Osintgram 2.0: a local web interface for Instagram OSINT
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
At a glance
- What is it?
- Osintgram 2.0 replaces the old interactive shell with a FastAPI app served on 127.0.0.1, 28 lookups, and an optional local Ollama model that picks commands for you. It is for analysts who accept that a paid data backend, not the tool, decides what they can see.
- Who is it for?
- Adopt Osintgram if you already pay for HikerAPI or keep a throwaway Instagram account for instagrapi logins, and you want the profile, network and posting-time analysis in one local page with the raw JSON still reachable. Do not adopt it if you need private-account access, multi-user hosting, or a tool that runs without a third-party data source.
- Can I use it commercially?
- Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
- Is it still maintained?
- Yes. The repository last received commits 15 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 21, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Osintgram 2.0 actually collects from a public Instagram profile
The tool takes an Instagram nickname and produces a dossier from what a public profile exposes: bio and every link in it, follower and following counts, category, public email, phone and business address down to coordinates, and the linked Facebook id. Instagram's own About this account data is included too, meaning country of registration, creation date, and how many times the username changed. Network analysis covers followers, followings, suggested related accounts, who tagged the target, who the target tagged, and who comments most, plus mutual connections between two accounts. Content analysis ranks hashtags by use, pulls captions and comments, breaks posts down by photo, video and carousel with views and paid partnerships, and builds a weekday by hour posting heatmap and a map of geotagged locations. A separate mode needs no target at all: it searches posts published with a hashtag, top or recent, or from a place, and returns who published them. The audience is an investigator, journalist or security analyst working on one account at a time on their own machine. The README is explicit that it is for educational purposes and that contributors assume no responsibility for use.
How the local web app, the data backend and Ollama fit together
Version 2.0 rebuilds the project around a web interface and a reusable service layer. The app is FastAPI served by uvicorn from src.web.app:app, and the README states the interface is served from 127.0.0.1. Data does not come from the app itself: you supply a HikerAPI key, pasted into a panel on first load and verified before it is accepted, or you log in with instagrapi using an Instagram account of your own. The README describes a trade-off between the two but points to the guide rather than resolving it here. Every request is cached, so a repeated lookup is not paid for twice, and the app prices a selection before it runs and shows remaining credit. AI mode is a local Ollama model with tool calling, default llama3.1:8b, that can only choose from the same 28 commands as base mode, so it cannot invent a lookup. Base mode skips Ollama entirely. Docker is the third path: docker-compose.yml mounts config, cache and dossier from the host and publishes the port on 127.0.0.1 only, with a comment warning that changing the mapping to 8000:8000 exposes the app to the whole network. That warning matters because the README states the app has no authentication.
Installing Osintgram and running a first search
The README gives a two-line quick start for a local install. Run it from the repository root after cloning; the first line resolves the web app, both Instagram data backends and the Ollama client, and the second starts the server with auto-reload.
pip install -r requirements.txt
uvicorn src.web.app:app --host 127.0.0.1 --port 8000 --reload # or: make runOpen http://127.0.0.1:8000. The page opens on a panel asking for a data backend, so paste a HikerAPI key there. The README says the key is verified before it is accepted and can be saved for next time. Without a key or an instagrapi login, no lookup can run.
AI mode needs Ollama installed and a tool-calling capable model pulled. The README names llama3.1:8b as the default and gives its size, about 4.7 GB. Base mode works without this step.
ollama pull llama3.1:8b # ~4.7 GB, the defaultIf you prefer containers, the compose file builds the image and starts the same app on the same address. The README notes the key, cache and saved searches stay on the host in config/, cache/ and dossier/ rather than inside the image, and that AI mode reaches an Ollama running on your host.
docker compose up --build # or: make dockerFor a first real use, pick base mode rather than AI mode. Tick a small set of commands, set the nickname parameter, and run them in order. The point of starting here is that you see the per-command price before committing credit, instead of discovering the cost after a model has chosen ten lookups for you.
The cost model and the private-profile ceiling
Two limits define what Osintgram can do. The first is money. Instagram data is not free, and the README frames the cost controls as the answer: price up front, remaining credit on screen, caching of every request, and a cap or stop enforced server-side rather than only in the browser. That last detail is the one worth noticing, because a browser-side stop would not protect a run once the requests were already in flight. The second limit is access. The README states plainly that you cannot see private profiles and that nothing can, calling tools which claim otherwise scams. So for a locked account the tool returns what any logged-out visitor sees, and no amount of command selection changes that. There is a third constraint that is easy to miss: the interface has no authentication and is meant for your own machine. The Docker comments repeat the warning twice, once on the port mapping and once on the EXPOSE line. Running it on a shared host or a public IP without an authenticated reverse proxy in front is a configuration the project itself tells you not to use. A final operational point from the README: do not use your own or primary Instagram account with the tool, and never commit config/credentials.ini, which holds API keys and Instagram credentials.
Osintgram versus the original CLI and versus Maltego
The most direct alternative is Osintgram 1.x itself. Releases 1.2 and 1.3 shipped in 2021, and the 2.0 release on 2026-09-14 is the first since then. The changelog entry in the README says 2.0 rebuilds the project around a web interface and a reusable service layer and adds AI mode, the cost controls and the newer analyses. Anyone holding a 1.x workflow is comparing an interactive shell against a browser UI with caching and priced selections; the underlying lookups overlap, the operational model does not. A different kind of alternative is a general-purpose OSINT platform such as Maltego. Maltego is built around entities and transforms and connects many data sources into one graph, which suits mapping relationships across domains, organisations and infrastructure. Osintgram is single-source by design: it reads Instagram, and its analyses are shaped around one account, its followers and its posts. If your question is who is behind an Instagram handle and when they post, the narrower tool is the better fit. If your question spans a domain, an email address and a company registration, Osintgram has nothing to contribute and you would be paying for Instagram lookups you do not need.
Licence, maintenance and what a 2.0 upgrade costs
Osintgram is GPL-3.0. For anyone running it locally for analysis, that changes nothing day to day. For anyone embedding it in a product, the copyleft terms of GPL-3.0 apply to distributed derivative work, and the practical question is whether your distribution triggers them. That is a question for your own counsel, not for this article. On maintenance, the last push to master was on 2026-09-14, the same day the 2.0 release was tagged, so the repository shows recent activity rather than a dormant one. The gap before that is the real story: 1.3 landed on 2021-05-17, so a 1.x user upgrading is jumping roughly five years of accumulated change in one step, including a new entry point, a new configuration layout under config/, and a new dependency set in requirements.txt. The upgrade cost is mostly environmental. Python 3.10 or later is required per the README badge, and the Dockerfile builds on python:3.12-slim, installing build-essential in a wheel stage because instagrapi pulls in Pillow and curl_cffi. If you were running a 1.x checkout on an older interpreter, the container path is the cheaper migration. The test suite, run with python -m pytest after pip install -r requirements-dev.txt, uses synthetic fixtures with no API key, quota or network, and the README says it also checks that the documentation has not drifted from the code.
Editorial conclusion
Adopt Osintgram if you already pay for HikerAPI or keep a throwaway Instagram account for instagrapi logins, and you want the profile, network and posting-time analysis in one local page with the raw JSON still reachable. Do not adopt it if you need private-account access, multi-user hosting, or a tool that runs without a third-party data source. Before installing, open doc/web-ui.md and read the per-command cost table; that table, not the command count, is what decides whether a run fits your budget.
Frequently asked questions
What is Osintgram?
Osintgram is an OSINT tool for Instagram, written in Python and licensed GPL-3.0. Version 2.0 serves a web interface on 127.0.0.1 that collects and lays out what a public Instagram profile gives away, such as followers, hashtags, geotagged locations and posting habits.
Does Osintgram work for private accounts?
No. The README states that you cannot see private profiles and that nothing can, and it calls tools claiming otherwise scams.
Is there a free OSINT tool?
Osintgram itself is free and GPL-3.0, and its test suite runs without an API key, quota or network. Running real lookups is not free: it needs a HikerAPI key or an instagrapi login, and the README notes that Instagram data is not free and that the app prices each selection before you run it.
What are some alternatives to Osintgram?
The repository does not list alternatives. The closest comparison inside the project is its own earlier line: releases 1.2 and 1.3 from 2021 used an interactive shell, while 2.0 rebuilds it around a web interface and a reusable service layer.
How do I use Osintgram?
Start the server, open http://127.0.0.1:8000, and give it a data backend, either a HikerAPI key pasted into the first panel or an instagrapi login. Then either tick commands in base mode or describe what you want in AI mode, which needs Ollama with a tool-calling model.
How do I install Osintgram?
Install the requirements with pip install -r requirements.txt, then start the server with uvicorn src.web.app:app --host 127.0.0.1 --port 8000 --reload, or run make run. A container path is also documented through docker compose up --build.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/datalux-osintgram)