Meta App Review
Meta Advanced Access is a gated permission tier required for any app that serves real users at scale on Facebook, Instagram, or WhatsApp. Without it, your app is limited to test users and developers only — it cannot access real customer data or perform actions on behalf of actual accounts. Getting Advanced Access approved is the outcome of Meta App Review, and Meta App Review is one of the most documentation-intensive, screened processes in any developer platform. This guide covers what Advanced Access is, which permissions require it, why applications get rejected, and what it actually takes to pass.
Standard Access vs. Meta Advanced Access
Every Meta API permission exists at two tiers. Understanding the difference matters before you build anything.
Standard Access
Automatically available. Works only with test users, developers, and admins explicitly added to your app. Hard rate limits apply. Suitable for development and testing — not for production.
Advanced Access
Requires Meta App Review approval. Once approved, your app can access data for any real user who grants the permission. Required for any live production integration with real customers.
The distinction is critical: an app can look fully functional in development on Standard Access and then fail completely when it goes live because real users are not test users. Many developers only discover this after launch.
Permissions That Require Meta Advanced Access
These are the most commonly requested permissions that require Advanced Access for production use. Each one requires a separate App Review submission with supporting documentation and a screencast.
- pages_messaging — Required for Facebook Messenger chatbot integrations serving real Page users
- instagram_manage_messages — Required for Instagram DM automation and inbox management at scale
- whatsapp_business_messaging — Required for WhatsApp Business API SaaS platforms serving multiple WABA accounts
- instagram_content_publish — Required for posting to Instagram on behalf of real business accounts
- pages_manage_posts — Required for publishing to Facebook Pages for real accounts
- instagram_manage_insights — Required for reading Instagram analytics for real accounts
- leads_retrieval — Required for accessing Facebook Lead Ads form submissions
- business_management — Required for managing Business Managers on behalf of real clients
What the Meta App Review Process Actually Involves
App Review for Advanced Access is not a simple form. Each step requires specific materials, and a gap in any one of them is grounds for rejection — even if your app is technically sound.
1
App configuration must be complete — Privacy policy URL, app icon, app category, and data use checkboxes must all be set correctly before a submission is even accepted. Missing or mismatched fields cause immediate rejection before review begins.
2
Request each permission individually — In App Review → Permissions and Features, you request Advanced Access per permission. Each permission requires its own justification, screencast, and use-case description. You cannot bundle permissions with a single generic explanation.
3
Record a screencast for each permission — This is the most critical and most commonly failed requirement. The screencast must show a real user flow: login or account connection, the specific feature that triggers the permission, and evidence that data is used only for the stated purpose. Meta's reviewers check this carefully — a vague or incomplete screencast is the most common rejection reason.
4
Write the use-case description — For each permission, you must explain exactly how your app uses the data, why that specific permission is the minimum necessary, and how you comply with Meta's Platform Terms and Developer Policies. Vague descriptions (“we use it to improve user experience”) are rejected.
5
Submit and wait for review — Standard review is 3–7 business days. If rejected, Meta provides a reason and you must revise and resubmit — each cycle takes additional days. Submissions that require clarification can take significantly longer.
Common Rejection Reasons for Meta Advanced Access
Screencast does not clearly show the specific permission being exercised — Meta reviewers cannot identify the feature that uses the data
Privacy policy doesn't explicitly mention the Meta APIs or permission data collected — a generic privacy policy is not sufficient
Use-case description is vague, generic, or doesn't explain why that specific permission is the minimum required
App appears to collect or store more data than the stated use case requires — scope creep signals non-compliance
App is not live or testable — reviewers need a working product to verify the stated use case exists
Test user credentials not provided — Meta reviewers need a way to log into a test version of your app to verify the flow shown in the screencast
App Review Rejected or Preparation Unclear?
Screencast preparation, policy alignment, and use-case documentation — these are the exact areas where most rejections happen and where professional preparation makes the difference.
WhatsApp Me Now
Meta Advanced Access by Platform
For Facebook Messenger: The pages_messaging permission requires Advanced Access for any chatbot or automation tool that interacts with real Page followers — not just the Page admins. This applies to any SaaS platform with Messenger features.
For Instagram: Both instagram_manage_messages and instagram_content_publish require separate Advanced Access approvals. If your app does both DM management and content publishing, that is two separate permission review cycles.
For WhatsApp Business API SaaS: The whatsapp_business_messaging permission requires Advanced Access when your app manages multiple WhatsApp Business Accounts. This is the requirement that catches most SaaS platforms — Standard Access only covers a single WABA tied to your own Business Manager.
See the relevant service pages for platform-specific submission guidance: Facebook API Approval, Instagram API Approval, or the full API Approval Services list.
Professional Meta Advanced Access Approval Support
Meta App Review is not a process where effort alone guarantees a result. The review is documentation-driven and screencast-driven — the quality, precision, and policy alignment of what you submit determines the outcome. A technically perfect app with a poor screencast or incomplete privacy policy will be rejected the same as an incomplete app.
Professional approval support covers: reviewing your app configuration for submission-blocking issues, preparing a compliant privacy policy that references Meta API data, scripting and recording the screencast to Meta's requirements, writing use-case descriptions for each permission in the format Meta's reviewers expect, and handling resubmission if a rejection occurs. For Beepost and similar tools needing both instagram_content_publish and pages_manage_posts, a dedicated Beepost app approval service covers the full submission.
Frequently Asked Questions
What is Meta Advanced Access?
Meta Advanced Access is the higher permission tier for Meta APIs. Unlike Standard Access (which is limited to test users and developers), Advanced Access allows your app to access data for any real user who grants the permission. It requires passing Meta App Review for each permission you request.
Does every Meta API permission require Advanced Access?
No. Some permissions are available to all apps without review. But production-critical permissions — including pages_messaging, instagram_manage_messages, whatsapp_business_messaging, instagram_content_publish, and others — require Advanced Access approval before your app can use them with real users.
What does Meta's App Review team actually check?
Reviewers check: your screencast (does it show the permission being used in a real user flow?), your privacy policy (does it mention the specific data collected via Meta APIs?), your use-case description (is the reason for the permission specific and policy-aligned?), and whether your app is live and testable. Any gap in these areas is grounds for rejection.
Why was my Meta Advanced Access request rejected?
The most common reasons: the screencast didn't clearly show the permission being used, the privacy policy was generic and didn't mention Meta API data, or the use-case description was too vague. A rejection notice from Meta will specify the reason — but the explanation is often brief and requires interpretation.
How long does Meta App Review take?
Typically 3–7 business days for the initial review. If rejected and resubmitted, each cycle takes additional days. Submissions requiring clarification from Meta can take several weeks across multiple cycles.
Do I need a separate Advanced Access request for each permission?
Yes. Each permission requires its own screencast, use-case description, and justification. You cannot submit one explanation for multiple permissions — each is reviewed independently. If your app needs three permissions, you need three separate, complete submissions.