IMMA AI Docs

Platform rules

TikTok consent requirements and Meta/TikTok posting limits that every integration must respect.

Preview

Preview: the API and MCP server are in private beta; details may change.

TikTok and Meta review every app that posts on a user's behalf, and both platforms reject apps that skip these rules. IMMA AI enforces them in packages/core, not only in a UI, so there is no way to bypass them by calling the API directly.

TikTok Direct Post always needs human consent

TikTok's Content Posting API requires the account owner to see a real preview and choose the post's privacy setting themselves, every time. IMMA AI never chooses privacy_level on your behalf, and it never defaults interaction toggles to on.

There are three ways to capture that consent, plus a no-consent fallback:

  1. Composer consent. When the account owner themselves is the one preparing the post in the IMMA AI dashboard composer, picking a privacy option there and pressing Schedule/Publish is the consent: no separate approval link is needed, because the owner already saw the preview and chose the setting in the same session.
  2. Hosted approval page (default when someone else prepares the post). Send approval: { "mode": "link" } (or omit approval entirely for TikTok targets). This covers a post prepared by someone other than the account owner, or one that comes from an AI agent, MCP or the API. IMMA AI generates a hosted page, commonly shared over Telegram, where the owner sees the caption, media and thumbnail, and picks who can view it from TikTok's own privacy_level_options, with no option preselected. Comment, Duet and Stitch toggles start unchecked.
  3. API consent flags, for integrators building their own UI. If your own interface already collects consent (for example a composer you built), you can send mode: "direct" with an explicit consent object instead of using IMMA AI's hosted approval page. Responsibility for meeting TikTok's UX requirements shifts to your own UI when you use this path.
  4. Inbox / draft mode (no-consent fallback). Send tiktok: { "mode": "inbox" }. When none of the above apply, the post is delivered as a draft to the creator's TikTok inbox, and they finish and publish it from the TikTok app themselves.

If your own interface already collects consent, you can send mode: "direct" with an explicit consent object instead of using IMMA AI's hosted approval page:

"tiktok": {
  "privacy_level": "PUBLIC_TO_EVERYONE",
  "disable_comment": true,
  "disable_duet": true,
  "disable_stitch": true,
  "brand_organic_toggle": false,
  "brand_content_toggle": false,
  "consent": {
    "preview_shown": true,
    "user_confirmed": true,
    "confirmed_at": "2026-09-28T11:25:00Z"
  }
}

If consent is missing, the API does not fail silently: it automatically falls back to generating an approval link (or inbox mode if tiktok.mode is "inbox"). Sending this flag is only valid if your own UI actually implements the full consent flow: a visible, unselected privacy dropdown, interaction toggles that default off, and a preview shown before the confirm action. By sending this flag you are certifying your UI meets that bar, since TikTok's own review holds your app to the same standard regardless of which system generated the request.

Posting limits

Each platform enforces its own limits, checked before a post is queued so you get a clear quota_exceeded style error instead of a platform level rejection after the fact.

PlatformLimitNotes
Instagram100 posts per account per rolling 24 hoursA carousel (up to 10 items) counts as one post
Threads250 posts, 1,000 replies, 100 deletes per account per 24 hoursCheck remaining quota via GET /threads_publishing_limit
Facebook PagesStandard Graph API rate limitsMinimum scopes: pages_show_list, pages_read_engagement, pages_manage_posts
TikTokAbout 15 posts per creator per dayAccess token is also rate limited to 6 requests per minute

For POST /posts/batch, quota is checked per target day from each item's scheduled_at, not just against the total batch, so one full day does not reject the rest of a month's calendar. See the batch endpoint in the API reference.

Why this matters for your integration

If you are building your own UI on top of the IMMA AI API instead of using IMMA AI's hosted approval page, your interface is what TikTok and Meta actually review. Follow the same rules IMMA AI's own UI follows: never preselect a privacy option, never default interaction toggles to on, always show a real preview before the confirm action, and never request a platform permission or scope that no screen in your product actually uses.

See Errors for what happens when these rules are violated (for example consent_required or privacy_level_mismatch).

On this page