← Back to AdSpend Hero

How we use the TikTok Marketing API

Last updated: 25 September 2026

This page describes, without marketing language, exactly what AdSpend Hero Pro does with the TikTok Marketing API. It is here for advertisers who want to know what they are authorising, and for TikTok's review team.

What the product is

AdSpend Hero Pro is a rule engine for advertisers. An advertiser writes rules in plain terms — for example "pause an ad group once it has spent €4 without a single add-to-cart" — and the service carries them out around the clock, checking every ten seconds. The point is to stop budget being spent on ad groups that are demonstrably not working, within minutes instead of at the end of the day.

Who authorises what

Nothing happens without the advertiser. They sign in to TikTok themselves through TikTok's own authorisation screen and select which advertiser accounts we may access. We never ask for TikTok passwords, and we only ever see the accounts they ticked. They can disconnect at any time, in our app or from TikTok's side.

What we read

EndpointWhat we use it for
/oauth2/access_token/Exchanging the advertiser's authorisation code for an access token
/oauth2/advertiser/get/Listing the advertiser accounts the user has authorised
/advertiser/info/Name, currency, time zone and country of those accounts
/campaign/get/, /adgroup/get/, /ad/get/Names, status and budgets of campaigns, ad groups and ads
/report/integrated/get/Spend, impressions, clicks, add-to-carts, purchases and revenue
/bc/get/, /advertiser/balance/get/Remaining balance or spending limit, so we can warn before an account runs dry

What we change

EndpointWhen
/adgroup/status/update/
/smart_plus/adgroup/status/update/
Pausing an ad group when the advertiser's rule is met, and switching it back on if a sale still arrives within the window they set
/campaign/status/update/The same at campaign level, when the advertiser's rule works at that level
/adgroup/update/, /campaign/update/Raising or lowering a budget, only when a rule the advertiser wrote says so

What the software cannot do, by design. It cannot create campaigns, ad groups or ads. It cannot delete or archive anything. It cannot touch creatives, audiences, pixels or catalogues. Every call passes through a guard that refuses any request whose path or payload contains delete, remove or archive — so this is not a policy we promise to follow, it is a rule the code enforces on itself.

How often we call

For an account that is actively delivering we read performance roughly every ten seconds, because a €20-a-day ad group can waste its first €4 in well under an hour. Accounts with nothing running are checked far less often. We respect TikTok's rate limits, back off when asked to, and retry politely rather than hammering.

What we do with the data

  • It is shown to the advertiser it belongs to, and to nobody else. Each customer's data is separated by account, and we test that separation automatically after every change.
  • Access tokens are stored encrypted, never as readable text.
  • We keep a log of every action so the advertiser can verify exactly what was paused and why.
  • We do not sell data, do not share it for advertising, and do not use it to train anything.
  • Delete the account and the data and tokens go with it. Details in our Privacy Policy.

Who we are

GOODVIBES ENTERPRISE - FZCO · Trade licence 50179 · IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates · support@adspend-hero.com

AdSpend Hero Pro is an independent product and is not affiliated with, endorsed by or sponsored by TikTok.

← Back to AdSpend Hero