Local web app
Served on the user's own machine. The changelog says the interactive shell is no longer the documented way to use it.
Osintgram is an open-source Instagram OSINT tool that collects and cross-references public data from an Instagram profile: bio and contact details, followers and followings, captions, hashtags, geotagged posts and posting times. Version 2.0 turned it into a local web app. This review covers what it does, how it gets its data, and the platform-terms and legal risks that come with it.
Osintgram is a free GPL-3.0 Instagram OSINT tool, now a local web app with 28 lookups and an optional local AI mode. It needs a data backend: a paid HikerAPI key or a login to an Instagram account of your own. It suits researchers who understand the risks; Instagram's terms bar automated collection without permission, and login use can get accounts flagged.
Osintgram pulls public data about an Instagram account and its network, then organizes it into profiles, lists, maps and heatmaps. It cannot see private profiles.
According to the repository, Osintgram collects public information from an Instagram profile and groups it in four areas: profile details (bio, links, counts, public email, phone and business address, and "About this account" data such as country of registration and username changes), network (followers, followings, related and tagged accounts, mutual connections), content (hashtags, captions, comments, likes, posting-time heatmap, geotagged locations, photo alt text) and contacts (public emails and phone numbers among a target's followers or followings). Hashtag and place searches need no target account.
The README states: "You cannot see private profiles. Nothing can. Tools claiming otherwise are scams." Osintgram is written by Giuseppe Criscione (Datalux), released under GPL-3.0, requires Python 3.10 or newer, and states it is not affiliated with or endorsed by Meta. It is one of the social media entries in our OSINT tools catalog.
Version 2.0 replaced the old interactive shell with a local web interface, added an optional AI mode that runs on your machine, and added cost controls and exports.
Served on the user's own machine. The changelog says the interactive shell is no longer the documented way to use it.
AI mode lets a local model chosen through Ollama pick lookups from a plain-language request. Base mode lists all 28 commands with no model needed.
Requests are cached, priced before a run and capped, because the paid backend charges per request.
Per-card JSON or CSV, a media zip, a standalone HTML report, and saved searches that can be compared with a later run.
Osintgram gets its data either from HikerAPI, a paid third-party service, or from instagrapi, which logs in to Instagram with a real username and password.
The user guide describes two interchangeable backends:
| Backend | Cost | Instagram account needed | Main risk |
|---|---|---|---|
| HikerAPI (recommended by the project) | Paid, per request; price set by HikerAPI | No | You are buying Instagram data from a third party; see the terms section below |
| instagrapi | Free | Yes, a real username and password | The guide warns that "Instagram can flag or challenge the account you use" |
The guide's advice for the login backend is to use a secondary account, "never your main one", and the README repeats: "Don't use your own or primary Instagram account." It also warns that the local interface has no authentication. We give no setup steps here.
Instagram's Terms of Use prohibit collecting information in an automated way without express permission, whether or not you are logged in, and allow Instagram to disable accounts that breach them.
Under "How You Can't Use Instagram", the Instagram Terms of Use say you can't "access or collect information in unauthorized ways", which "includes creating accounts or accessing or collecting information in an automated way without our express permission, regardless of whether such automated access or collection is undertaken while logged-in to an Instagram account." The same section says you can't "sell, license, or purchase any account or data obtained from us or our Service." The terms also allow Instagram to stop providing the service, including disabling access, when a user violates them (text verified via Open Terms Archive).
What that means in practice:
A terms breach can weaken evidence and expose an organization to claims. Take legal advice first.
The software is free under GPL-3.0 and the repository is active, not archived; real costs come from the data backend.
| Item | Status (checked 10 October 2026) |
|---|---|
| Software price | Free |
| License | GPL-3.0 |
| Current version | 2.0 (web interface, AI mode, cost controls); no release date published on the repository page |
| Repository status | Public and not archived; about 14,500 stars |
| Data costs | HikerAPI is paid per request; the instagrapi backend is free but risks the account used |
| AI mode | Optional; runs a local model through Ollama, with no external AI subscription |
Older articles describing a terminal shell that logs in with Instagram credentials are out of date. The README still states: "FOR EDUCATIONAL PURPOSE ONLY."
It suits researchers and security teams who can justify the purpose and accept the terms risk. It does not suit evidence work that must survive challenge, or any personal tracking.
Possible fit: security researchers studying what public business accounts expose, with legal sign-off.
Poor fit: litigation and HR cases, where collection method matters as much as content; anyone without a written lawful purpose; and anyone trying to monitor a partner, an ex or a private individual. The README itself reminds users that results contain other people's personal data that must be handled in line with data protection law.
Public Instagram data is still personal data, follower-network analysis reaches people who are not the subject, and platform changes can break collection at any time.
Username tools find where a handle is used, capture tools record what you view manually, and commercial platforms offer supported social media coverage.
Check whether an Instagram handle also exists on other sites, without collecting profile content.
WhatsMyName review →Browser extension that records pages an investigator views manually, keeping a dated trail of public posts.
Hunchly review →Commercial OSINT platform covering social media sources, sold to investigators and enterprises.
Social Links review →Checks whether an email address is registered on Instagram and 120+ other sites.
Holehe review →When an Instagram account matters to a legal, HR or fraud decision, an investigation reviews public content manually and captures it as evidence, without automated scraping or fake accounts.
Our Instagram investigations review public profiles, posts and connections by hand, capture them with dates and URLs, and grade each link to a real person by confidence. We do not use fake profiles, follow requests or tools that claim access to private accounts. Impersonation of your brand or executives on Instagram is handled through fake social media account investigations, and multi-platform cases through social media investigations. Focused cases start from 10 business days with a fixed quote after scoping. Browse the full range of OSINT services for legal and brand teams.
Send the handle and tell us what decision depends on it. We confirm a lawful purpose and reply with a fixed quote and a delivery date.
The Osintgram Instagram OSINT tool is not archived; the repository was public and active when checked on 10 October 2026. It no longer works the way old tutorials describe. Version 2.0 is a local web app with 28 lookups, an optional local AI mode and two data backends: a paid HikerAPI key or a login to an Instagram account of your own.
Do not pay. Osintgram is a GitHub project you run on your own machine, and its README mentions no Telegram bot. It also states that private profiles cannot be seen and that tools claiming otherwise are scams. Such bots often take payment and deliver nothing, or ask for your Instagram login.
Yes, the spare account can still be challenged, restricted or disabled. Instagram's terms bar collecting information in an automated way without express permission, whether or not you are logged in, and allow it to disable accounts that breach the terms. A secondary account protects your main one; it does not make the collection permitted.
It is usually not the best route. For a police report you need dated manual captures of the posts and messages with URLs, plus a log of who captured them. Automated collection that breaches platform terms can invite challenges. Report the account to Instagram, preserve evidence and contact the police; investigators can help organize the material.
It depends on necessity and proportionality. Brand protection can be a legitimate interest, but bulk follower collection captures data on many people unrelated to the impersonation. Document a balancing test, limit collection to what proves the impersonation, and remember that the platform's terms are a separate issue from GDPR.
Hire a provider when the result will support a legal step. A provider reviews the account manually, connects it to other platforms and identifiers, grades confidence and captures evidence without breaching Instagram's terms or using fake profiles. Where only Meta holds the identity, your lawyers can seek it through legal process, supported by the report.
Sources checked 10 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.