Skip to content
Cerebr-IA

MARKETIA integration

MARKETIA and TikTok

Each business connects its own TikTok accounts and ad accounts through TikTok's official login, and manages them in MARKETIA alongside its other channels.

What MARKETIA does

  • Shows the connected account's profile (display name, avatar, bio, verified status) and its counters: followers, following, likes and number of videos.
  • Lists the account's videos with their metrics so the business can see what content works.
  • Publishes and schedules videos and photos to the connected account from MARKETIA's calendar, following TikTok's Content Posting API guidelines: creator info is queried before every post, the user picks the privacy level (there is no default), turns comments, Duet and Stitch on or off as the account allows, discloses commercial content ("Your brand" or "Branded content") and sees the consent notice for TikTok's Music Usage Confirmation and, when applicable, the Branded Content Policy. Until TikTok audits the app, everything is posted as "Only me".
  • With TikTok API for Business: dashboards of campaigns, ad groups and ads with aggregated metrics (spend, impressions, clicks, conversions).
  • When the business turns these features on: moderation of comments on its videos and ads (reply, hide), receiving lead-form submissions from its ads, sending conversion events (Events API) with personal identifiers hashed with SHA-256, product catalogs, and viewing finished LIVE sessions and their results.
  • TikTok direct messages in the unified inbox: only after TikTok approves Business Messaging for MARKETIA; until then it is disabled.

What it does not do

  • It does not access accounts the business has not connected, nor data from other TikTok users beyond the comments and messages the business's accounts receive.
  • It does not broadcast or moderate live streams via API (TikTok does not allow it): it only reads finished LIVE sessions.
  • It does not sell data, use it for third-party advertising or to train AI models.
  • It never posts without a user action: every post is created or scheduled by a person at the business.

How authorization works

  1. An administrator of the business opens MARKETIA → Connections → TikTok (or TikTok Business) and clicks "Connect".
  2. MARKETIA redirects to TikTok's official consent screen with a signed state parameter (expires after 15 minutes and carries the organization and user) that protects against CSRF.
  3. The person signs in to TikTok and decides which permissions to grant. MARKETIA never sees their password.
  4. TikTok redirects back to the callback URL. MARKETIA's server exchanges the code for tokens, encrypts them and stores which scopes were granted.
  5. If a scope is missing, the feature that depends on it is disabled in the interface with instructions to reconnect and grant it. Nothing fails halfway.

Permissions and what they are used for

"MARKETIA" app on TikTok for Developers (Login Kit, Content Posting API and Display API)

Callback: https://fapi.marketia.cerebria.co/api/v1/tiktok/oauth/callback

PermissionUsed for
user.info.basicIdentify the connected account (open_id), its display name and avatar.
user.info.profileShow the profile link, bio and verified status.
user.info.statsShow followers, following, likes and video count.
video.listList the account's videos and their metrics for analytics.
video.publishPost directly to the profile the videos and photos the user creates or schedules in MARKETIA.

TikTok API for Business: advertiser authorization

Callback: https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/anunciante/callback

PermissionUsed for
Ad Account ManagementSee the authorized ad accounts: name, currency, time zone, status and balance.
ReportingAggregated metrics for campaigns, ad groups and ads.
Ads Management and Creative ManagementCreate and edit ads, and Spark Ads, when the business enables it.
Audience ManagementCreate custom audiences, for example people who watched a LIVE session.
Measurement and Pixel ManagementSend conversion events (Events API) with identifiers hashed with SHA-256.
DPA Catalog ManagementThe business's product catalogs (requires a Business Center).
Lead ManagementReceive lead-form submissions from the business's ads.
Ad CommentsModerate comments on the business's ads.
TikTok AccountsLink the advertiser with the business's TikTok accounts.

TikTok API for Business: TikTok account holder authorization

Callback: https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/cuenta/callback/

PermissionUsed for
user.info.basic, user.info.username, user.info.profileIdentify the account and link it with the connected organic account.
user.info.stats, user.account.type, user.insightsCounters, account type (Business or not) and account analytics.
video.list, video.insightsThe account's videos and their metrics.
comment.list, comment.list.manageRead, reply to and hide comments on the business's videos.
video.publishPost through the Business API when the business enables it.
biz.brand.insightsBrand mentions (Business accounts only).
message.list.read, message.list.send, message.list.manageDirect messages in the inbox. Only after TikTok's approval (Business Messaging).

What data is stored

  • From the TikTok account: identifier, username, display name, avatar (copied to our storage because TikTok's link expires), whether it is a Business or verified account, and follower, video and like counts.
  • From ad accounts: name, currency, time zone, status, balance and aggregated campaign metrics; from Business Centers, their name and company. Advertising metrics do not identify individuals.
  • Only if the business enables those features: comments on its videos and ads with the commenter's public name, the direct messages it receives, and lead-form data from its ads.
  • Access and refresh tokens, always encrypted, and the list of granted and declined scopes.

Encryption and security

  • TikTok API for Business tokens are encrypted at rest with AES-256-GCM (256-bit key derived with HKDF-SHA256, random nonce per token). Tokens for the TikTok for Developers app are encrypted with authenticated encryption (Fernet: AES-128-CBC + HMAC-SHA256).
  • Tokens are decrypted only on the server at the moment of calling TikTok, and are never returned to the interface or the API, nor written to logs or alerts.
  • The access token lasts 24 hours and is refreshed automatically; the refresh token rotates and is stored under a lock so the account is never invalidated.
  • Tenant isolation: every account is always looked up by its organization; an active ad account or TikTok account can only be connected to one business.
  • TikTok webhooks are verified with the Tiktok-Signature header and a maximum 5-minute time skew, and processed idempotently.
  • All traffic is encrypted with TLS (HTTPS).

Disconnection, retention and deletion

  • From MARKETIA (Connections → TikTok → Disconnect): access is revoked on TikTok, pending posts are cancelled, and the account, its tokens and dependent data are deleted.
  • When an advertiser authorization is removed: it is revoked on TikTok, its subscriptions are cancelled and its ad accounts, metrics and Business Centers are deleted.
  • From TikTok (Settings and privacy → Security → Manage app permissions, or in TikTok for Business): TikTok sends authorization.removed, the account is revoked immediately, we stop reading and sending anything and the business is notified. This event is always applied, even if the module is switched off.
  • Deletion on request: by emailing developer@cerebria.co, within 30 days at most. Details on the data deletion page.

Related documents: privacy · data deletion · terms · security

Callback and webhook URLs

PurposeURL
OAuth callback (TikTok for Developers, Login Kit)https://fapi.marketia.cerebria.co/api/v1/tiktok/oauth/callback
Advertiser OAuth callback (TikTok API for Business)https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/anunciante/callback
Account holder OAuth callback (TikTok API for Business)https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/cuenta/callback/
Webhook (TikTok for Developers)https://fapi.marketia.cerebria.co/api/v1/webhooks/tiktok
Webhook (TikTok API for Business)https://fapi.marketia.cerebria.co/api/v1/webhooks/tiktok-business
Web applicationhttps://marketia.cerebria.co
MARKETIA privacy policy (Spanish)https://fapi.marketia.cerebria.co/legal/privacidad
MARKETIA terms of service (Spanish)https://fapi.marketia.cerebria.co/legal/condiciones

Contact

For any question about the TikTok integration, test accounts or data requests: developer@cerebria.co

Privacy and deletion requests: developer@cerebria.co

Screens

Screenshots of the real application with fictitious sample data. The interface is in Spanish.

  • TikTokDesktop

    TikTok account, videos and statistics connected through official OAuth, with the granted permissions shown.

  • TikTok LIVEDesktop

    Finished LIVE sessions, ad audiences and a LIVE planner; explains what the TikTok API allows and what it does not.

  • TikTokMobile

    TikTok account, videos and statistics connected through official OAuth, with the granted permissions shown.

  • PublishingDesktop

    Publish and schedule to Facebook and Instagram (plus Threads and TikTok when connected) from a calendar.

  • ConnectionsDesktop

    Connect Meta Ads, Pages, Instagram, Threads, TikTok, WhatsApp and Shopify through official OAuth. Tokens are encrypted and never exposed.

  • ModerationDesktop

    Facebook, Instagram, Threads and TikTok activity: AI-classified comments, removed or hidden ones and the reactions breakdown.

Other integrations