Skip to content
Trust / Platform review

Platform review information

This public page tells platform reviewers exactly what Publishly does, why each permission is requested, how to test it, and what remains limited before approval. Last reviewed 2026-08-17.

In one minute

What Publishly is
A social publishing and scheduling platform. People who manage several brands, clients, or locations connect the accounts they own or are authorized to manage, write and schedule posts, and get a delivery receipt confirming each post went live — or a classified reason when it did not.
Why it needs API access
To publish the content a user has written to the account that user connected, and to read back enough of the result to prove the post is live. That is the whole purpose of the permissions requested below — nothing is used for advertising, resale, or profiling.
What the user sees before authorizing
A connect screen naming the network and what Publishly will be able to do, then the platform's own consent screen listing the exact permissions. Nothing is requested silently, and Publishlynever renders a form asking for the platform's username or password.
How authorization starts
Only from a signed-in user pressing Connect account inside the product. There is no other entry point.
How publishing works
The user selects media, writes a caption per network, and either publishes immediately or schedules a time. Publishing happens through the platform's official API and only against an instruction that user created.
How access is removed
Disconnect on the channel destroys the stored authorization. Full deletion — including the Meta de-authorization and data-deletion callbacks — is documented on the data-deletion page.
Reviewer contact
phliq5215@gmail.com — reviewer questions are answered ahead of the normal queue.
Submission in review

Meta: Instagram API with Instagram Login — Advanced Access

This submission covers the Instagram Login journey end to end: a user connects a professional Instagram account, publishes an image or video with a caption from Publishly and receives a delivery receipt with the live media permalink, reads and replies to comments on their own media, reads and replies to direct messages the account has received, views the account and post insights Publishly displays, and disconnects the account. Every Facebook Page permission and the Threads permissions are outside this submission and are not requested at authorization.

Authorization model: Instagram API with Instagram Login (Instagram business login, enable_fb_login=0)
Redirect URI: https://publishlyapi.com/oauth/instagram/callback
Deauthorize callback: https://publishlyapi.com/oauth/meta/deauthorize
Data deletion callback: https://publishlyapi.com/oauth/meta/data-deletion
Webhook callback: https://publishlyapi.com/webhooks/meta/instagram
Data deletion instructions: https://publishlyapi.com/data-deletion

Permissions requested: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments, instagram_business_manage_messages, instagram_business_manage_insights

Deliberately not requested: instagram_basic, instagram_content_publish, instagram_manage_comments, instagram_manage_messages, instagram_manage_insights, pages_show_list, pages_read_engagement, pages_manage_metadata, business_management. The authorization screen never asks for these, and the product surfaces that would need them stay switched off until they are separately reviewed and approved.

Real product and intended users

Publishly is a social publishing and scheduling service for agencies, multi-brand and multi-location operators, and creator teams. A user explicitly connects accounts they are authorized to manage, composes or schedules content, and receives per-destination delivery receipts, classified failure reasons, and connection-health alerts.

Publishly is a user-directed publishing tool, not an account farm, artificial-engagement service, or internal upload utility. It acts only after a user connects an account they are authorized to manage and explicitly creates or schedules content.

Reviewer journey

  1. Open the public homepage, Privacy Policy, Terms, data-deletion instructions, and live status page without signing in.
  2. Use credentials supplied only in the platform's protected review form to sign in to the dedicated reviewer workspace.
  3. Choose Connect accountand pick the network. Publishly hands off to the platform's own authorization screen — it never presents a form asking for the platform's username or password.
  4. Approve the reviewer-owned test account on that screen. Only the permissions listed above are requested; the consent screen is the sole place access is granted.
  5. Select media, write the caption, and inspect the platform-specific preflight/preview that enforces the network's real limits before anything is sent.
  6. Publish immediately or schedule for later, then follow queued - uploading - sent - confirmed_live (or a classified failure) in the receipt view, which links to the live media permalink.
  7. Disconnect the account from the channel menu and verify that the stored authorization is destroyed, then confirm the same outcome through the data-deletion instructions.

Every step above is user-initiated. Publishly holds no standing permission to post: it acts on an account only after a user connects it through the platform's own consent screen, and only against a publishing instruction that user created.

How Publishly handles platform data

  • It accesses only the accounts a user has explicitly connected through the platform's authorization screen.
  • It never asks a user for their platform password. Authorization is an OAuth handoff, and the credential Publishly receives is an access token issued by the platform.
  • Access tokens are encrypted with AES-256-GCM authenticated encryption before they are written to storage, and are never displayed back to the user.
  • Each workspace is isolated: connected accounts, tokens, media, and history are scoped to the workspace that created them.
  • A user can disconnect any account at any time, which destroys the stored authorization for that channel.
  • Full account and workspace deletion, plus the Meta de-authorization and data-deletion callbacks, are documented on the data-deletion page.

Test credentials and private app identifiers are intentionally absent from this public page. They are shared only through the provider's secure reviewer field.

Instagram

Authentication: Instagram API with Instagram Login. The Facebook Login for Business adapter is retained so existing Page-linked connections keep refreshing, publishing and disconnecting, but it is not offered for new connections.
Access path: Meta App Review plus business verification for advanced access
Callback: https://publishlyapi.com/integrations/social/instagram, https://publishlyapi.com/integrations/social/instagram-standalone, https://publishlyapi.com/oauth/instagram/callback
Canonical callback for new connections: https://publishlyapi.com/oauth/instagram/callback

Requested permissions: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments, instagram_business_manage_messages, instagram_business_manage_insights

Legacy Facebook Login for Business — existing connections only, not requested in this submission: instagram_basic, pages_show_list, pages_read_engagement, business_management, instagram_content_publish, instagram_manage_comments, instagram_manage_messages, instagram_manage_insights, pages_manage_metadata. Not requested at authorization unless a deployment explicitly sets META_ALLOW_FACEBOOK_LINKED_INSTAGRAM.

Why: instagram_business_basic identifies the professional account the user chose so the connection is bound to a verified Instagram identity and the username is shown before publishing. instagram_business_content_publish creates the media container and publishes the user's own scheduled post, then reads back the resulting media id and permalink to confirm it is live. instagram_business_manage_comments reads the comments on that media and posts the replies the user writes in Publishly. instagram_business_manage_messages reads the conversations the account has received so the user can answer them in Publishly, and sends those replies within the window Instagram allows. instagram_business_manage_insights reads the account and post metrics Publishly displays back to the user who owns them.

Evidence path: Sign in to the reviewer workspace, connect a reviewer-owned professional Instagram account through the Instagram Login screen and confirm the connected username matches. Upload original test media, add a caption, publish, open the delivery receipt showing the returned media id and permalink, and open the live media URL. Open the inbox to show the comments on that media and post a reply. Send a direct message to the connected account from a second Instagram account, show it arriving in the inbox, and reply to it. Open analytics to show the account and post insights. Then disconnect the connection and confirm the credential is removed. The deployment must run with INSTAGRAM_LOGIN_ENGAGEMENT=true so the consent screen presents all five permissions.

Current limitation: Only Instagram professional (Business or Creator) accounts can be connected. Publishly publishes only content the user created or scheduled in the product, and replies only to comments and messages that account actually received. Direct message replies are sent only inside the response window Instagram permits; outside it Publishly disables the reply rather than attempting a send. Publishly does not read or write anything on Facebook Pages.

Official references: reference 1 / reference 2 / reference 3 / reference 4 / reference 5 / reference 6

Facebook

Authentication: Meta OAuth through Facebook Login
Access path: Meta App Review plus business verification for advanced access
Callback: https://publishlyapi.com/integrations/social/facebook, https://publishlyapi.com/oauth/facebook/callback
Canonical callback for new connections: https://publishlyapi.com/oauth/facebook/callback

Requested permissions: pages_show_list, business_management, pages_manage_posts, pages_manage_engagement, pages_read_engagement, pages_read_user_content, read_insights

Why: pages_show_list discovers the Pages the authorizing user manages so they can choose which to connect. pages_read_engagement reads the Page and its own posts. pages_read_user_content reads the comments other people leave on those posts, which is what the Facebook inbox displays. pages_manage_posts publishes the post the user scheduled in Publishly and reads back its id to confirm it is live. pages_manage_engagement posts the replies the user writes to those comments. read_insights reads the Page and post metrics Publishly shows back to the owner. business_management identifies the Business that owns a selected Page so an agency can connect a client Page they administer rather than only their own.

Evidence path: Connect a reviewer-owned Page, select it, publish and confirm one Page post, display and reply to a comment, then open Page/post analytics. Show business/client Page selection to justify business_management.

Current limitation: Publishly posts only to Pages for which the authorizing user has the required Page task; it does not post to personal profiles.

Official references: reference 1 / reference 2

TikTok

Authentication: TikTok Login Kit OAuth
Access path: TikTok app review and Content Posting API Direct Post audit
Callback: https://publishlyapi.com/integrations/social/tiktok

Requested permissions: video.list, user.info.basic, video.publish, video.upload, user.info.profile, user.info.stats

Why: Identify the creator and show profile/stat context; upload or directly publish user-approved media; poll processing; list the creator's posts to confirm delivery.

Evidence path: Show login and consent, current creator nickname/capabilities, no-default privacy choice, preview, interaction/disclosure controls, mandatory consent, direct publish, processing state, confirmed receipt, and the same post in video list/profile analytics.

Current limitation: Before Direct Post audit, TikTok forces SELF_ONLY and low user/post caps. Publishly surfaces that state and never describes a private-only post as public.

Official references: reference 1 / reference 2 / reference 3 / reference 4 / reference 5 / reference 6 / reference 7 / reference 8 / reference 9 / reference 10

YouTube

Authentication: Google OAuth 2.0 web-server flow
Access path: Google OAuth verification for sensitive scopes; YouTube quota/compliance audit when requesting more quota
Callback: https://publishlyapi.com/integrations/social/youtube

Requested permissions: https://www.googleapis.com/auth/userinfo.profile, https://www.googleapis.com/auth/youtube.readonly, https://www.googleapis.com/auth/youtube.upload, https://www.googleapis.com/auth/yt-analytics.readonly

Why: Name the connected channel; upload user-scheduled videos; independently read the uploaded video/channel to confirm delivery; display the user's YouTube Analytics.

Evidence path: Show the English Google consent screen with every requested scope, connect a test channel, upload a video, open the confirmed receipt/live URL and analytics, then disconnect and demonstrate programmatic Google token revocation and local data removal.

Current limitation: Default YouTube Data API quota is finite; higher-volume production requires a successful YouTube compliance audit and quota extension.

Official references: reference 1 / reference 2 / reference 3

X

Authentication: OAuth 1.0a user context
Access path: Self-service X developer account/project setup and funded API access
Callback: https://publishlyapi.com/integrations/social/x

Requested permissions: Read and write

Why: Create and read posts for the authorizing account. Direct-message access is not requested.

Evidence path: Show the app configured Read and write with the exact production callback, connect the test account, publish once, and open the confirmed post URL.

Current limitation: The operator must fund API credits and configure a spend limit. User access tokens may be revoked even though they have no fixed expiry.

Official references: reference 1 / reference 2

Threads

Authentication: Threads OAuth
Access path: Meta App Review for requested Threads permissions
Callback: https://publishlyapi.com/integrations/social/threads, https://publishlyapi.com/oauth/threads/callback
Canonical callback for new connections: https://publishlyapi.com/oauth/threads/callback

Requested permissions: threads_basic, threads_content_publish, threads_manage_replies, threads_manage_insights

Why: Identify the Threads profile; publish and confirm posts; manage replies initiated through the product; display profile/post insights.

Evidence path: Connect a reviewer account, publish and confirm a thread, show reply management, and open profile/post insights.

Current limitation: Only accounts and actions authorized through the official Threads flow are supported.

Official references: reference 1

LinkedIn

Authentication: LinkedIn OAuth 2.0 / OpenID Connect
Access path: Self-serve Share on LinkedIn for members; Community Management Development then Standard tier for Pages
Callback: https://publishlyapi.com/integrations/social/linkedin, https://publishlyapi.com/integrations/social/linkedin-page

Requested permissions: openid, profile, w_member_social, rw_organization_admin, w_organization_social, r_organization_social

Why: Identify the member and publish member posts; for separately reviewed Page access, find Pages the user administers, publish/confirm organization posts, and show organization analytics.

Evidence path: Record separate member and Page journeys. For Standard tier provide a live integrated app, test credentials, narrated high-resolution OAuth/Page-post/comment-and-analytics recording, and explicitly identify any absent Community Management features.

Current limitation: Do not submit Community Management Standard access until the live Page flow and evidence are complete; a rejected application cannot simply reapply.

Official references: reference 1 / reference 2

Pinterest

Authentication: Pinterest OAuth 2.0
Access path: Trial access followed by Standard access review
Callback: https://publishlyapi.com/integrations/social/pinterest

Requested permissions: boards:read, pins:read, pins:write, user_accounts:read

Why: Identify the business account, list its boards, create/read Pins, confirm delivery, and display Pin analytics.

Evidence path: From a live HTTPS product, show exact OAuth redirect and consent, list a test board, create a Pin, open its confirmed URL, and display its analytics.

Current limitation: Trial-created Pins and Boards are creator-only sandbox data; public production use needs Standard access.

Official references: reference 1 / reference 2

Bluesky

Authentication: Per-user revocable Bluesky App Password
Access path: No central developer app review
Callback: No OAuth callback

Requested permissions: No operator-owned application permissions

Why: Create posts on the user's own PDS session using a dedicated app password; the account password is never requested.

Evidence path: Create a dedicated App Password with account security left enabled, connect, publish a canary, then revoke that App Password in Bluesky settings.

Current limitation: There is no operator app secret or approval. PDS hosts are user-selected and validated against SSRF before server requests.

Official references: reference 1 / reference 2

Mastodon

Authentication: Dynamic per-instance OAuth application registration
Access path: No central review; the selected Mastodon server registers the app
Callback: https://publishlyapi.com/integrations/social/mastodon

Requested permissions: profile, write:statuses, write:media

Why: Verify the account and publish statuses/media on the user-selected instance. Client credentials are created per instance and encrypted with the connection.

Evidence path: Enter a public test instance, dynamically register, authorize the exact granular scopes, publish and confirm a canary, then disconnect.

Current limitation: Instance policies and rate limits vary; Publishly does not claim one global Mastodon application or aggregate Mastodon analytics.

Official references: reference 1 / reference 2

Platform names and affiliation

Publishly integrates with supported social platforms through their available APIs. Platform names and marks belong to their respective owners and are used here only to identify the integration each section describes. Publishly is not owned by, endorsed by, affiliated with, or an official partner of any of these platforms. Approval is determined solely by each platform, and this page claims no partnership, certification, or approval that has not been granted.

Review and privacy contact

Operator: Silver Gorilla Group LLC, 3 Chevy Dr. #1034, E. Syracuse, NY 13057, United States.
Review & general questions: phliq5215@gmail.com
Privacy & data requests: phliq5215@gmail.com
Security reports: phliq5215@gmail.com

Privacy Policy · Terms of Service · Acceptable Use · Security · Data deletion · Contact