META Z logoMETA Z VN
Back to website
OFFICIAL API USE CASE · BUSINESS MESSAGING

TikTok Business Messaging Integration

How OmniDesk is designed to receive, organize and reply to customer conversations for an explicitly authorized TikTok Business Account.

Status: access subject to TikTok review Official API only Business authorization required Contact: [email protected]
Data flow Permissions Privacy Security Deletion

English disclosure

The integration is not presented as already approved. Live TikTok messaging access will be activated only after TikTok grants the required scopes and an eligible Business Account owner completes the official authorization flow.

1. Product and business use case

OmniDesk is a business customer-support workspace developed by META Z VN. It helps an authorized business team manage customer-initiated conversations from supported channels in one inbox. For TikTok, the intended use is to retrieve conversations for a connected Business Account, display them to employees assigned to that channel, and send replies on behalf of that business.

2. Eligible users

The integration is for businesses that own or are authorized to manage the connected TikTok Business Account. A business administrator chooses which employees can access each connected channel. Employees who are not assigned to a channel are not permitted to read or reply to its conversations.

3. Human oversight and automation boundaries

  • Customer conversations are handled by authorized business employees through a human-operated inbox.
  • Automatic or suggested messages are used only when supported by TikTok, enabled by the business administrator and permitted for the relevant account or conversation.
  • OmniDesk does not use Business Messaging access for unsolicited bulk outreach, scraping, account impersonation or bypassing TikTok messaging limits.
  • The business remains responsible for message content, employee assignment and compliance with TikTok policies and applicable law.

4. Data roles

The connected business determines why and how its customer conversations are handled and acts as the business data controller. META Z VN operates OmniDesk as a service provider or processor for the authorized business, subject to its documented instructions, platform requirements and applicable law. META Z VN does not sell messaging data or use it for unrelated advertising.

5. Authorization and revocation

OmniDesk does not request a TikTok password. The eligible account owner is redirected to the official TikTok authorization interface and chooses whether to grant access. The business can disconnect the channel in OmniDesk and can also revoke access through the relevant TikTok account or authorization controls. After revocation, OmniDesk must stop new API access for that authorization.

End-to-end data flow

01Business authorization

An eligible TikTok Business Account owner completes TikTok's official authorization flow.

02Webhook event

TikTok sends an event to the configured HTTPS webhook. The event is accepted only after the required verification checks.

03Authorized retrieval

OmniDesk uses the granted access token and permitted endpoints to retrieve the relevant conversation or message content.

04Scoped workspace

The conversation is associated with the correct organization and channel, then shown only to employees assigned to that channel.

05Reply or permitted automation

An authorized employee sends a reply, or an administrator-configured message is used only where TikTok indicates the capability is available.

06Audit, revoke and delete

Relevant actions are logged. The business can revoke access, disconnect the channel and request deletion of associated service data.

Data categories may include Business Account identifiers, conversation and message identifiers, message text, supported media, timestamps, delivery or capability status, employee assignment and security/audit events. OmniDesk requests and processes only data needed for the authorized workflow.

Requested access and purpose

AccessPurpose in OmniDeskRestriction
Business Messaging ReadList authorized conversations and messages, retrieve supported media and check conversation capabilities.Used only for a connected Business Account and employees assigned to that channel.
Business Messaging SendSend a human reply, upload supported reply media and use supported direct-reply capabilities.Used only for an eligible conversation and within TikTok capability and messaging limits.
Auto Message SettingConfigure supported automatic messages for a Business Account when this feature is included in the approved use case.Administrator-controlled; no unsolicited bulk messaging and no use outside TikTok-supported message types.
Business Messaging WebhooksReceive message-related events and synchronize the authorized conversation workspace.HTTPS endpoint, verification checks, replay/idempotency controls and organization/channel routing are required before production activation.

Data minimization

OmniDesk does not request every available TikTok permission. Each requested Business Messaging permission must be tied to the functions described above. Features outside the approved use case remain disabled.

Security and access controls

  • Organization data is separated and channel access is granted according to business role and assignment.
  • Access tokens and secrets are not displayed to ordinary users and must be protected in server-side storage.
  • Administrative actions, assignments and outbound replies are designed to be attributable through audit records.
  • Production activation requires HTTPS, webhook verification, secret management, backup and incident-response controls.

Công bố bằng tiếng Việt

Tích hợp này chưa được trình bày như đã được TikTok phê duyệt. Quyền nhắn tin thật chỉ được kích hoạt sau khi TikTok cấp đúng phạm vi quyền và chủ Tài khoản Doanh nghiệp đủ điều kiện hoàn tất luồng ủy quyền chính thức.

1. Mục đích sử dụng

OmniDesk là không gian chăm sóc khách hàng do META Z VN phát triển. Với TikTok, mục đích dự kiến là nhận hội thoại của Tài khoản Doanh nghiệp đã kết nối, hiển thị hội thoại cho đúng nhân viên được gán vào kênh và gửi câu trả lời thay mặt doanh nghiệp đó.

2. Phân quyền nhân viên

Quản trị viên doanh nghiệp quyết định nhân viên nào được truy cập từng kênh. Nhân viên không được gán vào kênh TikTok sẽ không được đọc hoặc trả lời hội thoại của kênh đó. Dữ liệu của các tổ chức khác nhau không được trộn lẫn.

3. Giới hạn tự động hóa

  • Nhân viên được ủy quyền là người trực tiếp xử lý phần lớn hội thoại.
  • Tin nhắn tự động hoặc gợi ý chỉ được dùng khi TikTok hỗ trợ, quản trị viên chủ động bật và tài khoản/hội thoại có khả năng tương ứng.
  • Không dùng quyền Business Messaging để gửi hàng loạt không mong muốn, thu thập dữ liệu trái phép, mạo danh hoặc vượt giới hạn TikTok.
  • Doanh nghiệp chịu trách nhiệm về nội dung trả lời, phân công nhân viên và việc tuân thủ chính sách.

4. Vai trò xử lý dữ liệu

Doanh nghiệp kết nối quyết định mục đích và cách xử lý hội thoại khách hàng. META Z VN vận hành OmniDesk với vai trò nhà cung cấp hoặc bên xử lý dữ liệu theo hướng dẫn hợp lệ của doanh nghiệp, yêu cầu nền tảng và pháp luật. Dữ liệu tin nhắn không được bán hoặc dùng cho quảng cáo không liên quan.

5. Thu hồi quyền và xóa dữ liệu

OmniDesk không yêu cầu mật khẩu TikTok. Chủ tài khoản thực hiện ủy quyền trên giao diện chính thức của TikTok. Doanh nghiệp có thể ngắt kết nối kênh, thu hồi quyền tại TikTok và gửi yêu cầu xóa dữ liệu dịch vụ liên quan theo Hướng dẫn Xóa dữ liệu.

Luồng dữ liệu từ đầu đến cuối

01Doanh nghiệp ủy quyền

Chủ Tài khoản Doanh nghiệp TikTok đủ điều kiện hoàn tất luồng ủy quyền chính thức của TikTok.

02Sự kiện webhook

TikTok gửi sự kiện tới webhook HTTPS đã cấu hình. Sự kiện chỉ được nhận sau các bước xác minh bắt buộc.

03Truy xuất có ủy quyền

OmniDesk dùng access token đã được cấp và endpoint được phép để lấy hội thoại hoặc nội dung tin nhắn liên quan.

04Workspace đúng phạm vi

Hội thoại được gắn đúng tổ chức và kênh, sau đó chỉ hiển thị cho nhân viên đã được phân công vào kênh.

05Trả lời hoặc tự động hóa được phép

Nhân viên được phép gửi câu trả lời; tin được quản trị viên cấu hình chỉ dùng khi TikTok xác nhận khả năng tương ứng.

06Nhật ký, thu hồi và xóa

Hoạt động liên quan được ghi nhận. Doanh nghiệp có thể thu hồi quyền, ngắt kết nối và yêu cầu xóa dữ liệu dịch vụ.

Nhóm dữ liệu có thể gồm mã Tài khoản Doanh nghiệp, mã hội thoại/tin nhắn, nội dung, media được hỗ trợ, thời gian, trạng thái gửi hoặc capability, phân công nhân viên và sự kiện bảo mật/kiểm toán. OmniDesk chỉ yêu cầu dữ liệu cần cho quy trình đã được ủy quyền.

Phạm vi quyền yêu cầu và mục đích

QuyềnMục đích trong OmniDeskGiới hạn
Business Messaging ReadLiệt kê hội thoại/tin nhắn đã được phép, lấy media được hỗ trợ và kiểm tra capability.Chỉ dùng cho Business Account đã kết nối và nhân viên được phân công đúng kênh.
Business Messaging SendGửi câu trả lời trực tiếp, upload media trả lời được hỗ trợ và dùng direct-reply khi khả dụng.Chỉ dùng cho hội thoại đủ điều kiện, trong capability và giới hạn nhắn tin của TikTok.
Auto Message SettingCấu hình tin nhắn tự động TikTok hỗ trợ khi chức năng này thuộc use case được duyệt.Do quản trị viên kiểm soát; không gửi hàng loạt không mong muốn hoặc dùng loại tin ngoài hỗ trợ.
Business Messaging WebhooksNhận sự kiện tin nhắn và đồng bộ workspace hội thoại đã được ủy quyền.Phải có HTTPS, xác minh, chống lặp/replay và route đúng tổ chức/kênh trước khi bật production.

Giảm thiểu dữ liệu

OmniDesk không yêu cầu tất cả quyền TikTok hiện có. Mỗi quyền Business Messaging phải gắn với chức năng được mô tả ở trên; chức năng ngoài use case được duyệt sẽ bị tắt.

Bảo mật và kiểm soát truy cập

  • Dữ liệu tổ chức được tách biệt; quyền kênh được cấp theo vai trò và phân công của doanh nghiệp.
  • Access token và secret không hiển thị cho người dùng thường và phải được bảo vệ ở phía máy chủ.
  • Thao tác quản trị, phân công và trả lời ra ngoài được thiết kế để truy vết bằng audit log.
  • Chỉ kích hoạt production sau khi kiểm tra HTTPS, webhook, quản lý secret, backup và xử lý sự cố.

Questions, review and contact

Questions about this integration, reviewer testing, privacy or security can be sent to [email protected]. Please do not send passwords, access tokens, private keys or real customer message content by email.

Privacy Policy Terms of Service Security Overview Data Deletion

Câu hỏi, xét duyệt và liên hệ

Câu hỏi về tích hợp, tài khoản reviewer, quyền riêng tư hoặc bảo mật có thể gửi tới [email protected]. Không gửi mật khẩu, access token, private key hoặc nội dung tin nhắn khách hàng thật qua email.

Chính sách Quyền riêng tưĐiều khoản Dịch vụTổng quan Bảo mậtXóa dữ liệu
© 2026 META Z VN
WebsitePrivacySecurityData deletion