Ultimate Insulation — The Home Doctors
Atlas HQ by Ultimate Insulation

The TikTok integration

Atlas HQ is the marketing and social media management platform built and operated by Ultimate Insulation, an insulation and building-performance contractor. This page explains exactly how Atlas HQ connects to TikTok, what it is permitted to do there, and the controls that sit around publishing.

In one sentence

Authorized Ultimate Insulation staff use Atlas HQ to schedule and publish the company’s own marketing videos to the company’s own TikTok business account. Atlas HQ does not post on behalf of anyone else, does not read other people’s content, and is not offered to the public as a standalone service.

1. Connecting the account (Login Kit)

An Ultimate Insulation office administrator opens the integrations screen inside Atlas HQ and chooses to connect TikTok. That starts a standard TikTok Login Kit authorization: the administrator is sent to TikTok, signs in with the company’s own credentials, and reviews the permissions TikTok presents before approving them.

TikTok returns the authorization to our registered redirect URI on this same domain. We exchange it server-side for an access token and a refresh token, which are stored as encrypted server secrets. The request is protected by a single-use, server-held state value, so an authorization cannot be replayed. Nobody can connect an account without first signing in to Atlas HQ as office staff.

Once connected, the same integrations screen reads the account’s basic profile back from TikTok and displays its display name, avatar, and account identifiers, so an administrator can confirm which TikTok account is linked.

2. The permissions we request, and why

Each permission below maps to a specific, visible feature described on this page. There is no permission here without a feature behind it that a person can watch working:

user.info.basic
Reads the connected account's display name, avatar, and account identifiers. These are shown on our integrations screen so an administrator can see at a glance which TikTok account Atlas HQ is connected to.
video.upload
Upload to TikTok — sends a video to the connected account's TikTok inbox for further editing. Nothing is posted: the creator opens the inbox notification and writes the caption, chooses the audience, and publishes inside the TikTok app.
video.publish
Direct Post — publishes a video to the connected account after the staff member has set the title, privacy level, and interaction settings on our post screen and given explicit consent.

3. How a video reaches TikTok

Every video starts the same way, and then the staff member chooses one of two clearly separated actions.

  1. A crew member films a job — an attic air-seal, a crawl-space encapsulation, a blower-door test — and the video is added to the company’s content library inside Atlas HQ.
  2. Office staff pick a video that has been marked as customer-visible. Internal-only footage cannot be selected at all.
  3. Atlas HQ shows a preview of the video and the connected TikTok account it would go to, then offers the two actions below. They are separate buttons on separate screens — one publishes, the other does not, and neither can be reached by accident from the other.
Post to TikTok
video.publish · Direct Post

Atlas HQ queries TikTok for the account’s current posting rules. The staff member writes the caption, chooses the privacy level, sets comment, duet, and stitch preferences, declares any commercial content, and acknowledges the required TikTok policies. Only then is the post sent, and Atlas HQ tracks the publish status until TikTok reports it complete.

Send to TikTok inbox
video.upload · Upload to TikTok

Atlas HQ sends the video and stops. Nothing is posted, and no caption, audience, or interaction setting is sent — the API call carries none. A notification arrives in the creator’s TikTok inbox, and they open it to finish editing, choose the posting settings, and publish inside the TikTok app.

In both cases the video is pulled by TikTok over HTTPS from a domain we own and have verified with TikTok, and the temporary copy is removed once TikTok has finished with it.

4. Safeguards

The posting controls below apply to Direct Post, where Atlas HQ is the one publishing. The inbox flow needs none of them, because it decides nothing: TikTok’s own composer collects the caption, the audience, and the music confirmation when the creator opens the draft. The last two apply to both.

Creator info is queried live, never cached

Every time the post screen opens, and again at submit, Atlas HQ queries TikTok's creator_info endpoint. The privacy options, comment/duet/stitch availability, and maximum video duration shown are the ones TikTok returned for that account at that moment — never a remembered copy.

Privacy level has no default

The privacy selection starts empty and publishing is blocked until a staff member deliberately chooses one. Only the options TikTok reports as available for that account are offered, so an unavailable choice can never be selected.

Commercial content disclosure

The disclosure toggle defaults to off. When it is turned on, the staff member must say whether the content promotes their own brand or is a paid partnership, and branded content cannot be set to a private audience.

Music Usage Confirmation

Before anything is sent, the person publishing must acknowledge TikTok's Music Usage Confirmation — and, for branded content, the Branded Content Policy. Both are linked directly from the post screen.

No silent retries, no watermarks

We never modify the video: the bytes posted are the bytes our crew filmed. If a post's outcome is ever uncertain, nothing is retried automatically — the operator is told to check TikTok first, so a video can't be posted twice.

Only authorized staff can publish

Publishing is limited to signed-in Ultimate Insulation office staff. Access tokens are held server-side as encrypted secrets, are never exposed to the browser, and are deleted when the account is disconnected.

5. Data we receive from TikTok, and what we do with it

From the connected account we receive its display name, avatar, and account identifiers; its username and current posting settings; and the publish status of videos we send. We use these only to show which account is connected, to render the post screen accurately, and to report whether a post succeeded.

We do not collect TikTok users’ personal data, do not read other accounts’ content, do not build advertising profiles, and do not sell any data. Access can be revoked at any time from TikTok’s own settings, and disconnecting the account deletes the stored tokens. Full detail is in our Privacy Policy and Terms of Service.

Questions about this integration

Email info@homedr.co or visit our contact page.

TikTok Integration · Atlas HQ by Ultimate Insulation