# Instagram API Error 1545133, 2534037 & 2534014: Fix 'Connected Tools' & 24-Hour Window Blocks

> Step-by-step fix for Instagram Graph API Error 1545133 (Allow Access to Messages disabled), Error 2534037, Error 2534014, and OAuth code 190 token drops in 2026.

- **Canonical URL:** https://rapiddm.com/blog/instagram-error-1545133-2534037-dm-automation-troubleshooting
- **Author:** RapidDM
- **Published:** 2026-09-28T10:15:00+05:30
- **Updated:** 2026-09-28T13:15:00+05:30
- **Tags:** Instagram Graph API, Troubleshooting, Error Codes, Meta Permissions

---

When an Instagram DM automation stops sending messages—even though your account shows "Connected" in your dashboard—the underlying Meta Graph API error almost always comes down to one of four specific subcodes: **`1545133`**, **`2534014`**, **`2534037`**, or **`190 (subcode 460)`**.

Here is what each error code means inside Meta's messaging infrastructure and the exact steps to fix it.

## Quick reference: Instagram messaging error subcodes

| Error code / subcode | Official Meta API message | Root cause | Time to fix |
| --- | --- | --- | --- |
| 1545133 (code: 10) | Application does not have permission for this action | "Allow Access to Messages" toggle is turned OFF inside the Instagram mobile app | 30 seconds |
| 2534014 (code: 10) | Message cannot be sent outside allowed window | More than 24 hours have passed since the user last messaged you or tapped a button | Workflow change |
| 2534037 (code: 100) | The recipient is not eligible to receive this message | Recipient privacy lock, unread Message Request, or age-gated account restriction | Skip & public reply |
| 190 / 460 (OAuth) | Error validating access token: Session invalidated | You changed your Instagram password, updated 2FA, or switched account types | 1 minute |

---

## 1. Fixing Error `1545133`: "Allow access to messages" disabled

Even after you approve every permission checkbox during the Meta OAuth login flow, Instagram keeps a separate privacy switch inside the mobile app called **Connected tools**. When that switch is off, Meta still sends comment webhooks to your automation tool, but rejects every outbound DM attempt with `code: 10, error_subcode: 1545133`.

### Step-by-step fix on iPhone and Android
1. Open the **Instagram mobile app** on your phone (do not use instagram.com on a laptop, as the web settings page omits this toggle on many accounts).
2. Tap your profile picture in the bottom-right corner, then tap the **three horizontal lines (☰)** in the top-right corner to open **Settings and activity**.
3. Scroll down to the *How others can interact with you* section and tap **Messages and story replies**.
4. Tap **Message controls**.
5. Scroll to the bottom under **Connected tools** and turn ON **Allow access to messages**.

You do not need to delete or recreate your automations after flipping this switch. Leave a new test comment from a secondary account and the DM will send right away.

---

## 2. Fixing Error Subcode `2534014`: 24-hour messaging window blocks

Meta gives Business and Creator accounts a **24-hour rolling window** to send automated DMs, voice notes, images, and links after a user interacts with your inbox.

Where teams get tripped up is understanding what counts as an inbox interaction versus a post comment:

| User action | Window opened by Meta | What your automation can send |
| --- | --- | --- |
| User comments on your Reel or post | 7-day Private Reply window (single shot) | Exactly 1 Private Reply message referencing comment_id. Cannot send a 2nd message yet. |
| User taps a button or Quick Reply inside your DM | 24-hour standard messaging window | Follow-up links, voice notes, 10-card carousels, and timed reminders within 24 hours. |
| User sends a DM or replies to your Story | 24-hour standard messaging window | Full multi-message sequence, voice notes, and carousels for 24 hours from their last message. |

### How to avoid `2534014` in multi-step campaigns
1. **Never put a raw time delay right after a comment trigger without a button click in between.** If Message #1 goes out via `comment_id` and you schedule Message #2 for 10 minutes later without the user tapping a button, Message #2 will fail with `2534014`.
2. **Keep timed follow-ups under 23 hours.** If a user taps your *"I'm following"* button at 2:00 PM on Tuesday, your 24-hour window closes at 2:00 PM on Wednesday unless they reply again. Schedule your follow-up nudge for 4 to 18 hours after their button tap, not 48 hours later.

---

## 3. Understanding Error Subcode `2534037`: Recipient not eligible

Unlike `1545133` (which breaks your entire account), `2534037` only affects specific individual commenters. Even on a healthy account, you will see `2534037` on roughly 1% to 3% of comments on a viral Reel for three reasons:

1. **Unread Message Request from an earlier post:** If a non-follower commented on one of your Reels last week, received your Private Reply in their *Message Requests* folder, and never tapped "Accept" or clicked the button, Meta will not let your account drop a second cold Message Request into their inbox until they accept the first thread.
2. **Age-gated or regional privacy protections:** Accounts belonging to users under 18 in the EU, UK, and certain US states have stricter rules around automated business-initiated messaging when the user does not follow the business.
3. **Strict personal inbox filters:** The user explicitly turned off incoming message requests from accounts they do not follow.

**How to handle `2534037`:**
Do not retry `2534037` in your queue. Instead, make sure your campaign always posts a **public comment reply** (and mentions following your account in the caption). Once a user follows your account or sends you a direct DM keyword, `2534037` clears for that conversation.

---

## 4. Fixing `OAuthException` Code `190` (Subcodes `460`, `458`, and `490`)

If your automations ran cleanly for months and stopped overnight with `OAuthException` Code `190`, your long-lived Meta access token was invalidated by a security event on your Instagram or Facebook account:

- **Subcode `460`:** You changed your Instagram password (or the password of the Facebook user who connected the account), or reset your two-factor authentication settings.
- **Subcode `458`:** Someone deauthorized the app inside Instagram's *Apps and Websites* settings.
- **Account type switch:** Switching an Instagram account from **Creator** or **Business** back to a **Personal** account immediately revokes all Graph API tokens.

**How to fix it:**
Log into your [RapidDM dashboard](/), open **Connected Accounts**, and click **Reconnect**. Re-authenticating via Instagram OAuth issues a fresh token in 15 seconds while keeping all of your existing post campaigns, keywords, and message templates intact.

## Frequently asked questions

### How do I fix Instagram API Error 1545133 ('Allow Access to Messages')?

Open the Instagram mobile app, go to Settings and activity → Messages and story replies → Message controls → Connected tools, and toggle ON 'Allow access to messages'. Without this switch enabled on mobile, Meta blocks all third-party DM automation tools.

### What is Instagram Error Subcode 2534014?

Error Subcode 2534014 ('Message cannot be sent outside the allowed window') means more than 24 hours have passed since the user last sent a message or tapped a quick-reply button in your DM thread. Meta blocks promotional or follow-up DMs once the 24-hour standard messaging window closes.

### What causes Error Subcode 2534037 on Instagram DMs?

Error Subcode 2534037 occurs when the recipient's Instagram account cannot receive messages from your Business or Creator account—typically because the user is in a region with strict minor-protection messaging rules, has blocked business messages, or has not accepted a pending Message Request.

### Why did my Instagram automation suddenly stop with Code 190 (Subcode 460)?

OAuthException Code 190 with Subcode 460 fires whenever you change your Instagram password, enable two-factor authentication, or switch your account from Creator/Business back to Personal. Reconnecting your account via OAuth refreshes the token immediately.
