How it works
A transparent integration with the TikTok Marketing API
Freshlytics is a third-party tool. It only ever sees the advertising data an advertiser explicitly authorizes it to read, through TikTok's official API — never through scraping, browser automation, shared passwords or any unofficial access.
The data flow, end to end
Four steps, and you control the first and the last one.
You authorize Freshlytics
From your Freshlytics workspace you start the standard TikTok OAuth flow. TikTok shows you which permissions are being requested; you sign in with your own TikTok Business account and choose which ad accounts to grant. We never ask for or store your TikTok password, and we cannot access accounts you did not select.
We read your account
Our sync service calls the TikTok Marketing API on a schedule — every 15 minutes for active accounts — and pulls campaign structure, performance reports, creatives, catalogs and delivery diagnostics. We honour TikTok's rate limits and request only what the product uses.
We store and normalize it
Metrics are stored in an encrypted database inside your workspace's isolated data set, converted to your reporting currency, and enriched with your targets. Access tokens are encrypted separately and used only to serve your workspace.
You get analysis and alerts
Fatigue, pacing and anomaly models run after each sync. Results appear in your dashboards and, where you asked for it, in Slack, Telegram or email.
You build and publish
New campaigns, uploaded creatives, catalog updates, audiences and budget changes are sent to TikTok when you publish a batch, approve a recommendation or enable a rule. Every write is logged with the user, the source and the values behind it.
You can end it at any moment
Disconnect an account in Freshlytics or revoke the app in TikTok Business Center. Syncing stops immediately, and you can request full deletion of everything we hold.
Permissions
What we ask for, and why
Freshlytics is a full campaign management platform, so it requests a broad set of TikTok Marketing API permissions. Every one of them maps to a feature you can see in the product, and each is listed here with the reason it exists.
| Permission | Type | Why Freshlytics needs it |
|---|---|---|
| Ad Account Management | Read | List the ad accounts and Business Center assets you authorize, with their currency, time zone and status, so data is attributed to the right account. |
| Ads Management | Read Write | Read campaign, ad group and ad structure for reporting; create campaigns, ad groups and ads when you publish a launch batch; apply budget, bid, schedule and status changes you approve or automate. |
| Reporting | Read | Spend, impressions, clicks, conversions, video engagement and cost metrics by day and by hour — the basis of every dashboard, fatigue score and alert. |
| Creative Management | Read Write | Upload the videos and images you attach to a launch batch, read creative metadata and thumbnails for the fatigue radar, and manage the ad identities used on your ads. |
| DPA Catalog Management | Read Write | Create and sync product catalogs and feeds, push product updates, and surface rejected or out-of-stock products before they cost you delivery. |
| Pixel Management | Read | List your pixels and their events so a launch batch can be pointed at the correct optimization event, and so conversion reporting is labelled correctly. |
| Custom Conversion Management | Read Write | Read and create custom conversions used as optimization goals in campaigns you launch from Freshlytics. |
| Offline & CRM Event Management | Write | Send server-side conversion events from your own systems, so optimization and reporting reflect results the pixel cannot see. Identifiers are hashed before transmission. |
| Audience Management | Read Write | List existing audiences for targeting in a launch batch, and create or update custom and lookalike audiences on your instruction. |
| Lead Management | Read | Retrieve leads from lead generation forms on your own ads and pass them to the CRM or webhook you configure. |
| Automated Rules | Read Write | Read and manage TikTok-native automated rules alongside the rules that run inside Freshlytics, so both are visible in one place. |
| Ad Diagnosis | Read | Read delivery diagnostics and rejection reasons so alerts can explain why an ad group stopped spending instead of only that it did. |
| Measurement | Read | Read attribution and measurement reporting to reconcile platform results with your own numbers. |
| App Management | Read | Only for advertisers promoting mobile apps: read the registered apps and their events to set up app-install and in-app-event campaigns. |
| Ad Comments | Read Write | Read and moderate the comments on your own ads — hide, pin or reply at your instruction. We never interact with organic content. |
| TikTok Accounts | Read | Only when you use Spark Ads: read the authorized posts and identities you have explicitly made available for advertising. |
| Brand Safety | Read | Read inventory filter and brand safety settings so they can be applied consistently across the ad groups you launch. |
| Reach & Frequency | Read | Read reach and frequency bookings so reserved buys appear in the same reporting as auction campaigns. |
Not requested at all: Creator Marketplace and creator data, TikTok One, mini programs, payment methods and billing instruments, mentions, business plugins, TikTok Shop storefront management, or any permission that would let Freshlytics post organic content, follow accounts, read direct messages or access a TikTok user's personal profile data.
On permissions that touch personal data. Custom audiences, lead form submissions and server-side conversion events can contain personal data belonging to your customers. For that data you are the controller and Freshlytics is your processor: we transmit it to TikTok on your instruction, hash identifiers before transmission where TikTok requires it, never use it for any other customer, never enrich or resell it, and delete it on request. See the Privacy Policy and Security & data.
Reliability
How the sync behaves in practice
The sync service is designed around TikTok's API limits rather than against them. If TikTok throttles or returns an error, Freshlytics backs off, retries with a longer interval and shows the real state of the data in the interface instead of silently displaying stale numbers.
- Active accounts refresh every 15 minutes; paused accounts fall back to hourly
- Incremental pulls for recent days, with a nightly reconciliation of the last 7 days for attribution updates
- Exponential backoff and per-account queues, so one heavy account never starves the others
- Every screen shows the last successful sync time and any account currently failing
- Token refresh is automatic; if authorization is revoked, syncing stops and you are told
Onboarding in the closed beta
We schedule a 30-minute call, connect your accounts together, set your targets and alert routing, and let the first full sync run. Historical data for the last 90 days is backfilled, then extended in the background.
Support
Beta customers get a shared channel with the team building the product. Questions about data, roadmap and integrations go to the people writing the code, not a ticket queue.
Ready to connect your accounts?
Request beta access and we will walk you through authorization, targets and alerts on a call.