The publishing flow
How it works
Four screens, in this order. Every call Spotly makes to TikTok is listed so you know exactly what happens on your account, and when.
1. Connecting an account
You start the connection from Spotly and land on TikTok's own authorization screen — Login Kit, OAuth 2.0 with PKCE. Spotly never sees your TikTok password: it receives an authorization code that it exchanges for a token, and only after you have approved the permissions listed on that screen.
Back in Spotly, the connected account is shown with its name, avatar and counters. If it is not the account you meant to connect, you can see it immediately, before publishing anything. Several accounts can be connected side by side; each keeps its own authorization.
2. Reading what the account allows
Before offering any publishing option, Spotly queries TikTok for the creator's current
settings (creator_info). That answer decides what the screen offers:
- the privacy levels available for this account — nothing is hardcoded, the list comes from TikTok;
- whether comments, Duet and Stitch can be enabled — options TikTok reports as unavailable are shown disabled rather than silently ignored;
- the maximum video duration allowed for the account.
An account set to private, for instance, does not offer Public to everyone — so Spotly does not offer it either. What you see is what TikTok allows at that moment.
3. Choosing the clip and the settings
Your clips are listed with a preview so you can confirm the right one, then you choose:
- Who can see it — the privacy level, taken from the list above. No default is applied on your behalf: the publish button stays disabled until you have chosen.
- Interactions — comments, Duet, Stitch.
- Publishing mode — draft sends the clip to the account's TikTok inbox so you can finish it in the app (cover, sounds, effects), direct publishes it as it is.
4. Publishing
The clip is uploaded only after an explicit confirmation. Spotly then polls TikTok's publish status until it comes back complete, and shows the outcome — including the failure reason if TikTok refuses the post. By using direct publishing you confirm that the content complies with TikTok's Music Usage Confirmation.
Permissions, one by one
| Permission | Where it is used |
|---|---|
user.info.basic |
Step 1 — identifies the connected account and displays its name and avatar so you can confirm it. |
user.info.stats |
Step 1 — follower and video counts, shown to tell several connected accounts apart. |
video.upload |
Step 4, draft mode — sends the clip to the account's TikTok inbox, where you finish and post it from the app. |
video.publish |
Step 4, direct mode — publishes the clip with the privacy level chosen in step 3. |
Nothing else is requested. Spotly does not read your feed, your followers' data, your messages or your existing videos.
What happens to the video file
The clip is read from the machine running Spotly and sent to TikTok over the Content Posting API. It is not copied to any third-party server on the way, and Spotly keeps no copy of its own once TikTok has confirmed the upload. See the Privacy Policy for the full picture, including what is stored and how to have it deleted.