What MARKETIA does
- Shows the connected account's profile (display name, avatar, bio, verified status) and its counters: followers, following, likes and number of videos.
- Lists the account's videos with their metrics so the business can see what content works.
- Publishes and schedules videos and photos to the connected account from MARKETIA's calendar, following TikTok's Content Posting API guidelines: creator info is queried before every post, the user picks the privacy level (there is no default), turns comments, Duet and Stitch on or off as the account allows, discloses commercial content ("Your brand" or "Branded content") and sees the consent notice for TikTok's Music Usage Confirmation and, when applicable, the Branded Content Policy. Until TikTok audits the app, everything is posted as "Only me".
- With TikTok API for Business: dashboards of campaigns, ad groups and ads with aggregated metrics (spend, impressions, clicks, conversions).
- When the business turns these features on: moderation of comments on its videos and ads (reply, hide), receiving lead-form submissions from its ads, sending conversion events (Events API) with personal identifiers hashed with SHA-256, product catalogs, and viewing finished LIVE sessions and their results.
- TikTok direct messages in the unified inbox: only after TikTok approves Business Messaging for MARKETIA; until then it is disabled.
What it does not do
- It does not access accounts the business has not connected, nor data from other TikTok users beyond the comments and messages the business's accounts receive.
- It does not broadcast or moderate live streams via API (TikTok does not allow it): it only reads finished LIVE sessions.
- It does not sell data, use it for third-party advertising or to train AI models.
- It never posts without a user action: every post is created or scheduled by a person at the business.
How authorization works
- An administrator of the business opens MARKETIA → Connections → TikTok (or TikTok Business) and clicks "Connect".
- MARKETIA redirects to TikTok's official consent screen with a signed
stateparameter (expires after 15 minutes and carries the organization and user) that protects against CSRF. - The person signs in to TikTok and decides which permissions to grant. MARKETIA never sees their password.
- TikTok redirects back to the callback URL. MARKETIA's server exchanges the code for tokens, encrypts them and stores which scopes were granted.
- If a scope is missing, the feature that depends on it is disabled in the interface with instructions to reconnect and grant it. Nothing fails halfway.
Permissions and what they are used for
"MARKETIA" app on TikTok for Developers (Login Kit, Content Posting API and Display API)
Callback: https://fapi.marketia.cerebria.co/api/v1/tiktok/oauth/callback
| Permission | Used for |
|---|---|
user.info.basic | Identify the connected account (open_id), its display name and avatar. |
user.info.profile | Show the profile link, bio and verified status. |
user.info.stats | Show followers, following, likes and video count. |
video.list | List the account's videos and their metrics for analytics. |
video.publish | Post directly to the profile the videos and photos the user creates or schedules in MARKETIA. |
TikTok API for Business: advertiser authorization
Callback: https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/anunciante/callback
| Permission | Used for |
|---|---|
Ad Account Management | See the authorized ad accounts: name, currency, time zone, status and balance. |
Reporting | Aggregated metrics for campaigns, ad groups and ads. |
Ads Management and Creative Management | Create and edit ads, and Spark Ads, when the business enables it. |
Audience Management | Create custom audiences, for example people who watched a LIVE session. |
Measurement and Pixel Management | Send conversion events (Events API) with identifiers hashed with SHA-256. |
DPA Catalog Management | The business's product catalogs (requires a Business Center). |
Lead Management | Receive lead-form submissions from the business's ads. |
Ad Comments | Moderate comments on the business's ads. |
TikTok Accounts | Link the advertiser with the business's TikTok accounts. |
TikTok API for Business: TikTok account holder authorization
Callback: https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/cuenta/callback/
| Permission | Used for |
|---|---|
user.info.basic, user.info.username, user.info.profile | Identify the account and link it with the connected organic account. |
user.info.stats, user.account.type, user.insights | Counters, account type (Business or not) and account analytics. |
video.list, video.insights | The account's videos and their metrics. |
comment.list, comment.list.manage | Read, reply to and hide comments on the business's videos. |
video.publish | Post through the Business API when the business enables it. |
biz.brand.insights | Brand mentions (Business accounts only). |
message.list.read, message.list.send, message.list.manage | Direct messages in the inbox. Only after TikTok's approval (Business Messaging). |
What data is stored
- From the TikTok account: identifier, username, display name, avatar (copied to our storage because TikTok's link expires), whether it is a Business or verified account, and follower, video and like counts.
- From ad accounts: name, currency, time zone, status, balance and aggregated campaign metrics; from Business Centers, their name and company. Advertising metrics do not identify individuals.
- Only if the business enables those features: comments on its videos and ads with the commenter's public name, the direct messages it receives, and lead-form data from its ads.
- Access and refresh tokens, always encrypted, and the list of granted and declined scopes.
Encryption and security
- TikTok API for Business tokens are encrypted at rest with AES-256-GCM (256-bit key derived with HKDF-SHA256, random nonce per token). Tokens for the TikTok for Developers app are encrypted with authenticated encryption (Fernet: AES-128-CBC + HMAC-SHA256).
- Tokens are decrypted only on the server at the moment of calling TikTok, and are never returned to the interface or the API, nor written to logs or alerts.
- The access token lasts 24 hours and is refreshed automatically; the refresh token rotates and is stored under a lock so the account is never invalidated.
- Tenant isolation: every account is always looked up by its organization; an active ad account or TikTok account can only be connected to one business.
- TikTok webhooks are verified with the
Tiktok-Signatureheader and a maximum 5-minute time skew, and processed idempotently. - All traffic is encrypted with TLS (HTTPS).
Disconnection, retention and deletion
- From MARKETIA (Connections → TikTok → Disconnect): access is revoked on TikTok, pending posts are cancelled, and the account, its tokens and dependent data are deleted.
- When an advertiser authorization is removed: it is revoked on TikTok, its subscriptions are cancelled and its ad accounts, metrics and Business Centers are deleted.
- From TikTok (Settings and privacy → Security → Manage app permissions, or in TikTok for Business): TikTok sends
authorization.removed, the account is revoked immediately, we stop reading and sending anything and the business is notified. This event is always applied, even if the module is switched off. - Deletion on request: by emailing developer@cerebria.co, within 30 days at most. Details on the data deletion page.
Related documents: privacy · data deletion · terms · security
Callback and webhook URLs
| Purpose | URL |
|---|---|
| OAuth callback (TikTok for Developers, Login Kit) | https://fapi.marketia.cerebria.co/api/v1/tiktok/oauth/callback |
| Advertiser OAuth callback (TikTok API for Business) | https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/anunciante/callback |
| Account holder OAuth callback (TikTok API for Business) | https://fapi.marketia.cerebria.co/api/v1/tiktok-business/oauth/cuenta/callback/ |
| Webhook (TikTok for Developers) | https://fapi.marketia.cerebria.co/api/v1/webhooks/tiktok |
| Webhook (TikTok API for Business) | https://fapi.marketia.cerebria.co/api/v1/webhooks/tiktok-business |
| Web application | https://marketia.cerebria.co |
| MARKETIA privacy policy (Spanish) | https://fapi.marketia.cerebria.co/legal/privacidad |
| MARKETIA terms of service (Spanish) | https://fapi.marketia.cerebria.co/legal/condiciones |
Contact
For any question about the TikTok integration, test accounts or data requests: developer@cerebria.co
Privacy and deletion requests: developer@cerebria.co