Node.js基于Cookie的Instagram接口问题:关注请求失败,取关正常
Hey there, let's figure out why your unfollow request works fine (200 OK) but the follow one keeps returning a 302 redirect. Here are the most likely causes and fixes:
1. Missing critical request headers or parameters
Instagram's follow endpoint often requires more validation than unfollow. The biggest culprit is usually missing the CSRF token in your request headers, or not setting other required headers that Instagram checks for authenticity.
Fix steps:
- Grab the
csrftokenvalue from your browser's cookies (you can find this in DevTools > Application > Cookies). - Add these mandatory headers to your follow request:
X-CSRFToken: The csrftoken value you just grabbedX-Instagram-AJAX: Set to1X-Requested-With: Set toXMLHttpRequestReferer: Should be the target user's profile URL (e.g.,https://www.instagram.com/their_username/)User-Agent: Match your browser's user agent string to avoid being flagged as a bot
Here's an updated code example that includes these:
// Helper to get csrftoken from cookies function getCookie(name) { const value = `; ${document.cookie}`; const parts = value.split(`; ${name}=`); if (parts.length === 2) return parts.pop().split(';').shift(); } const csrfToken = getCookie('csrftoken'); const followUrl = 'https://www.instagram.com/web/friendships/19237590/follow/'; fetch(followUrl, { method: 'POST', headers: { 'X-CSRFToken': csrfToken, 'X-Instagram-AJAX': '1', 'X-Requested-With': 'XMLHttpRequest', 'Referer': 'https://www.instagram.com/[target_username]/', // Replace with actual username 'User-Agent': navigator.userAgent, 'Content-Type': 'application/x-www-form-urlencoded' }, credentials: 'include' // Ensures cookies are sent with the request }) .then(response => { if (response.redirected) { console.log("Redirected! Your session might be invalid or you need to pass additional validation."); } return response.text(); }) .then(data => console.log("Response:", data)) .catch(err => console.error("Error:", err));
2. Invalid or expired session cookies
A 302 redirect often means Instagram is sending you to a login page because your session isn't valid. Even if unfollow works, follow might enforce stricter session checks.
Fix steps:
- Verify that your
sessionidcookie is still active (check in DevTools > Application > Cookies; if it's expired, log back into Instagram to refresh it). - Make sure your cookies include other required values like
ds_user_idandig_did, which Instagram uses to track authenticated sessions.
3. Anti-bot restrictions triggered
Instagram's anti-bot systems might flag your follow request if it's too frequent, or if your request doesn't match normal user behavior.
Fix steps:
- Add delays between requests to mimic human behavior.
- Avoid running the script repeatedly in a short time frame—this can lead to temporary restrictions.
- Ensure your request's
User-Agentmatches a real browser (not a generic or bot-like string).
4. Check for required request body parameters
While unfollow might work with an empty body, follow sometimes expects a small form payload (like d=1). You can check this by using your browser's DevTools:
- Go to the target user's profile
- Open DevTools > Network tab
- Click the "Follow" button and inspect the POST request to
/web/friendships/[user_id]/follow/ - Copy any form data from the "Payload" tab and include it in your request
内容的提问来源于stack exchange,提问作者CarlosIsLazy

