Glossary

Why Your Social Media Scheduler Keeps Disconnecting Accounts

Taras Shynkarenko
Taras Shynkarenko
•Updated: •7 min read
Why your social media scheduler keeps disconnecting accountsWhy your social media scheduler keeps disconnecting accounts

TL;DR, Quick Answer

7 min read

Schedulers post with OAuth tokens, and every network sets its own clock. Meta's long-lived user token lasts about 60 days, LinkedIn's lasts 60 days with a 365-day refresh token for approved partners only, X's lasts two hours without offline.access, and TikTok's lasts 24 hours with a 365-day refresh token that can rotate. X publishes no refresh token lifetime. A password change, a removed permission or a lost Page role ends a token early, and Meta returns a distinct error subcode for each.

Why does my social media scheduler keep disconnecting?

Your social media scheduler keeps disconnecting because it posts with OAuth tokens that each network expires on its own schedule, and several everyday account actions kill those tokens before the clock runs out. A scheduler never holds your password. It holds a token the network issued when you clicked Allow. When that token stops working, the scheduler has nothing else to post with, and you get a reconnect prompt.

The disconnects come from two sources. Some are the calendar: a token reached the end of its documented life. Others are events: you changed a password, removed a permission, or lost your role on a Page. The second group is harder to spot because it can happen on day two.

Two ways a token dies
The calendar
  • The token reached the end of its documented life
  • Meta's long-lived user token: about 60 days
  • X without offline.access: two hours
  • TikTok access token: 24 hours
An event
  • A password was changed
  • A permission was removed
  • A role on a Page was lost
  • Any of these can happen on day two
Events are harder to spot than the calendar because they can hit on day two.

How long does each network's token last?

Every network publishes a different number, and one does not publish a refresh lifetime at all.

NetworkAccess tokenRefreshSource
FacebookLong-lived user token "about 60 days", expires_in 5183944Exchange a valid token with fb_exchange_tokendevelopers.facebook.com, Long-lived access tokens
Facebook Page"do not have an expiration date"Not neededSame page
InstagramRefreshed tokens "valid for 60 days"ig_refresh_token, token must be at least 24 hours olddevelopers.facebook.com, Refresh Access Token
LinkedIn"all access tokens are issued with a 60-day lifespan"365 days, approved MDP partners onlylearn.microsoft.com, Authorization Code Flow and Refresh Tokens
X"two hours unless you've used the offline.access scope"Issued with offline.access, lifetime not publisheddocs.x.com, OAuth 2.0 Authorization Code Flow with PKCE
TikTok"valid for 24 hours after initial issuance", expires_in 86400"valid for 365 days after the initial issuance"developers.tiktok.com, User Access Token Management

Meta

Meta hedges its own number. The access token overview says "long-lived tokens last about 60 days," then tells you "Do not depend on these lifetimes remaining the same" because "they may change without warning or expire early." Meta's SDKs refresh long-lived tokens "once per day, when the person using your app makes a request to Facebook's servers," and without requests "the token will expire after about 60 days." A server-side scheduler does not get that daily refresh for free. The exchange call, the 56 seconds Meta's sample shaves off 60 days, and the non-expiring Page token are covered in the note on the Facebook long lived access token.

LinkedIn

LinkedIn is the cleanest number and the strictest gate. Access tokens last 60 days, and refresh tokens last 365 days, but LinkedIn writes that it "supports programmatic refresh tokens for all approved Marketing Developer Platform (MDP) partners." Refreshing does not extend the year either. The refresh token's life "remains the same as specified in the initial OAuth flow (365 days)." Once a year the member has to click Allow again no matter what. The day-by-day arithmetic, and a units mismatch in LinkedIn's own sample response, are in the note on why a LinkedIn access token expires after 60 days.

X

X gives the shortest access token of the four and the least information about renewal. Its OAuth 2.0 page says "the access token you create through the Authorization Code Flow with PKCE will only stay valid for two hours unless you've used the offline.access scope." With that scope, X issues a refresh token. Without it, "we will not generate a refresh token," and a scheduler would lose access two hours after you connect.

X does not publish how long the refresh token itself lasts. The scope list describes offline.access as "Stay connected to your account until you revoke access," which is a promise about revocation, not a number. If a tool tells you X tokens last a specific number of days, that figure did not come from this page.

TikTok

TikTok pairs a day-long access token with a year-long refresh token. The access token is "valid for 24 hours after initial issuance," and TikTok says it "can be refreshed without user consent," so a scheduler runs a background job to renew it every day. The refresh token lasts "365 days after the initial issuance," and the App Review FAQ repeats the ceiling: "User Access Tokens can be extended to a maximum of one year."

TikTok adds a rule that breaks careless integrations. On refresh, "The returned refresh_token may be different than the one passed in the payload. You must use the newly-returned token if the value is different than the previous one." TikTok does not say what happens to the old value afterwards, so a scheduler that ignores the new one is relying on behaviour TikTok never documented.

Why did my account disconnect after I changed my password?

Because Meta kills the session. Meta's Graph API error table has a dedicated subcode, 460 "Password Changed," and the fix it lists is that the person "must log in to the app again." Meta's session documentation names the same trigger when it describes a person who "reports their account as hacked, or changes their password as a precaution."

The other three networks do not mention password changes on the OAuth pages quoted here. LinkedIn, X and TikTok document expiry and revocation, but none of those pages says what a password change does to an existing token.

Person typing on a laptop at a desk, illustrating an account password change that ends a scheduler's connection.

Why did it disconnect after I changed app permissions?

Removing a permission ends the access that permission granted, and on LinkedIn, adding one can end everything.

  • Meta returns code 10 or 200-299 with the note "Permission is either not granted or has been removed."
  • LinkedIn writes: "If you request a different scope than the previously granted scope, all the previous access tokens are invalidated." A scheduler that adds a new LinkedIn permission in an update disconnects every LinkedIn account it holds.
  • TikTok lets people approve part of a request: "Users have the rights to only agree to a subset of scopes you requested from them." A token without video.publish fails with 401 scope_not_authorized.
  • Disconnecting the app yourself ends the grant on all four. Meta says people "can also choose to disconnect your app from their Facebook account." LinkedIn describes a permission "manually revoked by the member." X's offline.access lasts "until you revoke access." TikTok's revoke endpoint, POST https://open.tiktokapis.com/v2/oauth/revoke/, removes the app from the user's "Manage app permissions" page.

Why did my Facebook Page disconnect when someone else still has access?

Because Page tokens belong to one person, not to the Page. Meta says "Page access tokens are unique to each Page, admin, and app combination," and generating one requires that "The person requesting the token must have a role on the Page." If the person who connected the Page loses that role, the token dies with it. Meta's error for this is subcode 492 "Invalid Session": "User associated with the Page access token does not have an appropriate role on the Page."

LinkedIn works the same way for company pages. The w_organization_social permission is "Restricted to organizations where the authenticated member has one of the following company page roles: ADMINISTRATOR, DIRECT_SPONSORED_CONTENT_POSTER, CONTENT_ADMIN." Remove the member from those roles and posts to the page stop, even though the member's own token is still valid.

AdaptlyPost
AdaptlyPost

Start Your 7-Day Free Trial

All-platform analytics

Social Inbox

AI-powered assistant

The fix in both cases is to reconnect from an account that currently holds the role, not to reconnect the same person again.

Coworkers gathered around an office table, illustrating a team change that removes someone's role on a Page.

How do I tell which cause disconnected an account?

Read the error, not the symptom. Meta's subcodes separate most of the causes, though 463 and 467 overlap:

Meta subcodeNameCause
458App Not InstalledThe user has not logged into the app
460Password ChangedPassword reset
463ExpiredLogin status or token expired, revoked or otherwise invalid
467Invalid Access TokenExpired, revoked or otherwise invalid
492Invalid SessionPage role lost

TikTok returns 401 access_token_invalid for "invalid or has expired" and 401 scope_not_authorized for a missing scope. LinkedIn's refresh endpoint returns 400 invalid_request with "The provided authorization grant or refresh token is invalid, expired or revoked." If your scheduler shows you the raw error, match it against these lists before reconnecting. A Page-role error fixed by reconnecting the wrong person will come straight back.

Posts that fail for reasons other than tokens are covered in the notes on Facebook scheduled posts not working and LinkedIn scheduled posts not working.

Frequently asked questions

Why does my scheduler ask me to reconnect Facebook about every two months?

Meta's long-lived user token lasts "about 60 days," and Meta says an expired token cannot be exchanged for a new one. The person has to log in again.

Why does LinkedIn disconnect even when the scheduler refreshes tokens?

LinkedIn's refresh token lasts 365 days from the first authorization and does not reset when used. Refresh tokens are also limited to approved Marketing Developer Platform partners.

How long does an X refresh token last?

X does not publish a lifetime for it. Its OAuth 2.0 page documents only the two-hour access token and says a refresh token is issued when you request offline.access.

Why did TikTok disconnect a day after connecting?

The TikTok access token lasts 24 hours, so the scheduler has to renew it with the refresh token every day. If that refresh job did not run, the scheduler has no working access token once the 24 hours pass. TikTok also says to use the new refresh_token whenever the refresh call returns a different one, but it does not document what happens to the old value.

Does changing my Facebook password disconnect my scheduler?

Yes. Meta's error table lists subcode 460 "Password Changed," and the person must log in to the app again.

Why did a Facebook Page disconnect after a team change?

The Page token was tied to a person who no longer has a role on the Page. Meta returns subcode 492, and someone with a current Page role has to reconnect it.

Do Facebook Page tokens expire?

Meta says Page tokens "do not have an expiration date," so a Page connection is not on the 60-day clock. It can still die early. Page access tokens are "unique to each Page, admin, and app combination," so losing the person's role on the Page ends the token with subcode 492.

Why did every LinkedIn account disconnect after a scheduler update?

LinkedIn writes: "If you request a different scope than the previously granted scope, all the previous access tokens are invalidated." A scheduler that adds a new LinkedIn permission in an update disconnects every LinkedIn account it holds. Each account then has to be reconnected.

What does the TikTok error scope_not_authorized mean?

The token lacks a permission the call needs. TikTok writes that "Users have the rights to only agree to a subset of scopes you requested from them," so a person can approve less than the scheduler asked for. A token without video.publish fails with 401 scope_not_authorized.

What is the difference between Meta subcodes 463 and 467?

Very little, going by Meta's own table. Subcode 463 "Expired" covers a login status or access token that "has expired, been revoked, or is otherwise invalid." Subcode 467 "Invalid Access Token" uses the same words for the access token alone. Neither code tells you whether the calendar or an event ended the token, so check for a recent password, permission or role change before assuming the token ran out.

AdaptlyPost
AdaptlyPost

Start Your 7-Day Free Trial

All-platform analytics

Social Inbox

AI-powered assistant

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks AdaptlyPost as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

AdaptlyPost

AdaptlyPost

Schedule your content across all platforms

Manage all your social media accounts in one place with AdaptlyPost.

All-platform analytics

Social Inbox

AI-powered assistant

Related Glossary Terms

Related Articles