Business API access

Requested permissions and their purpose

HaloCrystal requests only the API capabilities required for the business-account features described below. Access is limited to accounts that complete authorization.

Account User

Retrieve basic profile and account identifiers for the business account that has authorized HaloCrystal.

Get Account Media

Retrieve media belonging to the authorized account for content management and operational reporting.

Account Comment

Access comments associated with authorized account media to support moderation, response workflows, and customer engagement.

Account Post Content

Publish content to an authorized account only when initiated or approved by the account owner or its authorized operator.

Auth Code Management

Receive authorization responses and securely maintain the OAuth authorization lifecycle for connected accounts.

Authorization controls

Consent firstWe do not access a business account before the account holder completes the authorization process.
Revocable accessAccount holders may revoke platform authorization and may also contact us to request deletion of data stored by HaloCrystal.
Minimum useWe use API-returned data only for the functionality described on this site and in our privacy policy.

Registered redirect endpoints

These public endpoints are intended for authorization responses.

Advertiser redirect URL
https://tk.halocrystal.com/advertiser-redirect.html
TikTok account holder redirect URL
https://tk.halocrystal.com/tiktok-account-holder-redirect.html