TikTok API for Business Integration
SmartWay Portal — LEAD EMPREENDIMENTO DIGITAIS LTDA
This page describes an integration being prepared for review. It does not state that SmartWay Portal is a TikTok partner, certified product, or approved application.
Company
SmartWay Portal is a web-based digital advertising management platform operated by LEAD EMPREENDIMENTO DIGITAIS LTDA, a legally registered Brazilian company (CNPJ: 51.340.668/0001-19). Official website: https://smartwayportal.com/. Contact: contact@smartwayportal.com.
Purpose
The platform is designed to integrate with authorized TikTok advertising accounts through official API access, enabling the company administrator to access advertising account information, campaign and ad-group data, permitted advertising resources, integrated performance metrics, and operation history. Access is private, there is no public registration, and no account may be connected without the account holder's authorization.
Implemented functionality
- server-side OAuth start, callback, one-time state validation, and code exchange;
- encrypted backend token storage linked to authorized advertiser accounts;
- retrieval of advertiser accounts, campaigns, ad groups, ads, identities, and pixels;
- authenticated Business Center access checks and catalog information retrieval;
- an authenticated workspace for campaigns, ad groups, integrated metrics, filters, CSV export, and operation history;
- controlled manual pause and simulation mode; and
- protected backend endpoints to create, enable, or disable campaigns, ad groups, and ads, without a complete creation interface.
Not currently available in the interface
The current product does not provide public sign-up, multi-company client management, client data isolation, a creative upload library, visual audience, pixel or catalog management, or a visual campaign creation/copy assistant. Dashboard reports depend on the configured metrics integration; the current code does not directly implement TikTok's Reporting endpoint.
Data and security
The application may process advertising account and object IDs, configuration and status data, integrated metrics, OAuth tokens, and technical logs. Tokens and secrets remain server-side in environment variables or encrypted storage and are not exposed to the browser. Operations require an administrator session, request-forgery protections, and an advertiser account associated with a recorded authorization.
Permissions
The application should request only categories needed for advertiser authentication and for reading accounts, campaigns, ad groups, and ads. Mutation access should be requested only if controlled pause and management are included in the submitted use case. Business Center, identity, pixel, and catalog access should be included only when demonstrated and required. Audience, creative-upload, and Reporting permissions should not be requested solely for planned modules.
OAuth and revocation
Expected callback for the official domain: https://smartwayportal.com/oauth/callback/. It must be registered exactly, including HTTPS and the trailing slash. Account holders may deny or revoke permissions through provider controls. Platform requests may be sent to contact@smartwayportal.com.
Documents
Privacy Policy · Terms of Use · Política de Privacidade · Termos de Uso