Connecting your TikTok account
What the login screen asks for, what BRoller does with it, and how to take it back.
How the connection works
Press Connect TikTok in BRoller and you are sent to TikTok's own login page. You sign in there and approve a list of permissions there. BRoller never sees your TikTok password and never asks for it. When you approve, TikTok hands BRoller a token that represents that approval and nothing more.
The token is stored in a cookie that the browser cannot read from JavaScript, marked Secure and SameSite. It is sent only to BRoller's own server, only when BRoller needs to talk to TikTok on your behalf.
What each permission is for
| Permission | What BRoller does with it |
|---|---|
user.info.basic | Identifies which account you connected so BRoller can show it and avoid sending a post to the wrong place. |
user.info.profile | Shows your display name, avatar and bio in the app, so you can confirm the account before anything is sent. |
user.info.stats | Reads follower, following, like and video counts so BRoller can chart them over time. |
video.list | Lists your own public posts with their view, like, comment and share counts. |
video.upload | Places a finished deck into your TikTok drafts. It cannot publish anything. |
What BRoller cannot do
- It cannot publish a post. Everything arrives as a draft that you publish from the TikTok app.
- It cannot read your For You feed, your following feed, or anyone else's account.
- It cannot read your direct messages, your private videos or your drafts.
- It cannot change your profile, follow accounts, comment, or like anything.
Disconnecting
Two ways, either is enough:
- In BRoller, open the account panel and press Disconnect. The stored token is deleted from BRoller's server and the cookie is cleared from your browser.
- In TikTok, go to Settings, then Security and permissions, then Manage app permissions, and remove BRoller. The token stops working immediately.
After disconnecting, any decks you already built stay in BRoller. The account statistics BRoller had already recorded are deleted along with the connection.
Changed your mind about a permission rather than the whole connection? TikTok grants permissions as one set, so the way to narrow it is to disconnect and reconnect. BRoller degrades gracefully: if a permission is missing, the feature that needs it is disabled rather than failing.
If the connection breaks
TikTok tokens expire. When one does, BRoller shows a Reconnect prompt instead of stale numbers. Reconnecting takes the same route as the first time and does not affect your decks. See when a send fails for the other cases.