TikTok API
TikTok for Developers provides APIs for content posting, user data access, and analytics. An official audit is required to enable public video publishing — unaudited apps are restricted to private-only posts.
API Overview
2026 EditionThe TikTok Content Posting API allows developers to build integrations that publish videos to TikTok creator accounts. It supports Direct Post (public to profile) and Upload/Inbox (saved as draft) workflows. The Display API provides access to public profile data and video lists. An official audit by TikTok is required for any app to post publicly — unaudited apps are limited to private posts and 5 users per 24 hours.
Critical: Audit Gate — Without completing TikTok's official app audit, all content posted via your app will be forced to SELF_ONLY (private) privacy, and your app is capped at 5 users per 24-hour window. Plan for a multi-week audit process before launch.
API Features
| Feature | Description | Required Scope | Status |
|---|---|---|---|
| Direct Post | Post video directly to a creator's public profile | video.publish | Audit Required |
| Upload / Inbox | Save video as draft in creator's TikTok inbox | video.upload | Available |
| User Info | Access basic profile info: username, avatar, follower count | user.info.basic | Available |
| Video List | List a user's public videos | video.list | Available |
| Creator Info Query | Check creator account permissions and quota before posting | video.publish | Available |
| Research API | Public data access for approved researchers | Separate Research application | Restricted |
Rate Limits
2026 Data| API / Endpoint | Rate Limit | Window | Notes |
|---|---|---|---|
| Content Posting Initiation | 6 requests / minute | Per user access token | Per creator account, across all apps |
| Daily Post Cap | ~15 posts / day | Per creator account | Shared across all API clients used by the creator |
| Display API Endpoints | 600 requests / minute | Per endpoint | e.g., /v2/user/info/, /v2/video/list/ |
| Research API | 1,000 requests / day | Daily | Up to 100,000 records/day |
| Unaudited App User Cap | 5 users / 24 hours | Rolling 24 hours | Hard cap for apps that have not passed audit |
Rate limit violations return HTTP 429 (rate_limit_exceeded). Do not treat publishing as a synchronous request — use a polling or webhook-based workflow to confirm the final PUBLISH_COMPLETE status.
Media Requirements
| Parameter | Requirement | Notes |
|---|---|---|
| Supported Format | MP4 (strongly recommended), MOV, WEBM | MP4 with H.264 codec is the standard |
| Video Codec | H.264 | H.264 is the recommended codec for TikTok compatibility |
| Duration | 3 seconds – 10 minutes | Check latest API docs — this range can vary by endpoint |
| Minimum Resolution | 720p (720×1280 px) | 1080p or higher strongly recommended for quality |
| Aspect Ratio | 9:16 (vertical) recommended | 1:1 and 16:9 also accepted |
| Transfer Methods | Local file upload or PULL_FROM_URL | For PULL_FROM_URL, your domain must be verified in TikTok Developer Portal under "Manage URL properties" |
| Watermarks | NOT ALLOWED | Third-party logos, watermarks, or promotional branding in the video are prohibited |
| Creator Attribution | Required | Your app UI must display the creator's username and avatar — checked during the audit |
Authentication & Access
| Requirement | Details |
|---|---|
| Auth Method | OAuth 2.0 — standard authorization code flow |
| Developer Account | TikTok for Developers account at developers.tiktok.com |
| App Audit | Required to enable public posting (video.publish scope). Unaudited apps default to SELF_ONLY privacy and 5-user cap. |
| Scope Approval | Each scope must be requested and approved separately in the TikTok Developer Portal |
| Creator Info Preflight | Always call the Creator Info API before posting to check account eligibility and current quota |
OAuth Scopes
Quick Start Guide
Create a TikTok App & Request Scopes
Register an app at developers.tiktok.com. Request video.publish and/or video.upload scopes. Submit for audit for public posting access.
Authorize User via OAuth 2.0
GET https://www.tiktok.com/v2/auth/authorize/ ?client_key=YOUR_CLIENT_KEY &scope=video.publish &response_type=code &redirect_uri=YOUR_REDIRECT_URI &state=RANDOM_STATE_VALUE
Preflight: Check Creator Info
POST https://open.tiktokapis.com/v2/post/publish/creator_info/query/
Authorization: Bearer USER_ACCESS_TOKEN
Content-Type: application/json; charset=UTF-8
{}Initiate Video Upload
POST https://open.tiktokapis.com/v2/post/publish/video/init/
Authorization: Bearer USER_ACCESS_TOKEN
Content-Type: application/json; charset=UTF-8
{
"post_info": {
"title": "My TikTok Video",
"privacy_level": "PUBLIC_TO_EVERYONE",
"disable_duet": false,
"disable_comment": false
},
"source_info": {
"source": "PULL_FROM_URL",
"video_url": "https://your-cdn.com/video.mp4"
}
}Poll for Publish Status
Use the returned publish_id to poll the status endpoint until you receive PUBLISH_COMPLETE.
Common Errors & Solutions
| Error | Meaning | Solution |
|---|---|---|
| HTTP 429 | Rate limit exceeded | Implement exponential backoff with jitter. Do not retry immediately. |
| access_denied | User denied OAuth authorization | Guide user back through the OAuth flow. Check that requested scopes match approved scopes. |
| spam_risk_too_high | Post blocked as spam | Review post content and frequency. Reduce posting rate well below the 15/day cap. |
| user_cap_exceeded | Unaudited user cap reached | 5-user limit reached for unaudited apps. Submit app for TikTok audit to remove this restriction. |
| video_url_unverified | Source domain not verified | Register your domain in TikTok Developer Portal under "Manage URL properties" before using PULL_FROM_URL. |
Best Practices
Always Preflight Check
Before every post, call the Creator Info API to validate account eligibility, check remaining quota, and verify the user has granted the correct scopes.
Show Creator Attribution
Your app UI must display the creator's username and avatar as part of the publishing flow — this is checked during the audit and is non-negotiable.
Use Idempotency Keys
Include idempotency keys in publish requests to safely retry failed calls without creating duplicate posts during network errors.
No Watermarks in Video
Do not embed third-party logos, watermarks, or promotional branding inside the video content. This violates TikTok's API policies and will fail the audit.
Verify Pull Domains
If using PULL_FROM_URL, pre-register all source domains in the TikTok Developer Portal. Unregistered domains will cause video_url_unverified errors.
Async Publishing Flow
Never treat video publishing as synchronous. Always poll the status endpoint to confirm PUBLISH_COMPLETE before showing success to the user.