Instagram ?__a=1接口无法通过cURL请求,是否需特定参数?
Fixing Instagram
?__a=1 Endpoint Access via cURL Hey there,
Instagram has absolutely locked down unauthenticated access to endpoints like ?__a=1 in recent years—that blank "Login • Instagram" HTML response is their way of blocking requests that don't look like they're coming from a legitimate browser session. Your current cURL setup has a couple of key issues that are triggering this block:
Key Problems in Your Original Code
- Invalid User-Agent: You set
CURLOPT_USERAGENTtotrue, which isn't a valid browser user-agent string. Instagram checks this heavily to block bots. - No Session/Cookie Handling: Instagram requires session cookies to even serve public content now; without them, you'll get redirected to the login page.
- Missing Request Headers: Browsers send additional headers that signal legitimacy—your request is missing these, so Instagram flags it as suspicious.
Updated cURL Configuration
Here's a revised version of your code that addresses these issues and should get you the JSON data you need:
<?php $url = "https://www.instagram.com/ferrari/?__a=1"; $ch = curl_init(); // Use a real browser User-Agent (update this to match a current browser if needed) $userAgent = 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36'; curl_setopt($ch, CURLOPT_USERAGENT, $userAgent); // Enable cookie storage to maintain a session curl_setopt($ch, CURLOPT_COOKIEJAR, 'instagram_cookies.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE, 'instagram_cookies.txt'); // Add headers that mimic a real browser request curl_setopt($ch, CURLOPT_HTTPHEADER, [ 'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8', 'Accept-Language: en-US,en;q=0.5', 'Upgrade-Insecure-Requests: 1', 'Sec-Fetch-Dest: document', 'Sec-Fetch-Mode: navigate', 'Sec-Fetch-Site: none', 'Sec-Fetch-User: ?1' ]); // Keep your existing valid settings curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); // Note: For production, set to true and use a CA cert curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($ch, CURLOPT_MAXREDIRS, 3); curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); $data = curl_exec($ch); // Handle the response if ($data) { $jsonData = json_decode($data, true); if ($jsonData) { // Extract the high-res profile picture URL $profilePic = $jsonData['graphql']['user']['profile_pic_url_hd']; echo "High-Res Profile Picture: " . $profilePic; } else { // If you still get HTML, try first visiting the user's main page to establish a session echo "Received HTML instead of JSON. Try first requesting https://www.instagram.com/ferrari/ to build a valid session cookie."; } } else { echo "cURL Error: " . curl_error($ch); } curl_close($ch); ?>
Additional Notes
- Session First, API Second: If you still get the login page, try making a request to the user's regular profile page (without
?__a=1) first to let Instagram set necessary cookies, then re-run the?__a=1request. - Endpoint Stability: The
?__a=1endpoint isn't officially supported by Instagram and can change at any time. A more reliable alternative is to scrape the user's profile HTML, find the script tag containingwindow._sharedData, parse its content as JSON, and extract the profile picture from there. - Rate Limiting: Even with valid requests, Instagram will block you if you make too many too quickly—add delays between requests if you're scraping multiple profiles.
内容的提问来源于stack exchange,提问作者a-coder
相关产品推荐
相关产品推荐

