Turn approved products into reviewable social drafts, keep privacy checks in front of publishing, and connect one selected Development provider through the protected OAuth acceptance lane.
Admin-only explanatory illustration. It is not publication evidence and is never used on product pages, social posts, Open Graph cards, or structured data.
No credentials required
Platform Preview & Media Preflight
Check a proposed caption, destination link, and image before social API credentials are approved. This tool runs in the browser and does not publish, save, upload, or change product records.
Enter the proposed content, then run the preflight. Results are advisory and do not replace platform review, media consent, or the Social Media Privacy Guard.
The secure OAuth lifecycle is implemented. A real authorization response is accepted only on the Development Preview when the explicit operator switch and exactly one selected social provider agree. Production OAuth and all provider publication remain closed.
Pinterest verification:p:domain_verify is included in the head of every HTML page, including the home page.
Connection guide
What “connected” means
A pixel is tracking, not publishing. Meta Pixel/CAPI, Pinterest Tag, TikTok Pixel, and Google/YouTube tags measure visits and conversions. Organic publishing requires a provider developer app, secure OAuth authorization, intended-account verification, reviewed media/copy, and explicit human approval. Provider secrets remain in Cloudflare; they never belong in product forms, Git, browser JavaScript, or plaintext D1 fields.
1. Meta: Facebook Page + Instagram
Create a Meta developer app and configure only the products/permissions needed for Devil n Dove-owned Page and professional Instagram access.
Ensure the Facebook Page and Instagram Professional account are controlled by the intended Devil n Dove business identity.
Configure the secure OAuth client references, exact callback URL, intended Page ID, optional linked Instagram ID, and a safe account label in Development Cloudflare settings.
Select meta as the one Build 85 Development acceptance provider only when the external app is ready for deliberate authorization.
Complete OAuth from the Build 85 panel. The callback verifies the intended Page/account before encrypted token persistence.
Prepare and human-approve a queue draft. Build 85 still does not authorize a Facebook or Instagram post.
2. X
Create an X developer app and configure OAuth 2.0 Authorization Code with PKCE and only the required scopes.
Configure the expected Devil n Dove user ID and safe account label in Development.
Select x as the one Development acceptance provider before starting OAuth.
Complete intended-account verification and human draft approval before any later publication acceptance is considered.
3. Pinterest
Create a Pinterest developer app for the Devil n Dove Business account and configure the exact callback URL.
Configure the expected Devil n Dove Pinterest username and safe account label in Development.
Select pinterest as the one Development acceptance provider and complete the guarded OAuth flow.
Use a public HTTPS product image and destination URL in a human-reviewed queue draft. Build 85 does not create the Pin.
4. TikTok
Create a TikTok developer app and configure the intended Devil n Dove account identity plus exact OAuth redirect.
Use the Build 85 selected-provider acceptance lane only after app/scopes are externally approved.
Keep video/photo transfer and Direct Post disabled until a separate publication acceptance proves the required upload/post contract.
5. YouTube
Create a Google Cloud OAuth client, enable the YouTube Data API, and configure the exact callback.
Configure the expected Devil n Dove channel ID and safe label in Development.
Use Build 85 only to verify the OAuth/channel identity and human-approved draft evidence.
Resumable upload remains outside this build and is not authorized automatically.
6. Measurement and campaigns
Tracking pixels/tags remain separate from organic publishing authorization.
Use the social queue’s UTM fields and complete privacy/media review before marking a draft ready.
Review outcomes in existing analytics after a future controlled provider publication acceptance; Build 85 does not create provider posts.
How a new product becomes a social draft
Product is saved as Active and Approved/Published, with a usable product image.
When “Create a social draft” is enabled, the app creates one idempotent draft linked to that product.
Open the queue to review copy, media, platform choices, UTM link, duplicate warning, and Social Media Privacy Guard result.
Explicitly mark the queue item ready + approved only after privacy/public-media review is satisfied.
The Build 85 OAuth panel may then show the evidence as ready for a future controlled publication acceptance. It still provides no provider Publish action.
Important: Automatic drafting is enabled only by an admin setting. Automatic publishing remains deliberately unavailable because every final post can expose names, addresses, private workshop details, customer information, copyright-protected material, or an unfinished product claim.
No credentials required
Platform Preview & Media Preflight
Check a proposed caption, destination link, and image before social API credentials are approved. This tool runs in the browser and does not publish, save, upload, or change product records.
Enter the proposed content, then run the preflight. Results are advisory and do not replace platform review, media consent, or the Social Media Privacy Guard.