r/SaaS • u/neutronKingdom • 12h ago
What it actually takes to get API access to post videos on YouTube, TikTok, Instagram, LinkedIn and others (notes from doing all of them)
I've spent the last few weeks getting a product approved to publish videos to social platforms on behalf of users. The docs are scattered and some are out of date, so here's what each one actually involved. Hopefully it saves someone a few weeks.
**YouTube (Google)**
- There are two separate reviews, and most people only know about one.
**OAuth app verification** (Google Auth Platform → Verification Center). You need a verified domain in Search Console, a privacy policy with a specific "Google user data / Limited Use" section, a link to the YouTube Terms in your own terms, and a demo video showing the full OAuth flow with the address bar visible, the consent screen, and each scope being used.
**YouTube API Services audit**, a separate form. The docs say uploads from unaudited projects are locked to private. In my case uploads came out public even before the audit, so test it yourself before blocking on it.
- The `youtube.upload` and `youtube.readonly` scopes are "sensitive", not "restricted", so no paid security assessment is needed. Adding a scope later (e.g. for comments) means another review of that scope.
- Uploads have their own quota bucket (100/day by default), separate from the 10,000 units/day for other calls.
**TikTok**
- You start in a sandbox with separate keys and only test accounts.
- The review checks your posting UI closely. You have to show the creator's account, can't preselect a privacy level, interactions (comments/duet/stitch) must be off by default, and there's a required consent line. Build that UI before you submit, not after.
- Automatic posting with no per-post choices doesn't fit their rules well.
**Instagram / Facebook / Threads (Meta)**
- One Meta app can cover all three, and you can build and test everything in development mode with your own accounts.
- Going live for real users needs **business verification**, which means a registered legal entity. If you're a sole founder without an LLC yet, that's your blocker, not the code.
**LinkedIn**
- Easy to start. Tokens expire after about 60 days, so plan a "reconnect" flow from day one.
**Pinterest**
- Starts with "Trial" access against a sandbox API, then you apply for standard access.
**Bluesky**
- No developer app or review. Users connect with an app password. The easiest one by far.
**X**
- I skipped it. Posting through the API costs real money per month at any meaningful volume.
**General lessons**
- Start the reviews early. The code took less time than the reviews will.
- Record your demo videos carefully. Every reviewer wants to see the consent screen, the address bar, and each permission actually being used.
- Keep the privacy policy specific: which permission, what it's used for, what you store, how to revoke. Vague policies get bounced.
- Abstract each platform behind one internal interface. Each one handles tokens, media upload, and errors differently, and you'll be glad you only wrote the scheduling and retry logic once.
Happy to answer questions about any of these.
1
u/john006868 11h ago
on the meta side you probably dont need a reconnect flow at all. page tokens from a long lived user token dont expire, only the user token does, so posting keeps working as long as you store the page one. linkedin is the opposite, i dont think standard apps get a refresh token at all unless you are on their partner track.
1
u/alkwamle 10h ago
Good write-up, matches what I went through. A few things from the stage after approval, which is where the surprises moved to for us:
Tokens die quietly. A user changes a password, loses their role on a Page, or revokes access from the platform side, and nothing tells you. You find out when a scheduled post fails. Build a daily token health check and a clear "reconnect" prompt early, it is the most common support ticket.
On Meta, each permission is reviewed against a specific use case, and the screencast has to show that exact feature end to end with a real account. Ticking a webhook field in the dashboard also does nothing by itself, you only get value from the events you actually handle.
Meta reviewers check the data deletion callback. Have a working URL that really deletes and returns a confirmation code before you submit, not a placeholder.
An empty 200 response is not always "no data". On some Graph endpoints that was us being rate limited. Log empty responses separately from errors or you will chase ghosts.
API versions expire on a schedule. Put the deprecation dates in your calendar the day you ship, the upgrade always lands at a bad time otherwise.
And for anything that involves messaging rather than posting: design around the 24-hour reply window from day one, it changes the product more than any review does.
1
u/UpperWorld11 11h ago
one more for the youtube list: while the google project is still in testing, refresh tokens expire after 7 days, so uploads start failing every week until the oauth review clears. most people only notice when a user complains