it is still working three months later — before a customer tells you it is not — is the product.

Scroll
The surface

Every channel, its real state, and how long it has left — on one screen you do not have to go looking for.

social / channels Interface preview
@acme.studio connected · last webhook 4 min ago 54 days
@acme.shop connected · token expires soon 3 days
@acme.labs disconnected at the provider · needs you Reconnect
@acme.press connecting · waiting for Instagram In progress
One account needs attention before it stops posting DisconnectReconnect @acme.labs

A preview of the working surface. The product is in development.

How it works
  1. Sign in, then connect — separately

    Google tells us who you are. Instagram authorisation is a second, explicit step, taken when you need it and never bundled into signing in.

  2. Connect the account

    You are handed to Instagram, you approve there, and you come back to a connection that is recorded against your workspace and nobody else's.

  3. The provider tells us the truth

    Connection state is driven by webhooks from the provider, not by a hopeful flag we set at connect time. When an account drops at Instagram's end, the screen changes without you refreshing it.

  4. Expiry is visible long before it bites

    Every connection shows how long it has left. A token running out is a scheduled event you can see coming, not an outage you discover from a customer.

  5. Reconnect or disconnect cleanly

    Reconnecting is one action from the same screen. Disconnecting removes the stored credentials, and you can revoke us from Instagram's side independently at any time.

What is underneath

The provider is replaceable by design

Everything above a single ChannelProvider interface is written against that interface, never against the vendor. Today it is served by a third party; moving to Meta's own API is a new implementation of that interface and no change above it.

Webhooks are the source of truth

account.connected and account.disconnected drive the state machine. Nothing infers health from the last time an action happened to succeed.

Credentials are never stored in the clear

Third-party tokens are encrypted before they are written and decrypted only to perform something you asked for. A copy of the database is not a copy of your accounts.

Isolation the database enforces

Every row carries the workspace that owns it, and PostgreSQL row level security refuses the rest. The runtime role is created without the privilege to bypass it, so a bug in a query cannot leak another customer's channels.

One origin, one session

The interface is served from the same origin as its API, so the session cookie and both OAuth redirects land in one place. There is no cross-site token relay to get wrong.

Its own data, entirely

This product owns its schema outright and shares no tables with the others. It can leave for its own repository and database without touching anything else.

Where it actually is
01

The connection lifecycle works end to endSign-in, onboarding, the Instagram login connect flow, both webhooks, the channel list, the connection detail view, reconnect and disconnect are all implemented and running.

02

Some of it is not built yetThe Facebook login route, headless mode, ads activation and the periodic health reconciliation worker are not there. Health today is driven by webhooks rather than by a background sweep.

03

It will not post on your behalf uninvitedConnecting an account authorises actions you direct. You can disconnect from here, and revoke access from Instagram directly, at any time.

Elsewhere