Skip to content

Staff only

Gallery desk

This page is not in the public menu. A staff key is required. Facebook photographs enter only through the official Graph API or files you export as administrator.

Facebook API

Token missing

Staff lock

Set GALLERY_STAFF_KEY

Hourly cron

Set GALLERY_CRON_SECRET

Graph API v26.0

Page photo permissions

Official requirement for GET /{page-id}/photos: a Page access token from someone who can Moderate the Page, plus pages_show_list and pages_read_engagement. This website never asks for publish, messaging, or ads scopes.

Grant these

  • pages_show_list
  • pages_read_engagement

pages_show_list lists Pages you manage. pages_read_engagement reads posts, albums, and photographs the Page uploaded. Page task required: Moderate.

Do not grant

  • pages_manage_posts
  • pages_manage_engagement
  • pages_messaging
  • ads_management

Optional only: pages_read_user_content (visitor tags). Not required for Page-uploaded gallery files.

  1. Open Meta for Developers → My Apps → Create App (type Other / Business). You must be an admin of facebook.com/globalresearchcenter.
  2. Keep the app in Development mode. App Review is not needed if only Page admins generate the token.
  3. Tools → Graph API Explorer. Select your app. In the permission list tick only pages_show_list and pages_read_engagement. Generate Access Token. When asked, choose the Global Research Centre Page — not your personal profile.
  4. Confirm with GET /me — the id must be 832272646627027 (the Page), not your user id. Then GET /832272646627027/photos?type=uploaded. Paste the Page token below after you open the desk.

How automation runs on Hostinger

  1. In Graph API Explorer, generate a Page token with only pages_show_list and pages_read_engagement. Confirm GET /me returns Page id 832272646627027.
  2. On the host, set FACEBOOK_PAGE_ACCESS_TOKEN, FACEBOOK_PAGE_ID=832272646627027, GALLERY_STAFF_KEY, and GALLERY_CRON_SECRET. Never put them in the browser bundle.
  3. Add a Hostinger cron every six hours: curl with header x-gallery-cron pointing at /api/gallery-cron. That pulls new Page photographs without anyone logging in.
  4. If Meta will not issue a token, export albums as the Page admin and upload them here, or drop JPEG files into public/media/inbox and press Sync now.