TikTok Posting API: Publish Video with Required Privacy Consent
Updated 2026-09-28
A tiktok posting api is TikTok's Content Posting API, the official way for an app to publish or draft a video to a creator's account. IMMA AI's tiktok posting api integration never picks a privacy level for the creator; it generates an approval page so the owner confirms who can see the post before IMMA AI calls TikTok.
What is the TikTok posting API?
TikTok's Content Posting API has two modes. Direct Post (video.publish) publishes a video straight to the creator's account once TikTok accepts the request. Upload (video.upload) instead sends the video to the creator's TikTok inbox as a draft, capped at 5 pending drafts per 24 hours, for the creator to finish and post inside the TikTok app itself. Both modes need an approved TikTok developer app and, before that app passes TikTok's audit, posts are limited to 5 test users, the connected account must be private, and every post is forced to SELF_ONLY visibility (it stays private even after the audit passes). TikTok also requires the app to fetch creator_info before showing a posting form, so the interface reflects the real creator: nickname, avatar and which privacy or interaction options that account is actually allowed to use. IMMA AI's tiktok posting api layer (preview) handles this lookup automatically through get_account_capabilities.
Does the TikTok posting API require user consent?
Yes, and this is the rule most third party integrations get wrong. TikTok requires the account owner to preview the exact video, caption and thumbnail and pick a privacy setting themselves, in a real interface, before Direct Post can publish anything; an app is not allowed to fill in privacy_level on the user's behalf. IMMA AI enforces this at the API layer, not only in its own dashboard: a POST /posts call targeting TikTok direct mode is rejected with 422 consent_required unless it carries a signed consent object confirming the owner already reviewed and approved the exact content. Without that flag, IMMA AI automatically creates a hosted approval link instead, commonly shared over Telegram, where the owner sees the real preview and chooses privacy from TikTok's own options with no default selected. Comment, Duet and Stitch toggles start off. Only after that explicit confirmation does IMMA AI call the Content Posting API, which keeps every integration, including headless ones built by other developers, compliant with TikTok's review requirements by construction.
What are TikTok's posting limits and requirements?
TikTok enforces limits that a tiktok posting api integration needs to check before queuing a post, not after a rejection. A creator can publish roughly 15 posts per day, and each access token is rate limited to 6 requests per minute. Video files must be MP4, WebM or MOV (H.264 is recommended), between 360 and 4096 pixels, 23 to 60 frames per second, under 4GB and under 10 minutes long; uploads are sent in 5 to 64MB chunks and the upload URL TikTok issues is valid for 1 hour. Photo posts allow up to 35 images in JPEG or WebP, pulled only from a verified URL domain, not a direct file upload. Access tokens last 24 hours and refresh tokens last 365 days; a refresh can return a new refresh token that must be stored, since the old one stops working. IMMA AI checks these limits, refreshes tokens automatically, and surfaces a clear quota message instead of letting a post fail at TikTok's servers.
TikTok posting API limits at a glance
| Limit | Value | Source |
|---|---|---|
| Posts per creator per day | About 15 | developers.tiktok.com content sharing guidelines |
| Token rate limit | 6 requests per minute | developers.tiktok.com content sharing guidelines |
| Video length | Up to 10 minutes, under 4GB | developers.tiktok.com content sharing guidelines |
| Pending inbox drafts | Up to 5 per 24 hours | developers.tiktok.com content sharing guidelines |
| Access token lifetime | 24 hours (refresh token 365 days) | developers.tiktok.com content sharing guidelines |
How it works
IMMA AI's tiktok posting api integration validates the video against TikTok's format rules, fetches the creator's current creator_info, and either checks a supplied consent object or generates an approval link for the owner. Only after explicit confirmation does IMMA AI call the Content Posting API to publish or draft the post. See the TikTok Content Posting API audit guide for how to pass TikTok's review, or the social media API page for how TikTok fits alongside Instagram, Facebook and Threads.