Business Purpose
CHUANGJU LIMITED operates an advertising optimization platform
for TikTok Ads and GMV Max. The current release supports
company-operated and invited authorized advertiser accounts;
later phases will serve authorized business owners, TikTok Shop
sellers, cross-border merchants, brands, and agencies.
Requested Use Cases
We request Marketing API access for reporting, campaign
management, creative management, catalog or product review,
Business Center account workflows, and measurement dashboards.
Data We Intend To Access
We intend to access authorized advertiser, campaign, ad group,
ad, creative, catalog, product, shop, spend, conversion, GMV,
ROAS, ROI, budget, status, request ID, and aggregate reporting
metrics.
Data We Do Not Seek
We do not scrape TikTok, access unauthorized accounts, resell
TikTok data, collect user-level click logs, bypass TikTok review
systems, or use API access for competitor intelligence.
Phased Permission Strategy
Phase 0
Operational pilot
Reporting/read, advertiser and campaign sync, GMV Max
campaign-level reporting, rule evaluation.
Phase 1
Controlled beta
OAuth and Business Center authorization, multi-account
isolation, product and creative recommendations.
Phase 2
Limited write
Human-confirmed campaign creation, pause/restart, budget
adjustment, ROI target updates, and audit logs.
Phase 3
Automation
Customer-configured rule execution with spend caps, emergency
pause, rollback, revocation, and deletion flows.
Operational Workflow
OAuth authorization
Advertiser and shop selection
Reporting sync
Rule evaluation
Human approval or configured automation
Audit log and BI review
Authorization Callback Endpoint
The advertiser authorization callback for TikTok Business API is:
https://hkchuangju.com/api/tiktok/advertiser/callback
The token-capable TikTok account holder redirect URL for Creator
and TikTok account OAuth v2 authorization flows is:
https://hkchuangju.com/api/tiktok/account/callback
The public review page for explaining and testing redirected
callback parameters is:
https://hkchuangju.com/oauth/tiktok-account/callback
This callback receives TikTok authorization results, including
authorization code, state, or error parameters. The public page does
not store tokens or secrets. Token exchange, state validation,
credential storage, and audit logging are handled in the internal
backend application.
TikTok Shop and TikTok Account Scope
For GMV Max workflows, we need to identify authorized TikTok Shops,
confirm whether each shop can be used for GMV Max campaigns, review
eligible products, and evaluate the TikTok accounts or posts that
are available for product or live GMV Max campaigns. The intended
API usage includes store access checks, product eligibility checks,
identity availability checks, and authorized post review for
campaign setup and optimization.
Shop access
GMV Max store selection
Use authorized Business Center and advertiser permissions to
list TikTok Shops, store status, store role, GMV Max
availability, and exclusive authorization status.
Product review
Product selection
Review eligible products, product occupancy, availability, and
campaign readiness before creating or adjusting GMV Max
campaigns.
Account identity
TikTok account access
Retrieve authorized TikTok account identities associated with
a shop or Business Center and confirm whether those identities
are available for Product GMV Max or LIVE GMV Max workflows.
Post review
Short video candidates
Review authorized TikTok posts, product-linked videos, creative
performance fields, and customized-post eligibility for
operator-approved campaign decisions.
Automation Guardrails
The system evaluates spend pacing, CPA, ROAS, ROI, GMV, conversion
volume, stock availability, margin, refund risk, product quality,
creative fatigue, and campaign status. Sensitive changes use
authorization checks, predefined limits, cooldown windows, exception
handling, approval thresholds, emergency pause, and rollback
records.
Demo Review Plan
Our review demo will show the company website, platform pages,
privacy and terms, a product dashboard, TikTok authorization flow,
advertiser selection, campaign data sync, GMV Max monitoring, rule
creation, manual approval for a campaign action, and the resulting
audit log. We will only demonstrate products and permissions that
are actually requested.
Security and Compliance Controls
Tokens and secrets are treated as sensitive credentials. Access
follows least-privilege principles. Customer data is separated by
advertiser and business scope. Customers can revoke authorization,
pause automation, and request deletion of stored operational data.
Finance and payment permissions are not required for the initial
optimization workflow.
Contact for Platform Review
TikTok Business API review, security, privacy, or business
verification questions can be sent to
chuangjulimited@chuangjuhk.top.