Review access
Use the production URL and credentials included in the private reviewer-instructions field. UGCFlow does not publish credentials on this public page. The supplied account must have access to Social accounts, approved test content, and the provider connection being reviewed.
End-to-end review steps
- 1Open the production login URL and use the reviewer credentials supplied privately in the review submission.
- 2Open Social accounts and choose the provider being reviewed.
- 3Read the displayed data-purpose disclosure, then continue to the provider consent screen.
- 4Confirm that the consent screen shows the same app identity and scopes listed in this guide.
- 5Return to UGCFlow and confirm that the connected account identity and connected status are visible.
- 6Open an approved video, choose Publish, select the connected account, and review the provider-specific options.
- 7Choose the safest review visibility offered by the provider, confirm the publication, and inspect its resulting status.
- 8Return to Social accounts and disconnect the provider to verify credential removal and revocation controls.
Requested scopes and functionality
YouTube
Data requested
Channel identifier, channel name, and metadata or status for videos uploaded through UGCFlow.
youtube.upload · youtube.readonly
Why UGCFlow uses it
Identify the channel selected by the user, upload a user-selected video, and show the resulting publication status.
User control
Every upload starts from an explicit publish action. New review uploads default to Private. Disconnecting revokes Google access, deletes stored credentials and channel identity data, and cancels unpublished scheduled videos.
Meta
Data requested
Instagram professional account identifier, username, profile details, and publishing authorization.
instagram_business_basic · instagram_business_content_publish
Why UGCFlow uses it
Show the connected professional account and publish a user-selected video as an Instagram Reel.
User control
The user chooses the content and whether the Reel is shared to the profile feed before publishing.
Threads
Meta
Data requested
Threads account identifier, username, basic profile details, and publishing authorization.
threads_basic · threads_content_publish
Why UGCFlow uses it
Show the connected Threads account and publish a user-selected video thread.
User control
The user initiates each publication and chooses who can reply before the post is queued.
TikTok
TikTok
Data requested
Basic account information identifies the connected creator. UGCFlow also uses current creator posting capabilities, Direct Post authorization, and publication status for content sent through UGCFlow.
user.info.basic · video.publish
Why UGCFlow uses it
user.info.basic identifies the connected creator. video.publish loads current creator posting capabilities, sends only approved creator-selected content after explicit consent, and checks publication status.
User control
OAuth tokens are encrypted at rest. Connecting a TikTok account alone never publishes content. Disconnecting removes the stored credential and prevents future publishing.
Expected provider-specific result
YouTube
The reviewer sees channel identity, selects title/category/audience and Private visibility, then observes the uploaded video publication status.
The reviewer connects a professional account, chooses whether to share the Reel to the profile feed, and confirms a user-selected video publication.
Threads
The reviewer connects a Threads account, chooses who can reply, and confirms a user-selected video thread publication.
TikTok
The reviewer sees the exact approved video preview plus the connected creator’s nickname and avatar when TikTok provides them, otherwise a connected-account fallback identity. The reviewer manually chooses a privacy option from TikTok’s current creator information and sees supported Comment, Duet, and Stitch controls default off. The reviewer completes commercial-content and AIGC disclosures, accepts the linked TikTok policy declaration, explicitly starts Direct Post using video.publish, and sees the resulting publication status.
Demo video checklist
- Record at 1280×720 or higher and keep the browser address bar visible.
- Show the production UGCFlow brand, the complete provider consent screen, and every requested scope in English.
- Show the connected identity, the exact feature that uses each scope, the explicit publish action, and the resulting publication status.
- Show disconnect and deletion controls. Use a clean test account and do not expose passwords, access tokens, client secrets, or personal messages.
- Record separate focused evidence when different permissions support materially different provider flows.
Support during review
If a reviewer cannot access a step or a supplied test account, contact developer@ugcflow.online and include the provider, review case, and failing step. Do not send provider client secrets or OAuth tokens by email.
