Publishing Channels
Publishing channels (Studio Settings › Publishing channels, studio.tflowx.com/settings#social) is where your company registers the social channels Studio content will be published to. Paste the API key or token each platform issues; TFlow verifies it against the platform before saving, and the channel then appears in the publish dialog.
🔒 TFlow never asks for your account password. A token carries publishing permission only, can be revoked on the platform at any time, is stored encrypted, and is never shown again on screen or in responses. No screen in TFlow requests a password.
ℹ️ Connecting channels is free. Automatic publishing to external channels is a licensed feature and Studio's publish dialog is being rolled out; a connected channel is usable the moment it opens.
1. Connecting
Open Settings in Studio's left rail → the Publishing channels group. If you belong to several companies, pick one at the top right.
- Who can do this: the company master or a store content manager (store_manager). Other members can view the status only. Managers are assigned in the main app under My Organization › Storefront.
- Each channel offers two ways.
- Connect API key: register the key or token the platform issued (sections 2–7; How to get it links there). TFlow verifies it against the platform and saves nothing if verification fails. Required for automatic and scheduled publishing.
- Register handle only: register just the account name (@handle or blog ID) without any key. It is stored immediately without verification and is used for company-account control in the browser extension (semi-automatic publishing) — the extension types nothing if the account signed in on the compose page differs from the registered handle. Connecting an API key for the same account later upgrades that row in place.
- The API / Handle tag next to an account shows how it was registered.
- Each account shows name · status · expiry · last check — Expiring soon (60-day token) or Revoked means reconnect with a new token.
- Check re-verifies now; Disconnect deletes the stored token (published posts are untouched). Several accounts per platform are allowed.
🖼️ Screenshot Studio settings — Publishing channels group with the Instagram form open 📍
studio.tflowx.com/settings#social· save asimages/studio/social-channels.png
The main app's My Organization › Publishing tab (master only) lets you review the company's connections and disconnect them — the place to reclaim accounts a departed employee connected. Connecting and checking happen in Studio.
Common errors
| Message | Cause · fix |
|---|---|
| The platform rejected these keys | Wrong, expired or revoked token. Re-issue the token on the platform and paste it again. Make sure the app has publishing permission |
| The platform could not confirm the account | Keys are valid but the account type does not qualify (e.g. a personal Instagram account, not a page admin) |
| The platform did not respond | Platform outage or a transient network issue. Try again shortly |
| You do not have permission for this action | Not a master or store manager. Ask for the role under My Organization › Storefront |
2. Instagram
You need: one access token · Requirement: an Instagram professional (business/creator) account
- In the Instagram app: Settings › Account type › Switch to professional account.
- Sign in to Meta for Developers → Create app → choose the Instagram use case.
- In the app dashboard, Instagram › API setup with Instagram login → Add Instagram testers → add your own account.
- In the Instagram app, Settings › Apps and websites › Tester invites → accept.
- Back in the dashboard, Generate access token → confirm permissions → copy the long-lived token.
- Paste it into Access Token in TFlow and press Connect.
⏳ The token expires after 60 days. Repeat step 5 and reconnect before then. (Automatic refresh is in preparation.)
3. Threads
You need: one access token
- Add the Threads API use case to your Meta for Developers app (the same app as Instagram is fine).
- Threads › Use case settings → Add testers → accept the invite in the Threads app.
- Generate access token → copy the long-lived token → paste into Access Token in TFlow.
Tokens expire after 60 days, like Instagram.
4. Facebook Page
You need: Page ID · Page access token · Requirement: you are an admin of the page
- Add the Facebook Login product to your Meta for Developers app.
- In the Graph API Explorer, pick the app, add the permissions
pages_manage_posts,pages_read_engagement,pages_show_list, and Generate user token. - Switch User or Page › Page access token and select the target page; copy the page token shown.
- Find the Page ID under the page's About › Page transparency, or query
me/accountsin the explorer. - Enter Page ID and Page Access Token in TFlow and press Connect.
💡 If the explorer's user token is short-lived (1 hour), the page token dies with it. Extend it to a long-lived token in the Access Token Debugger first, then repeat step 3 — page tokens derived that way do not expire.
5. X
You need: API Key · API Key Secret · Access Token · Access Token Secret (four values)
- Create a developer account at the X Developer Portal and register a payment method. Since 2026 the posting API is pay-per-use — about $0.015 per post, about $0.20 when the post contains a link — billed to your developer account. TFlow does not cover this cost.
- Create a Project › App and set User authentication settings to Read and write.
- On Keys and tokens, generate the API Key / Secret, then regenerate the Access Token / Secret after changing the permission — tokens created while read-only cannot post.
- Enter the four values in TFlow and press Connect.
X user tokens do not expire.
6. LinkedIn
You need: one access token · Scope: personal profiles only (company pages require LinkedIn partner approval and are not supported)
- Create an app at LinkedIn Developers (an app must be associated with a company page to be created).
- On the Products tab add Share on LinkedIn and Sign In with LinkedIn using OpenID Connect.
- Auth › OAuth 2.0 tools › Token generator → create a token with the scopes
openid profile w_member_social. - Paste it into Access Token in TFlow and press Connect.
⏳ The token expires after 60 days and LinkedIn does not expose a refresh API. Repeat step 3 and reconnect before then.
7. YouTube
You need: OAuth Client ID · OAuth Client Secret · Refresh Token
- In the Google Cloud Console, create a project and enable YouTube Data API v3.
- Create an external OAuth consent screen and set its publishing status to In production — in Testing status, refresh tokens expire every 7 days.
- Credentials › OAuth client ID (Desktop app) → copy Client ID / Secret.
- In the OAuth 2.0 Playground, open the gear icon → Use your own OAuth credentials, enter the values above, authorize with the scope
https://www.googleapis.com/auth/youtube.upload, and copy the Refresh token. - Enter the three values in TFlow and press Connect.
⚠️ Until Google completes its API compliance audit of your project, videos uploaded this way are private only. For public publishing, apply for the audit on your own project (2–4 weeks).
8. Naver Blog, the browser extension and other channels
- Naver Blog has no official posting API, so the browser extension (semi-automatic) is the only path. Use Register handle only to register the blog ID; the extension then fills the compose page only in a browser signed in to that blog. No Naver login credentials are collected.
- The Browser extension row (bottom of Settings › Publishing channels) shows whether it is installed, the install link, and the company accounts the extension checks against. The extension opens the X or Naver compose page from Studio with the body and images filled in; you press Publish yourself.
- TikTok and LinkedIn company pages require platform audits or partner approval first and are not yet connectable.