SİNYAL / TikTok integration

Desktop publishing.
Explicitly authorized.

SİNYAL uses TikTok Login Kit and the Content Posting API to support operator-controlled publishing for creator accounts that explicitly authorize the application.

ImportantThe public SİNYAL website is product documentation, not an OAuth redirect endpoint or account portal. Authorization and posting occur in the desktop application.
Product configuration

Desktop creator publishing

Platform: Desktop. Login Kit provides creator authorization and connected-account identity. Content Posting API Direct Post provides the operator-confirmed publishing action. Production API availability remains subject to TikTok approval, permissions, and policies.

End-to-end flow

Authorization, review, and posting remain visible.

SİNYAL does not treat platform access as an invisible background action. The creator authorizes the account, and the operator confirms the selected media and settings before Direct Post begins.

  1. 01

    Start authorization

    The operator starts TikTok Login Kit from the SİNYAL desktop application.

  2. 02

    Review TikTok consent

    TikTok displays the requested permissions and the creator chooses whether to authorize the account.

  3. 03

    Return to the desktop app

    TikTok returns the authorization response to the registered local loopback callback. SİNYAL validates the state and PKCE session before exchanging the code.

  4. 04

    Confirm account identity

    SİNYAL uses user.info.basic to show the connected account identity to the operator.

  5. 05

    Select content and settings

    The operator selects a local media file, reviews the caption and creator settings, and explicitly confirms the action.

  6. 06

    Direct Post and status

    With video.publish authorization, SİNYAL transfers the selected file to TikTok for Direct Post and checks the returned publish status.

Permissions

Each scope has a defined product purpose.

SİNYAL requests and uses permissions only in the context of a creator account that authorizes the desktop application.

user.info.basic

Connected account identity

Used to retrieve basic identity information for the TikTok account connected through Login Kit.

Used by the current workflow
video.publish

Direct Post

Used to query creator posting options and directly post content after explicit operator confirmation.

Used by the current workflow
video.upload

Draft upload

This separate TikTok scope is for sending a draft to the creator's TikTok inbox. SİNYAL's current Direct Post workflow does not use it.

Not used by the current workflow

SİNYAL uses TikTok's FILE_UPLOAD media-transfer method within Direct Post. That transfer method operates under video.publish and is distinct from the separate video.upload draft-upload scope.

Website and redirect configuration

The public website and desktop callback serve different purposes.

The website URL identifies SİNYAL publicly. The redirect URI is a local loopback address registered specifically for the Desktop Login Kit authorization response.

ConfigurationExact valuePurpose
Official website

https://greedysensei.github.io/sinyal-website/

Public product and policy documentation
Desktop redirect URI

http://127.0.0.1:8765/tiktok/callback

Local OAuth response for the desktop app
Media source

Operator-selected local file

Transferred through TikTok's FILE_UPLOAD flow

The GitHub Pages website is not configured as the OAuth callback. SİNYAL does not use a public redirect domain for this Desktop Login Kit flow.

Data boundaries

What the desktop integration may process.

Only information needed to maintain the authorized connection, prepare the selected publishing action, and record its result is relevant to the integration.

ACCOUNT

Authorization records

  • TikTok account identifier and basic profile information
  • Granted scopes, token type, and expiry details
  • Access and refresh tokens for the authorized connection
  • Desktop OAuth state and PKCE session information
CONTENT

Publishing records

  • The local media file deliberately selected by the operator
  • Caption, privacy selection, and posting settings
  • Creator information checked before posting
  • Publish identifier, status response, and operational log

This public website does not store TikTok tokens, connect accounts, accept media uploads, or expose desktop application records.

Product boundaries

Clear expectations for reviewers and creators.

These statements distinguish SİNYAL from TikTok and distinguish the public documentation website from the desktop product.

×

No public account portal. Website visitors cannot connect an account or initiate a post.

×

No unauthorized posting. TikTok actions require an authorized account context.

×

No hidden automatic posting. The operator reviews the selected media and confirms the action.

×

No credential publication. Client secrets and tokens are not included in this website or public repository.

×

No TikTok affiliation claim. SİNYAL is an independent product and is not sponsored, endorsed, or operated by TikTok.

Related policy

Read how authorization and publishing data are handled.

Privacy policy