Skip to main content

Built for social media agencies

Every client account, one dashboard.

W AUTO POST is a social media management platform for agencies. Schedule and publish your clients' content through the official platform APIs, and give every client their own space to review what goes out — without logging into each account by hand.

Publishes through official platform APIs

  • TikTokTikTok
  • InstagramInstagram
  • YouTubeYouTube

Accounts are connected with the platform's own authorisation screen. We never ask for, receive or store social media passwords, and never bypass two-factor authentication.

What you get

The tools an agency actually needs to run a publishing operation across many accounts.

Multi-client, multi-account

A client can have as many accounts as they need — several TikTok profiles, Instagram and YouTube side by side. Each is connected and monitored independently.

Upload once, publish everywhere

One piece of media becomes as many posts as you have destinations, each with its own caption, schedule and status. The file itself is stored once.

Calendar and scheduling

Month, week, day and agenda views across every client. Schedule in the account’s own timezone; everything is stored in UTC so nothing drifts.

Client approval workflow

Send content for review and let the client approve, reject or request changes. Approval can be required per client, or switched off entirely.

Automatic retries

Temporary failures — rate limits, network blips, platform errors — are retried on a backoff. Permanent errors stop immediately and tell you exactly why.

Full audit trail

Every connection, upload, approval, schedule change and publish attempt is logged with who did it and what happened.

How it works

The agency workflow, start to finish.

  1. 01

    Add the client

    Create the client, set their timezone, and decide whether their content needs their approval before it can be scheduled.

  2. 02

    Connect their accounts

    The client authorises your app on the platform’s own screen. They grant the permissions; you never see a password.

  3. 03

    Upload and compose

    Upload the media once, then create a destination for each account — its own caption, hashtags and publish time.

  4. 04

    Client reviews

    If approval is on, the client sees the queue in their own dashboard and approves, rejects or asks for changes.

  5. 05

    It publishes itself

    The scheduler runs on the server. Nothing needs to stay open on your machine, and nothing publishes twice.

Two dashboards, one system

You get the full operational surface. Your client gets a focused, mobile-friendly space that only ever shows their own work.

CapabilityAgency adminClient
See every client and accountYesNo
Connect and disconnect accountsYesNo
Upload and edit contentYesNo
Schedule and reschedule postsYesNo
Approve, reject or request changesYesYes
See their own scheduled and published postsYesYes
See their own account healthYesYes
See their own activity and analyticsYesYes
See other clients’ dataYesNo

Supported platforms, and exactly what we ask for

W AUTO POST integrates only through each platform's official API. We request the narrowest set of permissions the features need, and every one is listed here with what it is used for.

TikTok

TikTok

Publish video, read post status and account info via the Content Posting API.

user.info.basic
Read the connected account’s username and avatar, so the agency can tell several TikTok accounts apart.
video.upload
Send a video the agency has uploaded to the account as a draft.
video.publish
Publish that video at the time the agency scheduled and the client approved.
Instagram

Instagram

Publish to Business and Creator accounts via the Instagram Graph API.

instagram_basic
Read the connected professional account’s profile and media list.
instagram_content_publish
Create and publish a post or Reel on the account.
pages_show_list
Find the Facebook Page the Instagram professional account is linked to.
business_management
Confirm the account belongs to the business that authorised us.
YouTube

YouTube

Upload video and read basic analytics via the YouTube Data API v3.

youtube.upload
Upload a video to the connected channel.
youtube.readonly
Read the channel name and the public view, like and comment counts of videos we published.

We do not request permission to read private messages, follower lists, or any data unrelated to publishing and reporting on the content we posted. Access can be withdrawn at any time from the platform's own app settings, or by asking the agency to disconnect the account — both stop publishing immediately. Connecting an account requires an approved developer application for that platform; availability of specific features depends on the platform's API and on the permissions each client grants.

Security is part of the product

No passwords, ever

Accounts are connected with official OAuth. We do not ask for, receive or store social media passwords, and we do not bypass two-factor authentication.

Tokens encrypted at rest

Access tokens live in a table that application users cannot read at all, and are encrypted with AES-256-GCM on top of that.

Isolation enforced in the database

Client separation is enforced by PostgreSQL row level security, not by filtering in the browser. A client cannot reach another client’s data by changing an ID.

Publishing cannot double-fire

Idempotency keys, database constraints and recorded platform post IDs mean a retry or a duplicate trigger cannot publish the same post twice.

Frequently asked questions

Do you need my client’s social media password?

No. Accounts are connected through the platform’s own OAuth authorisation screen. Your client signs in with the platform directly and chooses which permissions to grant. We never see, receive or store a password, and we never ask anyone to disable two-factor authentication.

Does my computer need to stay on for posts to publish?

No. Scheduling runs on the server. Once a post is scheduled and approved, it publishes on its own whether or not anyone has the dashboard open.

Can a client see another client’s content?

No. Every client user is bound to exactly one client, and that boundary is enforced by row level security inside the database. Even a hand-crafted API request with another client’s ID returns nothing.

What happens if a post fails to publish?

Temporary problems such as rate limits or network errors are retried automatically with a backoff. Permanent problems — an expired authorisation, an unsupported file, a rejected caption — stop straight away and appear in Failed Posts with the exact reason, so you can fix and retry manually.

Which analytics do you show?

Only the figures the connected platform actually returns for that account. If a platform does not report a metric, the product says so rather than showing a zero or an estimate.

How is data deleted?

Clients can be paused, archived or deleted, and connected accounts can be disconnected at any time, which deletes the stored authorisation. Anyone can request deletion from the Data Deletion page, and we confirm by email once a verified request is processed.

Run your whole publishing operation from one place.

Get in touch to set up your agency workspace and connect your first client account.