X Bookmarks
sharbelxyz/x-bookmarks
Fetch, summarize, and manage X/Twitter bookmarks via bird CLI or X API v2.
A skill your agent uses when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling…
$ npx skills add ericrisco/rsc-harness --skill tiktok-api -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness tiktok-api --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tiktok-api .claude/skills/tiktok-api && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tiktok-api" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tiktok-api into .claude/skills/tiktok-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tiktok-api", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/tiktok-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill tiktok-api -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness tiktok-api --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/tiktok-api .agents/skills/tiktok-api && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tiktok-api" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tiktok-api into .agents/skills/tiktok-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tiktok-api", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill tiktok-api -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness tiktok-api --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/tiktok-api .cursor/skills/tiktok-api && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tiktok-api" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tiktok-api into .cursor/skills/tiktok-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tiktok-api", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/tiktok-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill tiktok-api -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness tiktok-api --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/tiktok-api .gemini/skills/tiktok-api && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tiktok-api" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tiktok-api into .gemini/skills/tiktok-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tiktok-api", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness tiktok-apiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill tiktok-api -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/tiktok-api .github/skills/tiktok-api && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tiktok-api" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tiktok-api into .github/skills/tiktok-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tiktok-api", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill tiktok-api -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness tiktok-api --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/tiktok-api .opencode/skills/tiktok-api && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tiktok-api" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/tiktok-api into .opencode/skills/tiktok-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tiktok-api", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tiktok-apiA skill your agent uses when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling…
Tiktok API is an agent skill from ericrisco/rsc-harness. Use when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling views, watch time and impression sources, then logging that performance into the wiki as a dated feedback record. Covers short-lived tokens breaking a cron, unverified pull-from-URL ownership, and rate limits. NOT what to post or how to package it (that is shortform-strategy and shortform-packaging).
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/metrics-and-publish.md`).
It sits in Backend & APIs, covering Rate limiting, Scheduled and recurring tasks and OAuth and OpenID Connect. It works with TikTok. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
open.tiktokapis.comtiktok.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
TIKTOK_CLIENT_KEYTIKTOK_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tiktok API loads about 4.8k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 1,566 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,566 words, ~4,800 tokens.
.claude/skills/tiktok-api/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You own the wire: authenticate to a TikTok account, publish video, pull the numbers, and write those numbers into the wiki as a durable feedback log. You do not decide what to make, when to post it, or how to caption it — that is the shortform strategy/packaging family. Deliver clean transport and a queryable log; let the siblings interpret.
TikTok splits across three separate APIs, and a real account touches all three:
https://open.tiktokapis.com/v2/post/publish/... — the write side: init a publish, transfer the file, poll status. Audit-gated.https://open.tiktokapis.com/v2/video/... — the cheap read side: your own profile and basic per-video counters (view_count, like_count, comment_count, share_count).Auth is user OAuth v2 via Login Kit, never a service token. A human owns the account; you act on their behalf with a refresh token. There is no official TikTok SDK — you call the REST endpoints directly with any HTTP client. Treat the access token as a short-lived, refreshable credential object, never a hardcoded literal.
Use when:
/v2/post/publish/video/init/ (or /inbox/ for a draft), then FILE_UPLOAD chunked PUT or PULL_FROM_URL, then poll /v2/post/publish/status/fetch/.POST /v2/video/query/ (or /v2/video/list/); watch-time / completion / impression-source via the Business Account API.02-DOCS/wiki/shortform/" loop that turns API responses into an account feedback log siblings can read.scope_not_authorized, url_ownership_unverified, rate_limit_exceeded (6 req/min), 24-hour access-token expiry, audit/video.publish not approved, unaudited-app private-only posting.Do NOT use when (route to the sibling that owns it):
| You actually want | Go to |
|---|---|
| What to post / cadence / niche / hook strategy | shortform-strategy (catalog id) |
| Clip ideas, hooks, a topic backlog | shortform-ideation (catalog id) |
| Caption / cover / title packaging, A/B framing | shortform-packaging (catalog id) |
| Cut/caption/render the actual clip file | shortform-editing (catalog id) |
| Render a video file programmatically | ../remotion-video/SKILL.md |
| Post one asset to TikTok + IG + YouTube at once | ../social-publisher/SKILL.md |
| Instagram's Graph / Content Publishing API | ../instagram-api/SKILL.md |
| YouTube's two APIs (same family, other platform) | ../youtube-api/SKILL.md |
| Wrap an arbitrary REST provider with OAuth + retries | api-connector-builder (catalog id) |
| Chain publish → Notion row → Slack across tools | automation-flows (catalog id) |
One line: this skill authenticates, calls, and ingests TikTok's Content Posting + Display + Business APIs into the wiki. What to post and how to package it belong to the shortform-strategy / shortform-ideation / shortform-packaging siblings; multi-network posting belongs to social-publisher.
A checklist, because each missing step produces a distinct, confusing failure later:
SELF_ONLY) and only to a limited set of test users. This is the #1 "works on my machine, breaks in prod" surprise — see rule below.PULL_FROM_URL), verify the domain / URL-prefix in the portal (DNS TXT or URL-prefix), or every init returns url_ownership_unverified.The three gates are independent. Do not assume one approval covers everything:
Bad: "My app is approved, so publish + insights both work."
Good: Content Posting *audit* gates public publish;
Display *scope* (video.list) gates own-video counts;
Business *portal* access gates watch time / completion / impression sources.
Three separate gates — check each.Scope table — request only what the job needs:
| Scope | Grants | Use for |
|---|---|---|
video.publish | Direct Post to the public feed | /post/publish/video/init/ (audit-gated) |
video.upload | Upload to drafts/inbox for the user to finish | /post/publish/inbox/video/init/ |
video.list | Read your own videos + basic counters | Display POST /v2/video/query/ |
user.info.basic | Read profile (open_id, display name, avatar) | POST /v2/user/info/ |
Full app-registration + product-enable walkthrough, the audit gate, and scope_not_authorized troubleshooting live in references/oauth-setup.md.
OAuth v2: send the user to https://www.tiktok.com/v2/auth/authorize/, receive a code at your redirect URI, exchange it at https://open.tiktokapis.com/v2/oauth/token/, and store the refresh token.
The lifecycle is the load-bearing fact: access token expires in 24 hours (expires_in: 86400); refresh token lasts 365 days (refresh_expires_in: 31536000) and renews without user re-consent. So a daily-pull cron MUST refresh the access token every run, and a long-idle account silently dies at the 365-day refresh boundary.
# python: raw REST, no official TikTok SDK. requests/httpx both fine.
import time, json, os, requests
TOKEN_URL = "https://open.tiktokapis.com/v2/oauth/token/"
STORE = "tiktok_token.json" # gitignored — holds the rotating refresh_token
def load(): return json.load(open(STORE)) if os.path.exists(STORE) else {}
def save(t): t["obtained_at"] = int(time.time()); json.dump(t, open(STORE, "w"))
def access_token():
t = load()
fresh = t.get("access_token") and time.time() < t.get("obtained_at", 0) + t["expires_in"] - 60
if fresh:
return t["access_token"]
r = requests.post(TOKEN_URL, data={ # refresh every run, 24h expiry
"client_key": os.environ["TIKTOK_CLIENT_KEY"],
"client_secret": os.environ["TIKTOK_CLIENT_SECRET"],
"grant_type": "refresh_token",
"refresh_token": t["refresh_token"], # 365-day lifetime; rotates
}, headers={"Content-Type": "application/x-www-form-urlencoded"})
r.raise_for_status()
new = r.json()
save(new) # persist the NEW refresh_token
return new["access_token"]// node: built-in fetch, no SDK.
import fs from "node:fs";
const STORE = "tiktok_token.json";
async function accessToken() {
const t = JSON.parse(fs.readFileSync(STORE, "utf8"));
if (t.access_token && Date.now() / 1000 < t.obtained_at + t.expires_in - 60) return t.access_token;
const r = await fetch("https://open.tiktokapis.com/v2/oauth/token/", {
method: "POST",
headers: { "Content-Type": "application/x-www-form-urlencoded" },
body: new URLSearchParams({
client_key: process.env.TIKTOK_CLIENT_KEY,
client_secret: process.env.TIKTOK_CLIENT_SECRET,
grant_type: "refresh_token",
refresh_token: t.refresh_token,
}),
});
const n = await r.json();
n.obtained_at = Math.floor(Date.now() / 1000);
fs.writeFileSync(STORE, JSON.stringify(n)); // persist rotated refresh_token
return n.access_token;
}Rule: persist the refresh token and re-read it each run, never a bare access_token. A hardcoded access_token=... literal is a guaranteed failure within 24 hours — and is exactly what verify.sh flags.
Full token-exchange flow (authorize URL params, PKCE, code exchange) is in references/oauth-setup.md.
Publishing is always three steps: init the publish, transfer the bytes, poll until processing finishes (it is async). Pick the transfer mode first:
| Situation | Source | Endpoint |
|---|---|---|
| File is local / in your control | FILE_UPLOAD | /post/publish/video/init/ |
| File is at a verified HTTPS URL | PULL_FROM_URL | /post/publish/video/init/ |
| Should land as a draft the user finalizes | FILE_UPLOAD | /post/publish/inbox/video/init/ |
Init (FILE_UPLOAD) — returns publish_id and an upload_url:
import math, requests
CHUNK = 10 * 1024 * 1024 # 10 MB, inside the 5–64 MB window
size = os.path.getsize("clip.mp4")
chunk_count = 1 if size < 5 * 1024 * 1024 else math.ceil(size / CHUNK)
init = requests.post(
"https://open.tiktokapis.com/v2/post/publish/video/init/",
headers={"Authorization": f"Bearer {access_token()}",
"Content-Type": "application/json; charset=UTF-8"},
json={
"post_info": {"title": "caption #fyp", "privacy_level": "SELF_ONLY"}, # public needs audit
"source_info": {
"source": "FILE_UPLOAD",
"video_size": size,
"chunk_size": CHUNK if size >= 5 * 1024 * 1024 else size,
"total_chunk_count": chunk_count,
},
}).json()
publish_id = init["data"]["publish_id"]
upload_url = init["data"]["upload_url"]Transfer — PUT chunks sequentially to upload_url with a Content-Range header. Chunk min 5 MB, max 64 MB (final chunk up to 128 MB), 1–1000 chunks; a file under 5 MB is one chunk equal to the file size. Each PUT returns 206 (more to send) or 201 (last chunk accepted):
with open("clip.mp4", "rb") as f:
for i in range(chunk_count):
first = i * CHUNK
data = f.read(CHUNK)
last = first + len(data) - 1
r = requests.put(upload_url, data=data, headers={
"Content-Type": "video/mp4",
"Content-Range": f"bytes {first}-{last}/{size}", # exact byte span
})
assert r.status_code in (206, 201), r.text # 206 = continue, 201 = donePoll — TikTok processes asynchronously; check status until PUBLISH_COMPLETE. Respect the cap below — do not tight-loop:
import time
while True:
s = requests.post(
"https://open.tiktokapis.com/v2/post/publish/status/fetch/",
headers={"Authorization": f"Bearer {access_token()}",
"Content-Type": "application/json; charset=UTF-8"},
json={"publish_id": publish_id}).json()
status = s["data"]["status"]
if status in ("PUBLISH_COMPLETE", "FAILED"):
break
time.sleep(10) # 6/min cap — sleep, never spinRate limit: 6 requests/minute per user access token → rate_limit_exceeded. Throttle init/status calls and back off; a tight status-poll loop blows the budget in seconds.
PULL_FROM_URL requires the domain/URL-prefix to be verified in the portal (HTTPS only, no redirects, 1-hour download timeout) or init returns url_ownership_unverified. Full PULL_FROM_URL init body and verification steps are in references/metrics-and-publish.md.
The load-bearing distinction: Display gives you counters; only the Business API gives you watch time, completion, and traffic.
# (a) Display API — basic counters only. scope video.list, up to 20 ids/request.
counts = requests.post(
"https://open.tiktokapis.com/v2/video/query/",
params={"fields": "id,title,view_count,like_count,comment_count,share_count,duration,create_time"},
headers={"Authorization": f"Bearer {access_token()}",
"Content-Type": "application/json"},
json={"filters": {"video_ids": ["<id1>", "<id2>"]}}).json()
# returns: view_count, like_count, comment_count, share_count, duration, title, create_time# (b) Business Account API — the real engagement signal.
# Returns the metrics Display CANNOT: average_time_watched, total_time_watched,
# full_video_watched_rate (completion), impression_sources (FYP / Following / profile /
# search), audience_countries. (Endpoint shape in references/metrics-and-publish.md.)Bad: expect average_time_watched / full_video_watched_rate from /v2/video/query/
Good: counters from Display /v2/video/query/;
watch time + completion + impression_sources from the Business Account API.Caveat: Business insight metrics lag 24–48h and can differ from the in-app numbers. Treat a fresh pull as provisional — the wiki log (next section) is where you watch them settle. Full metric catalog split by API is in references/metrics-and-publish.md.
A pull that prints to stdout and vanishes is wasted. Every pull appends a dated entry under 02-DOCS/wiki/shortform/, platform-namespaced, so the account's numbers become queryable history the strategy/packaging siblings can read.
02-DOCS/wiki/shortform/
index.md # rolling pointer to latest snapshot + open questions
tiktok-account-2026-06-02.md # dated account snapshot (one per pull)
videos/tiktok-<video_id>.md # per-video running log, newest entry on topFilenames carry the tiktok- prefix because the same shortform/ wiki may also hold Instagram and YouTube pulls — namespacing keeps platforms from colliding.
Per-pull entry template. The frontmatter is OKF v0.1 conformant — a non-empty type is the only hard requirement; title/tags/timestamp are the recommended OKF surface; the domain date/range/account/platform/source keys the siblings parse are preserved additively (OKF tolerates extra keys). date is the reporting day; timestamp is the ISO 8601 write moment:
---
type: shortform-metrics
title: TikTok account snapshot — 2026-06-02
tags: [tiktok, metrics, snapshot]
timestamp: 2026-06-02T09:00:00Z
date: 2026-06-02
range: 2026-05-26..2026-06-01
account: <open_id>
platform: tiktok
source: display-api + business-account-api
---
## KPIs
views: 52,140 | likes: 3,902 | comments: 211 | shares: 488
## Watch
full_video_watched_rate: 28.4% | avg_time_watched: 6.1s | total_time_watched: 88h
## Impression sources (top 3)
For You 71% · Personal profile 14% · Search 7%
## What changed since last pull
completion +3.1pts after the tighter cold-open; FYP share up 5pts.Rule: append, never overwrite. The feedback log is the value — overwriting yesterday's snapshot destroys the trend the siblings need, and erases the 24–48h settling you only see across pulls. The per-video log (videos/tiktok-<id>.md) is an OKF append-log: write its frontmatter header once, prepend each new dated block newest-first, never edit a past block. index.md is the OKF reserved file — no frontmatter, standard markdown links only. Exact file tree, frontmatter, naming, and how siblings read the log: references/wiki-schema.md.
The publish token is capped at 6 requests/minute. Wrap publish/status calls in a token-bucket or backoff-with-jitter helper, and refresh the access token (24h expiry) before each cron run.
Error → cause map:
| Symptom | Cause | Fix |
|---|---|---|
scope_not_authorized | Scope missing or not approved for the app | Add the scope; re-consent; check app approval |
Only SELF_ONLY posts work | App not audited | Submit for audit; use test users until approved |
url_ownership_unverified on init | PULL_FROM_URL domain not verified | Verify domain/URL-prefix (DNS TXT) in the portal |
rate_limit_exceeded | >6 req/min on the user token | Throttle + backoff; stop tight-looping the poll |
401 / access_token_invalid mid-cron | 24h access token expired | Refresh before each run; persist refresh_token |
| Empty watch time / completion | Wrong API or <24–48h since post | Use the Business API, not Display; wait for lag |
| Refresh fails after long idle | 365-day refresh token expired | Re-run the OAuth consent flow |
| Anti-pattern | Why it bites | Do instead |
|---|---|---|
Commit client_secret / a token file holding refresh_token | Leaks full account control to anyone with repo read | Gitignore it; load from env/secret store |
Hardcode a 24h access_token literal | Dead within a day; breaks every cron | Persist the refresh token; refresh each run |
| Tight-loop the status poll | Blows the 6/min cap → rate_limit_exceeded | Sleep ~10s between polls; back off on 429 |
Expect watch time from Display video/query | That field does not exist there | Counts from Display, watch time from Business |
| Treat an unaudited app as production | Only SELF_ONLY posts work for real users | Submit for audit before public posting |
PULL_FROM_URL without domain verification | Every init returns url_ownership_unverified | Verify domain/URL-prefix first, HTTPS, no redirects |
| Assume one approval covers publish + insights | Three independent gates | Posting audit + Display scope + Business portal |
| Overwrite yesterday's wiki snapshot | Destroys the trend + the 24–48h settling | Append a new dated entry every pull |
../social-publisher/SKILL.md — when the asset goes to many networks, not just TikTok.../instagram-api/SKILL.md — same family pattern, Instagram's Graph/Content Publishing API.../youtube-api/SKILL.md — same transport+ingestion shape, YouTube's two APIs.../remotion-video/SKILL.md — produce the clip file this skill only uploads.shortform-strategy, shortform-ideation, shortform-packaging, shortform-editing (catalog ids) — what the numbers mean, what to make, and how to package/edit it.api-connector-builder, automation-flows, knowledge-ops (catalog ids) — generic connector wrapping, cross-tool chaining, and wiki conventions.© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/tiktok-api of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Tiktok API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tiktok API this skillericrisco/rsc-harness | 156 | — | ~4.8k | Automated safety check: Pass | MIT | |
| X Bookmarkssharbelxyz/x-bookmarks | 289 | — | ~2k | Automated safety check: Notes | None | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| Passport Developmenttrypostit/trypost | 676 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~4k | Automated safety check: Pass | MIT |
sharbelxyz/x-bookmarks
Fetch, summarize, and manage X/Twitter bookmarks via bird CLI or X API v2.
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
trypostit/trypost
Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
thomast1906/github-copilot-agent-skills
Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling…. Tiktok API is an agent skill from ericrisco/rsc-harness. Use when connecting a real TikTok account to code via the Content Posting, Display and Business Account APIs — OAuth, chunked video publish with status polling, and pulling views, watch time and impression sources, then logging that performance into the wiki as a dated feedback record.
Tiktok API fits situations like: connecting a real TikTok account to code via the Content Posting; display and Business Account APIs — OAuth; chunked video publish with status polling; watch time and impression sources.
Run `npx skills add ericrisco/rsc-harness --skill tiktok-api -a claude-code`. Or copy the skill folder (skills/tiktok-api in ericrisco/rsc-harness) into .claude/skills/tiktok-api in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill tiktok-api -a codex`. Or copy the skill folder (skills/tiktok-api in ericrisco/rsc-harness) into .agents/skills/tiktok-api in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill tiktok-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tiktok-api, .gemini/skills/tiktok-api, .github/skills/tiktok-api and .opencode/skills/tiktok-api in your project.
Going by SKILL.md and its folder, Tiktok API needs a shell for the scripts in its folder and credentials named TIKTOK_CLIENT_KEY and TIKTOK_CLIENT_SECRET. Our summary lists: Python 3; A Bash shell; A credential in TIKTOK_CLIENT_KEY; A credential in TIKTOK_CLIENT_SECRET.
SKILL.md names 2 domains. In commands or code: open.tiktokapis.com and tiktok.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Tiktok API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Tiktok API: X Bookmarks (sharbelxyz/x-bookmarks, 289 stars), Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Passport Development (trypostit/trypost, 676 stars) and Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.