- SignalDesk2 hr ago
Original Summary
I've spent the last few weeks getting a product approved to publish videos to social platforms on behalf of users. The docs are scattered and some are out of date, so here's what each one actually involved. Hopefully it saves someone a few weeks. YouTube (Google) - There are two separate reviews, and most people only know about one. OAuth app verification (Google Auth Platform → Verification Center). You need a verified domain in Search Console, a privacy policy with a specific "Google user data / Limited Use" section, a link to the YouTube Terms in your own terms, and a demo video showing the full OAuth flow with the address bar visible, the consent screen, and each scope being used. YouTube API Services audit, a separate form. The docs say uploads from unaudited projects are locked to private. In my case uploads came out public even before the audit, so test it yourself before blocking on it. - The
youtube.uploadandyoutube.readonlyscopes are "sensitive", not "restricted", so no paid security assessment is needed. Adding a scope later (e.g. for comments) means another review of that scope. - Uploads have their own quota bucket (100/day by default), separate from the 10,000 units/day for other calls. TikTok - You start in a sandbox with separate keys and only test accounts. - The review checks your posting UI closely. You have to show the creator's account, can't preselect a privacy level, interactions (comments/duet/stitch) must be off by default, and there's a required consent line. Build that UI before you submit, not after. - Automatic posting with no per-post choices doesn't fit their rules well. Instagram / Facebook / Threads (Meta) - One Meta app can cover all three, and you can build and test everything in development mode with your own accounts. - Going live for real users needs business verification, which means a registered legal entity. If you're a sole founder without an LLC yet, that's your blocker, not the code. LinkedIn - Easy to start. Tokens expire after about 60 days, so plan a "reconnect" flow from day one. Pinterest - Starts with "Trial" access against a sandbox API, then you apply for standard access. Bluesky - No developer app or review. Users connect with an app password. The easiest one by far. X - I skipped it. Posting through the API costs real money per month at any meaningful volume. General lessons - Start the reviews early. The code took less time than the reviews will. - Record your demo videos carefully. Every reviewer wants to see the consent screen, the address bar, and each permission actually being used. - Keep the privacy policy specific: which permission, what it's used for, what you store, how to revoke. Vague policies get bounced. - Abstract each platform behind one internal interface. Each one handles tokens, media upload, and errors differently, and you'll be glad y- 情报分类:技术学习与提效
- 分类依据:内容涉及技术、AI、软件工具或工程实践
- 信息来源:Reddit · SaaS
- 发布时间:2026/10/4 03:50:40
- No replies yet