Agent skill

Tiktok API

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling…

MITAuto-check passedBackend & APIs

Install Tiktok API

skills CLI
$ npx skills add ericrisco/rsc-harness --skill tiktok-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness tiktok-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tiktok-api .claude/skills/tiktok-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tiktok-api
GitHub stars
156
Token cost
~4.8k tokens
SKILL.md length
1,566 words
Files
7 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling…

  • Works in 6 steps: One-time setup (do this before any code) → Get an authed client and keep the token… → Publish a video (init → transfer → poll) → …
  • Connecting a real TikTok account to code via the Content Posting
  • SKILL.md covers When to use / When NOT, 1. One-time setup (do this…, 2. Get an authed client and… and 3. Publish a video (init →…, plus 5 more sections
  • Runs Shell scripts from its folder; reaches open.tiktokapis.com and tiktok.com; needs TIKTOK_CLIENT_KEY and TIKTOK_CLIENT_SECRET

What it does

Tiktok API is an agent skill from ericrisco/rsc-harness. Use when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling views, watch time and impression sources, then logging that performance into the wiki as a dated feedback record. Covers short-lived tokens breaking a cron, unverified pull-from-URL ownership, and rate limits. NOT what to post or how to package it (that is shortform-strategy and shortform-packaging).

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/metrics-and-publish.md`).

It sits in Backend & APIs, covering Rate limiting, Scheduled and recurring tasks and OAuth and OpenID Connect. It works with TikTok. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Connecting a real TikTok account to code via the Content Posting
  • Display and Business Account APIs — OAuth
  • Chunked video publish with status polling
  • Watch time and impression sources

Example prompts

  • “/tiktok-api”

Requirements

  • Python 3
  • A Bash shell
  • A credential in TIKTOK_CLIENT_KEY
  • A credential in TIKTOK_CLIENT_SECRET

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. One-time setup (do this before any code)
  2. Get an authed client and keep the token alive
  3. Publish a video (init → transfer → poll)
  4. Pull performance (two APIs, one rule)
  5. Ingest into the wiki — the actual deliverable
  6. Rate & failure math

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • open.tiktokapis.com
    • tiktok.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TIKTOK_CLIENT_KEY
    • TIKTOK_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tiktok API loads about 4.8k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 1,566 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,566 words, ~4,800 tokens.

Download SKILL.mdSave it as .claude/skills/tiktok-api/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
tiktok-api
description
Use when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling views, watch time and impression sources, then logging that performance into the wiki as a dated feedback record. Covers short-lived tokens breaking a cron, unverified pull-from-URL ownership, and rate limits. NOT what to post or how to package it (that is `shortform-strategy` and `shortform-packaging`).
tags
tiktok, content-posting-api, tiktok-display-api, tiktok-business-api, oauth2, chunked-upload, video-publish, watch-time, completion-rate, shortform-feedback-log
recommends
shortform-strategy, shortform-packaging, shortform-ideation, shortform-editing, social-publisher, instagram-api, youtube-api, api-connector-builder…
origin
risco

TikTok API — Transport + Ingestion for a Real Account

You own the wire: authenticate to a TikTok account, publish video, pull the numbers, and write those numbers into the wiki as a durable feedback log. You do not decide what to make, when to post it, or how to caption it — that is the shortform strategy/packaging family. Deliver clean transport and a queryable log; let the siblings interpret.

TikTok splits across three separate APIs, and a real account touches all three:

  • Content Posting API — https://open.tiktokapis.com/v2/post/publish/... — the write side: init a publish, transfer the file, poll status. Audit-gated.
  • Display API — https://open.tiktokapis.com/v2/video/... — the cheap read side: your own profile and basic per-video counters (view_count, like_count, comment_count, share_count).
  • TikTok API for Business — the rich read side: watch time, completion, impression sources. Enabled through a separate business portal, not the standard developer app.

Auth is user OAuth v2 via Login Kit, never a service token. A human owns the account; you act on their behalf with a refresh token. There is no official TikTok SDK — you call the REST endpoints directly with any HTTP client. Treat the access token as a short-lived, refreshable credential object, never a hardcoded literal.

When to use / When NOT

Use when:

  • Wiring a script or agent to publish to an account: Direct Post or upload-to-draft via /v2/post/publish/video/init/ (or /inbox/ for a draft), then FILE_UPLOAD chunked PUT or PULL_FROM_URL, then poll /v2/post/publish/status/fetch/.
  • Pulling an account's own video stats: counters via Display POST /v2/video/query/ (or /v2/video/list/); watch-time / completion / impression-source via the Business Account API.
  • Building the recurring "fetch performance → write to 02-DOCS/wiki/shortform/" loop that turns API responses into an account feedback log siblings can read.
  • Debugging TikTok-specific failures: scope_not_authorized, url_ownership_unverified, rate_limit_exceeded (6 req/min), 24-hour access-token expiry, audit/video.publish not approved, unaudited-app private-only posting.

Do NOT use when (route to the sibling that owns it):

You actually wantGo to
What to post / cadence / niche / hook strategyshortform-strategy (catalog id)
Clip ideas, hooks, a topic backlogshortform-ideation (catalog id)
Caption / cover / title packaging, A/B framingshortform-packaging (catalog id)
Cut/caption/render the actual clip fileshortform-editing (catalog id)
Render a video file programmatically../remotion-video/SKILL.md
Post one asset to TikTok + IG + YouTube at once../social-publisher/SKILL.md
Instagram's Graph / Content Publishing API../instagram-api/SKILL.md
YouTube's two APIs (same family, other platform)../youtube-api/SKILL.md
Wrap an arbitrary REST provider with OAuth + retriesapi-connector-builder (catalog id)
Chain publish → Notion row → Slack across toolsautomation-flows (catalog id)

One line: this skill authenticates, calls, and ingests TikTok's Content Posting + Display + Business APIs into the wiki. What to post and how to package it belong to the shortform-strategy / shortform-ideation / shortform-packaging siblings; multi-network posting belongs to social-publisher.

1. One-time setup (do this before any code)

A checklist, because each missing step produces a distinct, confusing failure later:

  1. Register a TikTok developer app in the developer portal.
  2. Add the products you need: Login Kit (OAuth), Content Posting API (publish), Display API (read counts). Insights live in the separate TikTok for Business portal — enable that account access too if you need watch time/completion.
  3. Set an exact redirect URI for the OAuth flow.
  4. Submit the app for audit before posting public content. An unaudited app can only post privately (SELF_ONLY) and only to a limited set of test users. This is the #1 "works on my machine, breaks in prod" surprise — see rule below.
  5. If you publish by URL (PULL_FROM_URL), verify the domain / URL-prefix in the portal (DNS TXT or URL-prefix), or every init returns url_ownership_unverified.

The three gates are independent. Do not assume one approval covers everything:

text
Bad:  "My app is approved, so publish + insights both work."
Good: Content Posting *audit* gates public publish;
      Display *scope* (video.list) gates own-video counts;
      Business *portal* access gates watch time / completion / impression sources.
      Three separate gates — check each.

Scope table — request only what the job needs:

ScopeGrantsUse for
video.publishDirect Post to the public feed/post/publish/video/init/ (audit-gated)
video.uploadUpload to drafts/inbox for the user to finish/post/publish/inbox/video/init/
video.listRead your own videos + basic countersDisplay POST /v2/video/query/
user.info.basicRead profile (open_id, display name, avatar)POST /v2/user/info/

Full app-registration + product-enable walkthrough, the audit gate, and scope_not_authorized troubleshooting live in references/oauth-setup.md.

2. Get an authed client and keep the token alive

OAuth v2: send the user to https://www.tiktok.com/v2/auth/authorize/, receive a code at your redirect URI, exchange it at https://open.tiktokapis.com/v2/oauth/token/, and store the refresh token.

The lifecycle is the load-bearing fact: access token expires in 24 hours (expires_in: 86400); refresh token lasts 365 days (refresh_expires_in: 31536000) and renews without user re-consent. So a daily-pull cron MUST refresh the access token every run, and a long-idle account silently dies at the 365-day refresh boundary.

python
# python: raw REST, no official TikTok SDK. requests/httpx both fine.
import time, json, os, requests

TOKEN_URL = "https://open.tiktokapis.com/v2/oauth/token/"
STORE = "tiktok_token.json"   # gitignored — holds the rotating refresh_token

def load(): return json.load(open(STORE)) if os.path.exists(STORE) else {}
def save(t): t["obtained_at"] = int(time.time()); json.dump(t, open(STORE, "w"))

def access_token():
    t = load()
    fresh = t.get("access_token") and time.time() < t.get("obtained_at", 0) + t["expires_in"] - 60
    if fresh:
        return t["access_token"]
    r = requests.post(TOKEN_URL, data={                 # refresh every run, 24h expiry
        "client_key": os.environ["TIKTOK_CLIENT_KEY"],
        "client_secret": os.environ["TIKTOK_CLIENT_SECRET"],
        "grant_type": "refresh_token",
        "refresh_token": t["refresh_token"],            # 365-day lifetime; rotates
    }, headers={"Content-Type": "application/x-www-form-urlencoded"})
    r.raise_for_status()
    new = r.json()
    save(new)                                           # persist the NEW refresh_token
    return new["access_token"]
javascript
// node: built-in fetch, no SDK.
import fs from "node:fs";
const STORE = "tiktok_token.json";

async function accessToken() {
  const t = JSON.parse(fs.readFileSync(STORE, "utf8"));
  if (t.access_token && Date.now() / 1000 < t.obtained_at + t.expires_in - 60) return t.access_token;
  const r = await fetch("https://open.tiktokapis.com/v2/oauth/token/", {
    method: "POST",
    headers: { "Content-Type": "application/x-www-form-urlencoded" },
    body: new URLSearchParams({
      client_key: process.env.TIKTOK_CLIENT_KEY,
      client_secret: process.env.TIKTOK_CLIENT_SECRET,
      grant_type: "refresh_token",
      refresh_token: t.refresh_token,
    }),
  });
  const n = await r.json();
  n.obtained_at = Math.floor(Date.now() / 1000);
  fs.writeFileSync(STORE, JSON.stringify(n));          // persist rotated refresh_token
  return n.access_token;
}

Rule: persist the refresh token and re-read it each run, never a bare access_token. A hardcoded access_token=... literal is a guaranteed failure within 24 hours — and is exactly what verify.sh flags.

Full token-exchange flow (authorize URL params, PKCE, code exchange) is in references/oauth-setup.md.

3. Publish a video (init → transfer → poll)

Publishing is always three steps: init the publish, transfer the bytes, poll until processing finishes (it is async). Pick the transfer mode first:

SituationSourceEndpoint
File is local / in your controlFILE_UPLOAD/post/publish/video/init/
File is at a verified HTTPS URLPULL_FROM_URL/post/publish/video/init/
Should land as a draft the user finalizesFILE_UPLOAD/post/publish/inbox/video/init/

Init (FILE_UPLOAD) — returns publish_id and an upload_url:

python
import math, requests

CHUNK = 10 * 1024 * 1024                      # 10 MB, inside the 5–64 MB window
size = os.path.getsize("clip.mp4")
chunk_count = 1 if size < 5 * 1024 * 1024 else math.ceil(size / CHUNK)

init = requests.post(
    "https://open.tiktokapis.com/v2/post/publish/video/init/",
    headers={"Authorization": f"Bearer {access_token()}",
             "Content-Type": "application/json; charset=UTF-8"},
    json={
        "post_info": {"title": "caption #fyp", "privacy_level": "SELF_ONLY"},  # public needs audit
        "source_info": {
            "source": "FILE_UPLOAD",
            "video_size": size,
            "chunk_size": CHUNK if size >= 5 * 1024 * 1024 else size,
            "total_chunk_count": chunk_count,
        },
    }).json()
publish_id = init["data"]["publish_id"]
upload_url = init["data"]["upload_url"]

Transfer — PUT chunks sequentially to upload_url with a Content-Range header. Chunk min 5 MB, max 64 MB (final chunk up to 128 MB), 1–1000 chunks; a file under 5 MB is one chunk equal to the file size. Each PUT returns 206 (more to send) or 201 (last chunk accepted):

python
with open("clip.mp4", "rb") as f:
    for i in range(chunk_count):
        first = i * CHUNK
        data = f.read(CHUNK)
        last = first + len(data) - 1
        r = requests.put(upload_url, data=data, headers={
            "Content-Type": "video/mp4",
            "Content-Range": f"bytes {first}-{last}/{size}",  # exact byte span
        })
        assert r.status_code in (206, 201), r.text     # 206 = continue, 201 = done

Poll — TikTok processes asynchronously; check status until PUBLISH_COMPLETE. Respect the cap below — do not tight-loop:

python
import time
while True:
    s = requests.post(
        "https://open.tiktokapis.com/v2/post/publish/status/fetch/",
        headers={"Authorization": f"Bearer {access_token()}",
                 "Content-Type": "application/json; charset=UTF-8"},
        json={"publish_id": publish_id}).json()
    status = s["data"]["status"]
    if status in ("PUBLISH_COMPLETE", "FAILED"):
        break
    time.sleep(10)                                      # 6/min cap — sleep, never spin

Rate limit: 6 requests/minute per user access token → rate_limit_exceeded. Throttle init/status calls and back off; a tight status-poll loop blows the budget in seconds.

PULL_FROM_URL requires the domain/URL-prefix to be verified in the portal (HTTPS only, no redirects, 1-hour download timeout) or init returns url_ownership_unverified. Full PULL_FROM_URL init body and verification steps are in references/metrics-and-publish.md.

Show full SKILL.md (609 more words)Show less

4. Pull performance (two APIs, one rule)

The load-bearing distinction: Display gives you counters; only the Business API gives you watch time, completion, and traffic.

python
# (a) Display API — basic counters only. scope video.list, up to 20 ids/request.
counts = requests.post(
    "https://open.tiktokapis.com/v2/video/query/",
    params={"fields": "id,title,view_count,like_count,comment_count,share_count,duration,create_time"},
    headers={"Authorization": f"Bearer {access_token()}",
             "Content-Type": "application/json"},
    json={"filters": {"video_ids": ["<id1>", "<id2>"]}}).json()
# returns: view_count, like_count, comment_count, share_count, duration, title, create_time
python
# (b) Business Account API — the real engagement signal.
# Returns the metrics Display CANNOT: average_time_watched, total_time_watched,
# full_video_watched_rate (completion), impression_sources (FYP / Following / profile /
# search), audience_countries. (Endpoint shape in references/metrics-and-publish.md.)
text
Bad:  expect average_time_watched / full_video_watched_rate from /v2/video/query/
Good: counters from Display /v2/video/query/;
      watch time + completion + impression_sources from the Business Account API.

Caveat: Business insight metrics lag 24–48h and can differ from the in-app numbers. Treat a fresh pull as provisional — the wiki log (next section) is where you watch them settle. Full metric catalog split by API is in references/metrics-and-publish.md.

5. Ingest into the wiki — the actual deliverable

A pull that prints to stdout and vanishes is wasted. Every pull appends a dated entry under 02-DOCS/wiki/shortform/, platform-namespaced, so the account's numbers become queryable history the strategy/packaging siblings can read.

text
02-DOCS/wiki/shortform/
  index.md                       # rolling pointer to latest snapshot + open questions
  tiktok-account-2026-06-02.md   # dated account snapshot (one per pull)
  videos/tiktok-<video_id>.md    # per-video running log, newest entry on top

Filenames carry the tiktok- prefix because the same shortform/ wiki may also hold Instagram and YouTube pulls — namespacing keeps platforms from colliding.

Per-pull entry template. The frontmatter is OKF v0.1 conformant — a non-empty type is the only hard requirement; title/tags/timestamp are the recommended OKF surface; the domain date/range/account/platform/source keys the siblings parse are preserved additively (OKF tolerates extra keys). date is the reporting day; timestamp is the ISO 8601 write moment:

markdown
---
type: shortform-metrics
title: TikTok account snapshot — 2026-06-02
tags: [tiktok, metrics, snapshot]
timestamp: 2026-06-02T09:00:00Z
date: 2026-06-02
range: 2026-05-26..2026-06-01
account: <open_id>
platform: tiktok
source: display-api + business-account-api
---
## KPIs
views: 52,140 | likes: 3,902 | comments: 211 | shares: 488

## Watch
full_video_watched_rate: 28.4% | avg_time_watched: 6.1s | total_time_watched: 88h

## Impression sources (top 3)
For You 71% · Personal profile 14% · Search 7%

## What changed since last pull
completion +3.1pts after the tighter cold-open; FYP share up 5pts.

Rule: append, never overwrite. The feedback log is the value — overwriting yesterday's snapshot destroys the trend the siblings need, and erases the 24–48h settling you only see across pulls. The per-video log (videos/tiktok-<id>.md) is an OKF append-log: write its frontmatter header once, prepend each new dated block newest-first, never edit a past block. index.md is the OKF reserved file — no frontmatter, standard markdown links only. Exact file tree, frontmatter, naming, and how siblings read the log: references/wiki-schema.md.

6. Rate & failure math

The publish token is capped at 6 requests/minute. Wrap publish/status calls in a token-bucket or backoff-with-jitter helper, and refresh the access token (24h expiry) before each cron run.

Error → cause map:

SymptomCauseFix
scope_not_authorizedScope missing or not approved for the appAdd the scope; re-consent; check app approval
Only SELF_ONLY posts workApp not auditedSubmit for audit; use test users until approved
url_ownership_unverified on initPULL_FROM_URL domain not verifiedVerify domain/URL-prefix (DNS TXT) in the portal
rate_limit_exceeded>6 req/min on the user tokenThrottle + backoff; stop tight-looping the poll
401 / access_token_invalid mid-cron24h access token expiredRefresh before each run; persist refresh_token
Empty watch time / completionWrong API or <24–48h since postUse the Business API, not Display; wait for lag
Refresh fails after long idle365-day refresh token expiredRe-run the OAuth consent flow

Anti-patterns

Anti-patternWhy it bitesDo instead
Commit client_secret / a token file holding refresh_tokenLeaks full account control to anyone with repo readGitignore it; load from env/secret store
Hardcode a 24h access_token literalDead within a day; breaks every cronPersist the refresh token; refresh each run
Tight-loop the status pollBlows the 6/min cap → rate_limit_exceededSleep ~10s between polls; back off on 429
Expect watch time from Display video/queryThat field does not exist thereCounts from Display, watch time from Business
Treat an unaudited app as productionOnly SELF_ONLY posts work for real usersSubmit for audit before public posting
PULL_FROM_URL without domain verificationEvery init returns url_ownership_unverifiedVerify domain/URL-prefix first, HTTPS, no redirects
Assume one approval covers publish + insightsThree independent gatesPosting audit + Display scope + Business portal
Overwrite yesterday's wiki snapshotDestroys the trend + the 24–48h settlingAppend a new dated entry every pull

Cross-references

  • ../social-publisher/SKILL.md — when the asset goes to many networks, not just TikTok.
  • ../instagram-api/SKILL.md — same family pattern, Instagram's Graph/Content Publishing API.
  • ../youtube-api/SKILL.md — same transport+ingestion shape, YouTube's two APIs.
  • ../remotion-video/SKILL.md — produce the clip file this skill only uploads.
  • shortform-strategy, shortform-ideation, shortform-packaging, shortform-editing (catalog ids) — what the numbers mean, what to make, and how to package/edit it.
  • api-connector-builder, automation-flows, knowledge-ops (catalog ids) — generic connector wrapping, cross-tool chaining, and wiki conventions.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/tiktok-api of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/metrics-and-publish.md
  • references/oauth-setup.md
  • references/wiki-schema.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Tiktok API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tiktok API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tiktok API this skillericrisco/rsc-harness156—~4.8kAutomated safety check: PassMIT
X Bookmarkssharbelxyz/x-bookmarks289—~2kAutomated safety check: NotesNone
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
Passport Developmenttrypostit/trypost676—~1.9kAutomated safety check: PassMIT
Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~3.2kAutomated safety check: PassMIT
Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~4kAutomated safety check: PassMIT

Similar skills

  • X Bookmarks

    sharbelxyz/x-bookmarks

    Fetch, summarize, and manage X/Twitter bookmarks via bird CLI or X API v2.

    289 GitHub stars~2k tokensUpdated 7 mo ago
    Backend & APIsAuto-check: notes
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    676 GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Frappe Core API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.

    187 GitHub starsUsed in 1 repo~3.2k tokens
    Backend & APIsAuto-check passed
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    187 GitHub starsUsed in 1 repo~4k tokens
    Backend & APIsAuto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Tiktok API

What does Tiktok API do?

A skill your agent uses when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling…. Tiktok API is an agent skill from ericrisco/rsc-harness. Use when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling views, watch time and impression sources, then logging that performance into the wiki as a dated feedback record.

When should I use Tiktok API?

Tiktok API fits situations like: connecting a real TikTok account to code via the Content Posting; display and Business Account APIs — OAuth; chunked video publish with status polling; watch time and impression sources.

How do I install Tiktok API in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill tiktok-api -a claude-code`. Or copy the skill folder (skills/tiktok-api in ericrisco/rsc-harness) into .claude/skills/tiktok-api in your project. Claude Code loads it when a task matches its description.

How do I install Tiktok API in Codex?

Run `npx skills add ericrisco/rsc-harness --skill tiktok-api -a codex`. Or copy the skill folder (skills/tiktok-api in ericrisco/rsc-harness) into .agents/skills/tiktok-api in your project. Codex loads it when a task matches its description.

Can I use Tiktok API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill tiktok-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tiktok-api, .gemini/skills/tiktok-api, .github/skills/tiktok-api and .opencode/skills/tiktok-api in your project.

What does Tiktok API need to run?

Going by SKILL.md and its folder, Tiktok API needs a shell for the scripts in its folder and credentials named TIKTOK_CLIENT_KEY and TIKTOK_CLIENT_SECRET. Our summary lists: Python 3; A Bash shell; A credential in TIKTOK_CLIENT_KEY; A credential in TIKTOK_CLIENT_SECRET.

Does Tiktok API access the network?

SKILL.md names 2 domains. In commands or code: open.tiktokapis.com and tiktok.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Tiktok API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tiktok API use?

Tiktok API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tiktok API use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.

What are the alternatives to Tiktok API?

Skills that share tags, products or a category with Tiktok API: X Bookmarks (sharbelxyz/x-bookmarks, 289 stars), Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Passport Development (trypostit/trypost, 676 stars) and Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tiktok API?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.