If you have ever tried to publish a video to TikTok from your own code, you have run into the TikTok Content Posting API, or at least the wall that sits in front of it. When you search for the tiktok content posting api explained, most results jump straight into endpoint names and OAuth flows without telling you what the API is for, where it stops, and why so many small brands never finish integrating it. This post goes the other way. It walks through what the API actually does, the modes you choose between, the review work that catches people off guard, and the limits that decide your whole design.
Your app
|
| 1. OAuth: user authorizes your app
| scopes: video.publish, video.upload
v
TikTok API
|
| 2. Init upload -> returns publish_id
| 3. PUT chunks to upload_url
v
Media stored
|
+--> DIRECT POST -> video is public
|
+--> DRAFT -> sits in the user's
inbox, they finish it in the app
What the TikTok Content Posting API Actually Does
The Content Posting API is TikTok’s route for getting a video or a photo carousel from your app and onto someone’s TikTok account. It handles two jobs and only two jobs: upload the media, and tell TikTok what to publish or draft.
That is the whole scope. It is not an analytics API, not a comment API, not an advertising API. Every capability beyond publishing lives somewhere else on TikTok’s developer platform, and mixing them up is the fastest way to build the wrong thing.
In practice, your app sends TikTok a request to start an upload. TikTok answers with an upload URL and a publish ID. You push the file bytes to that URL in chunks. Then you call publish, in one of the two modes described below.
Video is the main event. Photo carousels are supported too. The metadata you can attach is limited: a caption of up to 4,000 characters, a cover image or cover timestamp, privacy level, and the consent flags TikTok requires before anything goes live.
If you are deciding whether to build on this or on a platform that already speaks every network, the tradeoff is the same as with any single-platform integration. Building it yourself means owning the OAuth, the review, the chunking, and the error handling forever. Using a platform that already does it means one connection covers TikTok alongside Instagram, YouTube, X, LinkedIn, Facebook and Threads.
Direct Post vs Draft Upload: Choosing Your Posting Mode
This is the single most consequential design decision, and it is easy to get wrong.
Direct post publishes straight to the user’s profile. The video becomes public the moment TikTok finishes processing it. You control privacy level, comments, duets, stitches, and the disclosure flags.
Draft upload sends the video to the TikTok Creator Inbox instead. Nothing goes live. The creator opens the TikTok app, finishes the post with trending sounds, stickers, or edits, and pushes it out themselves.
Direct post is what you want for a fully automated pipeline. Draft upload is what you want when a human still needs to be in the loop, or when trending audio matters. TikTok does not let the API attach trending audio, so if your content depends on the current sound, you have to bake the audio into the file before upload or send a draft and let the creator add the sound in the app.
One thing worth knowing: business app connections publish public-only unless you send them as drafts. If your brand account is connected through TikTok’s business path, plan the publishing flow accordingly.
The OAuth and App Review Requirements Nobody Warns You About
TikTok does not hand out posting access on day one. The path looks like this.
You register an app and request scopes. Posting needs the video publish and video upload scopes. TikTok reviews your app before it can post on behalf of real users, which means a form, screenshots, a description of your use case, and time. Until approval lands, your calls fail in ways that are hard to debug because the endpoints exist and the tokens look valid.
Then there are the consent fields. TikTok requires content_preview_confirmed and express_consent_given to be true. These exist so the user has actually looked at the post before it ships. They are mandatory, not decorative, and forgetting them is a common first failure.
The other requirement set is quieter. Every post needs a privacy_level, plus explicit values for allow_comment, allow_duet, and allow_stitch. TikTok will not guess. If you want the per-field detail, our post on TikTok draft upload covers the flow from the other direction, and the post options docs list every TikTok setting next to the other networks so you can see what differs.
How the Upload Flow Works Step by Step
Here is the sequence in plain language.
- Authorize. The user grants your app the posting scopes through TikTok’s OAuth flow. You end up with an access token tied to that user.
- Init. Your app tells TikTok what it is about to send: file size, chunk size, and content type. TikTok returns a
publish_idand anupload_url. - Chunk it. You PUT the file to the upload URL in pieces, with content-range headers. Large files must be chunked. This is the part that breaks when your chunk size does not match what you declared at init.
- Check status. You poll for processing state until TikTok reports the upload is complete.
- Publish or draft. You send the final call with your metadata and choose direct post or draft.
- Handle the result. Success gives you a post ID. Failure gives you an error code you have to map to something a human can act on.
There is a step missing from most tutorials: cleanup. If you built a pipeline that uploads media once and references it across networks, you want a reusable media ID rather than re-uploading the same file for every platform. That pattern is worth copying. Creator OS exposes it as an upload that returns a med_ id you can reuse everywhere, which is described in the Creator OS docs.
Rate Limits, Quotas, and Common Error Codes
TikTok enforces quotas on the posting endpoints. Your app has a per-day allowance, and users can only post so often. When you exceed it, you get rate limit responses that tell you to back off and try again later.
The errors you will actually see cluster into a few groups. Token errors mean the access token expired or the scopes are wrong. Consent errors mean one of the required flags is missing or false. Media errors usually mean chunking went wrong or the file format was rejected. Privacy errors mean the value you sent is not allowed for that account type, which is common with business connections.
Two more limits that surprise people. TikTok’s video constraints and the caption limit mean you should validate before you send, not after. And if you are publishing to several networks at once, TikTok’s rules are just one set among many, so validation has to run per platform. Our CLI ships a validate:post-length and a validate:media command for exactly this reason.
What You Cannot Do With TikTok’s Posting API
Be clear about the edges before you promise a client anything.
- No trending audio from the API. You bake sound into the file or you send a draft.
- No comment replies. Replying to TikTok comments is not supported. Hiding and deleting work, but only on TikTok for Business accounts.
- No DMs. TikTok is not part of any DM inbox through this API.
- No ads. Advertising is a separate system entirely.
If replies and DMs matter to your workflow, TikTok is the one social network where a unified inbox will not cover everything, because TikTok itself does not expose those surfaces. Our breakdown of automating Instagram and TikTok replies shows where that line sits in practice.
Content Posting API vs TikTok Ads API: Which One You Need
These are two different products with two different goals, and people conflate them constantly.
The Content Posting API publishes organic content to a creator or business account. The Ads API buys distribution. One is “put this video on my profile.” The other is “show this to people who do not follow me, and bill me for it.”
If your goal is organic reach and a posting calendar, you need the Content Posting API. If your goal is paid reach, you need the Ads API. If your goal is both, you need two integrations, two reviews, and two sets of credentials, unless you use something that already fronts both. Creator OS supports TikTok Spark Ads through the ads add-on, and Spark Ads boost your own organic TikToks, which is the bridge most small brands are actually looking for. See TikTok ads API for small brands for that side of the picture.
Simpler Alternatives: Skip API Approval With Creator OS
You do not have to build and maintain this integration yourself.
Creator OS connects TikTok the same way it connects Instagram, YouTube, X, LinkedIn, Facebook, Threads, Skool, and a WordPress blog: you authorize the account once, and then you publish, schedule, reply where replies exist, and read analytics from one place. The web app, the iOS app, a REST API, a CLI, and a hosted MCP server all hit the same workspace.
For agents, the clean path is the MCP server. Add https://mcp.creatoros.ca/mcp as a connector in Claude or ChatGPT, or from Claude Code run:
claude mcp add --transport http creatoros https://mcp.creatoros.ca/mcp \
--header "Authorization: Bearer cos_live_..."
Then your agent has tools like create_post, upload_media_from_url, get_best_time_to_post, and check_caption_length available in plain language. A read-only connection only sees read tools, and the API refuses writes from it.
From the terminal, the same job looks like this:
creatoros media:upload ./reel.mp4
creatoros posts:create --text "Three ways to frame a hook" \
--platforms tiktok,instagram \
--media med_9f2... \
--scheduledAt 2026-03-04T18:00:00Z --timezone America/Toronto
Creator OS fills TikTok’s required consent and privacy fields through the simple post form, so you are not hand-assembling them. If you want TikTok’s drafts instead, set the draft flag and the video lands in the Creator Inbox.
If you would rather hand the whole thing to an agent, our open-source Social Agents harness runs your socials on Creator OS. It interviews you about your brand, then posts, replies, and reports, with a local dashboard. Start it with npm start creatoros social-agents. It is at github.com/kevinbadi/social-agents, and there is a walkthrough on the KevBuildsApps YouTube channel.
If you shoot video, the other half of the job is editing. OPEN VIDEO EDIT is a set of open-source Claude Code skills that turn a raw talking-head clip into an animated short with captions, logos, b-roll cards, and counters. It renders locally with Python and ffmpeg and lives at github.com/kevinbadi/open-edits. The launch video covers it: watch it here.
One more pattern worth stealing: if your posts carry links, generate trackable short links so you can see clicks rather than guessing. And keep your agent credentials tight by reading read-only API keys for AI agents before you hand a key to anything. If you want the wider view of publishing to many networks from one integration, one social media API for every platform is the counterpart to this post.
Get Started Posting to TikTok From One Dashboard
The Creator plan is $19.99/month or $59.99/year for up to 8 connected accounts (7 socials plus Skool). API keys, the MCP server, the CLI, and the agent skills are included in every plan. If you run several brands, agency plans cover up to 40 accounts for $49/month or $399/year.
Connect TikTok, run one test post on a draft, then schedule the real one. Full field-by-field detail is at https://www.creatoros.ca/docs, and the MCP specifics are at https://www.creatoros.ca/docs/mcp.
Create your account and publish your first TikTok from the same dashboard you already use for everything else.