TikTok MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| TIKTOK_ACCOUNTS | No | Optional. Comma-separated list of account name:refresh_token pairs for multiple accounts, e.g. personal:refresh_token_one,brand:refresh_token_two. | |
| TIKTOK_AUDIT_LOG | No | Optional. Path to a file where each attempted write is logged as one JSON line. | |
| TIKTOK_READ_ONLY | No | Optional. Set to 1 to remove all write tools from the server. | |
| TIKTOK_CLIENT_KEY | Yes | Your TikTok app's client key. | |
| TIKTOK_HTTP_TOKEN | No | Optional. Token required when running over HTTP to allow connections from hosts other than 127.0.0.1. | |
| TIKTOK_CLIENT_SECRET | Yes | Your TikTok app's client secret. | |
| TIKTOK_REFRESH_TOKEN | Yes | The refresh token obtained by running `npx -y @thenavidm/tiktok-mcp auth`. Valid for about 365 days. | |
| TIKTOK_ALLOW_DESTRUCTIVE | No | Optional. Set to 0 to keep drafts but remove publishing tools. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_accountsA | Every TikTok account this server can act as, with the name to pass as |
| get_profileA | Profile and audience for a connected account: username, display name, bio, verified flag, follower and following counts, total likes across all videos, and how many videos are public. This is the only account it can see; TikTok's official API cannot read anybody else's profile. |
| revoke_accessA | Hands the token back to TikTok and removes your app from the account's connected-apps list. The refresh token in your config stops working immediately and only re-running |
| list_videosA | Your public TikTok posts, newest first, with views, likes, comments, shares and a computed engagement rate. Pages past TikTok's 20-per-page limit automatically. Only public posts appear: TikTok's API cannot see private or draft videos. |
| get_videosA | Fetch up to 20 of your videos by id, with full stats. Also the way to refresh a cover_image_url: those links expire 6 hours after they are issued, so a cover that 404s needs this call rather than a cached URL. |
| top_videosA | Your best posts, ranked. TikTok has no ranked endpoint, so this pages recent videos and sorts them locally: |
| search_my_videosA | Find your posts whose title or description matches a query. TikTok has no search over your own library, so this pages recent videos and filters locally. A miss means it is not in the last |
| stats_summaryA | Aggregate stats over your recent posts: total and mean views, the median and 90th percentile, mean engagement rate, and how many days apart you post. Reach for this instead of listing videos and adding them up, and read the median rather than the mean: one viral post drags a mean far away from what a typical post of yours actually does. |
| get_creator_infoA | What this account is allowed to post: which privacy levels are available, whether comments, duet or stitch are switched off, and the longest video it may upload. Call this before post_video or post_photos. TikTok requires the privacy level to come from the list this returns, and it changes when the creator flips their account private. |
| post_videoA | Publish a video straight to the account from a public URL. Returns a publish_id; poll get_post_status with it, because the call returns as soon as TikTok accepts the job, long before the post is live. While your app is unaudited every post lands private no matter which privacy_level you pass. |
| post_photosA | Publish a photo carousel of up to 35 images from public URLs. Returns a publish_id; poll get_post_status with it. Same domain-verification and audit rules as post_video. |
| send_video_to_draftsA | Send a video to the account's TikTok inbox instead of publishing it. The creator gets a notification and finishes the post in the app, so nothing goes public without them. Needs only video.upload, which makes this the path that works before your app passes the Content Posting audit. TikTok allows at most 5 unpublished drafts from the API in any 24 hours. |
| send_photos_to_draftsA | Send photos to the account's TikTok inbox for the creator to finish in the app. Needs only video.upload. The creator's TikTok app must be version 31.8 or newer or TikTok rejects it. |
| get_post_statusA | Track a post created by post_video, post_photos or either drafts tool. Statuses: PROCESSING_DOWNLOAD while TikTok fetches the file, SEND_TO_USER_INBOX for a draft that arrived, PUBLISH_COMPLETE when it is posted, FAILED with a fail_reason. A public post only reports its post_id after moderation clears it, which is usually a minute but can be hours, so an empty post_id on a PUBLISH_COMPLETE is normal rather than an error. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/navidmoazzez/tiktok-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server