INSTARA
← All articles

Instagram account delivery formats: login:pass, cookies, IAM, 2FA

You paid for an account, opened the delivery, and saw a string of twenty fields separated by colons. Where is the login, where is the password, what is that long key at the end, and where do you paste it? For an operator running traffic or farming, the delivery format matters more than the price: wrong format and the account you paid for simply won't load into your antidetect. Let's break down what each format actually contains and when to pick which.

What the account string is made of

A classic delivery is a single line with fields split by colons. Sellers state the field order in the product description, and you must never guess it: the same data in a different order breaks auto-import. The base set looks like this:

  • login — the username or the bound email;
  • pass — the current account password;
  • email and email_pass — the recovery mailbox and its access (not always included);
  • 2FA-secret — the base key that generates one-time codes;
  • cookies — a browser session as JSON or a string;
  • user_agent and device_id — the fingerprint of the device the account lived on.

The fuller the string, the more stable the login. A minimal login:pass is cheaper but forces you to pass verifications by hand.

Login:pass — the base format

The simplest option: login and password, sometimes with an email. It fits manual work where you log in yourself via the mobile app or a browser and are ready to clear a checkpoint by SMS or mail. The upside is the lowest price and universality. The downside: logging in from a new IP almost always triggers a confirmation, and without mailbox access you hit a wall. Take login:pass when you have your own proxies matching the account geo and you're not firing hundreds of logins in a row.

Cookies — login without a password

Cookies are a saved session. Import them into an antidetect (Dolphin, AdsPower, Vision) and you land inside without typing a login, as if continuing an old session. This sharply lowers checkpoint risk because the platform sees a familiar session. Note: cookies don't live forever, and if the session expires you need the password or 2FA to reauthorize. That's why a proper delivery is always "cookies + login:pass + secret" in case the cookies drop.

Which format for which software

ToolBest format
Dolphin{anty}, AdsPowercookies (JSON) + user_agent
Mobile farms, GoLoginlogin:pass:email + 2FA-secret
Manual phone loginlogin:pass + email
Auto-import, scriptsfull string with every field

IAM — Instagram App Manifest

IAM (also called the "mobile format" or import string) is a data dump emulating a login through the official app: device_id, phone_id, uuid and session tokens. This format is prized by those working through mobile emulators and API wrappers: the account signs in as "the same device", meaning fewer antifraud triggers. If you work with accounts for antidetect, IAM gives the most native fingerprint.

2FA-secret — a key, not a code

In the delivery you get not the six-digit code itself but the secret, a base32-style string. From it your app or antidetect generates one-time OTP codes endlessly. This is more reliable than SMS: the code doesn't depend on someone else's phone. Accounts with 2FA enabled are collected in the Instagram with 2FA category. How exactly to turn the secret into a code is a separate topic, but remember: you must not lose the secret, no one reissues it.

Mini-FAQ

Can I log in with cookies only, no password?

Yes, while the session is alive. As soon as Instagram asks for reauthorization you'll need the password and 2FA-secret. So keep the full string.

Why won't the account log in if the login and password are correct?

Usually it's geo: logging in from an IP far from the account's history triggers a checkpoint. Use a proxy from the account's country and import cookies if you have them.

What if the format doesn't match my software?

Most fields convert: a login into any antidetect can be assembled from login:pass:secret. If unsure, message support before buying.

Bottom line

The delivery format isn't a footnote in the description but the compatibility of an account with your working stack. Manual work needs only login:pass; scale calls for the full string with cookies and 2FA-secret. At Instara delivery is automatic 24/7, payment by USDT (TRC-20) or SBP, and invalids are replaced no questions asked. Unsure which format fits your antidetect? Ask support @instaraallert_bot before paying and you'll get exactly the fields your software needs.

Need accounts?
Delivery from stock right away or in 2–5 minutes, 24/7
Go to catalog →