申请主体与产品归属
登记主体
土拨鼠(厦门)网络有限公司
统一社会信用代码:91350200MAEPRR1536
企业身份对应
企业域名:tbsapi.com
企业邮箱:min360058129@tbsapi.com
TBSAPI 是土拨鼠(厦门)网络有限公司的技术品牌,TBS GMVmax 是本公司开发和运营的广告自动化辅助产品。开发者账户类型选择“技术公司”,与营业执照所列软件开发、技术服务、数字技术服务和信息技术咨询业务一致。详细主体信息见 公司主体核验页。
产品用途
土拨鼠 GMVmax 是为拥有一个或多个 TikTok Shop 店铺的广告运营团队开发的内部 SaaS 工具。客户授权自己的广告账户后,系统汇总 GMV Max 计划和表现数据,评估客户配置的规则,先生成预演结果,再在满足权限和安全条件时执行客户确认的动作。
主要用户包括内部电商运营团队、独立电商卖家和获得客户授权的广告运营服务团队。
不提供消费者登录,不出售 TikTok 数据,不抓取 TikTok 密码,不代表用户静默创建广告,也不使用一个客户的数据服务其他客户。
首轮请求的访问能力
广告账户列表读取
用途:列出当前客户在 OAuth 中主动授权的广告账户,并为后续数据建立明确归属。
广告计划与 GMV Max 读取
用途:显示计划名称、状态、预算和 GMV Max 配置,支持只读分析与规则预演。
广告报告读取
用途:读取消耗、收入、订单、ROI 和时间维度指标,用于看板、异常识别和规则条件。
商品和素材关联读取
用途:解释 GMV Max 表现来源,并让用户按商品或素材定位问题。仅在相应账户数据可用时读取。
本轮不申请计划创建、预算修改、状态修改或素材写入。写权限将在只读产品通过审核并形成真实使用证据后单独申请。
OAuth 流程
- 管理员登录 https://gmv.tbsapi.com/console。
- 在“集成与数据源”中选择 TikTok 官方 API,并点击连接。
- 系统创建一次性 state,并将用户跳转到 TikTok 官方授权页面。
- 用户在 TikTok 页面选择广告账户和权限。
- TikTok 将授权码返回固定 HTTPS 回调。服务端校验 state、交换令牌并加密保存。
- 用户返回控制台,检查授权账户和能力探测结果。
https://gmv-auth.tbsapi.com/api/integrations/tiktok_official/oauth/callback审核测试步骤
- 打开产品首页,确认产品用途、公司主体、隐私政策、数据删除和支持链接均无需登录。
- 使用申请备注中提供的审核账户登录控制台。
- 在数据总览查看明确标记的演示账户和演示数据。
- 打开规则中心,选择规则并点击“预演”,检查条件、建议动作和安全拦截结果。
- 打开安全策略,确认官方写入和插件写入均为关闭。
- 打开集成页并启动 TikTok OAuth。使用审核测试账户完成授权。
- 返回集成页,确认只显示本次授权的广告账户与读取能力。
- 断开授权,确认后续官方同步停止且令牌状态被清除。
如果审核环境需要专用账户或同步测试时间,请联系 min360058129@tbsapi.com 并提供申请编号。
安全限制
- 只启用平台已批准的权限,并且每个广告账户仍需有权用户明确完成 OAuth。
- 官方写入和插件写入默认关闭,并由不同开关控制。
- 规则默认以预演模式运行,预演与真实执行使用同一验证链。
- 预算变更比例、每日消耗、动作数量、数据新鲜度、冷却和紧急停止均为强制检查。
- 每次动作记录操作人、目标、原值、建议值、结果和平台响应。
审核链接
Applicant entity and product ownership
Registered entity
Tuboshu (Xiamen) Network Co., Ltd.
Registered Chinese name: 土拨鼠(厦门)网络有限公司
Unified social credit code: 91350200MAEPRR1536
Corporate identity
Corporate domain: tbsapi.com
Corporate email: min360058129@tbsapi.com
TBSAPI is the company's technology brand. TBS GMVmax is an advertising automation assistance product developed and operated by the company. The Technology Company account type matches the registered software development, technology services, digital technology services and information technology consulting business scope. See the Company Verification page.
Product purpose
TBS GMVmax is an internal SaaS tool for advertising operations teams that own or manage one or more TikTok Shop stores. After a customer authorizes an advertiser, the product aggregates GMV Max campaign and performance data, evaluates customer-configured rules, produces a preview, and executes customer-confirmed actions only when permission and safety conditions are satisfied.
Primary users are in-house ecommerce operators, independent ecommerce merchants, and advertising operations providers authorized by their clients.
The service does not provide consumer sign-in, sell TikTok data, collect TikTok passwords, create ads silently, or use one customer's data for another customer.
Access requested for initial review
Advertiser list read
Purpose: list only advertisers the current customer explicitly authorizes in OAuth and establish data ownership.
Campaign and GMV Max read
Purpose: show campaign name, status, budget and GMV Max configuration for read-only analysis and rule previews.
Advertising report read
Purpose: read spend, revenue, orders, ROI and time-window metrics for dashboards, anomaly detection and rule conditions.
Product and creative association read
Purpose: explain sources of GMV Max performance and help users locate product or creative issues when that account data is available.
This initial request does not include campaign creation, budget modification, status modification or creative writes. We plan to request write access separately only after read-only approval and verifiable usage.
OAuth flow
- An administrator signs in at https://gmv.tbsapi.com/console.
- Under Integrations and Data Sources, the user selects TikTok Official API and chooses Connect.
- The server creates one-time state and redirects the user to TikTok's official authorization page.
- The user selects advertiser accounts and permissions on TikTok.
- TikTok returns an authorization code to the fixed HTTPS callback. The server validates state, exchanges the code and encrypts the token.
- The user returns to the console and reviews authorized advertisers and capability detection.
https://gmv-auth.tbsapi.com/api/integrations/tiktok_official/oauth/callbackReview test steps
- Open the product homepage and confirm that product purpose, company identity, privacy, deletion and support are public.
- Use the reviewer account supplied in the application notes to sign in to the console.
- Open Overview and inspect clearly labeled demonstration advertisers and data.
- Open Rules, choose a rule and select Preview. Review conditions, proposed actions and safety checks.
- Open Safety Policy and confirm official writes and extension writes are both disabled.
- Open Integrations and start TikTok OAuth. Complete authorization with a reviewer test account.
- Return to Integrations and confirm only authorized advertisers and read capabilities are shown.
- Disconnect authorization and confirm official sync stops and token status is cleared.
For a dedicated review account or coordinated sync test, contact min360058129@tbsapi.com with the application reference.
Safety limits
- Only platform-approved scopes can activate, and each advertiser still requires explicit OAuth consent.
- Official and extension writes are separate controls, both disabled by default.
- Rules default to preview mode. Preview and live execution use the same validation chain.
- Budget-change percentage, daily spend, action count, data freshness, cooldown and emergency stop are mandatory checks.
- Every action records actor, target, original value, proposed value, result and platform response.