TikTok privacy_level_options: public vs private account values
TikTok creator_info returns different privacy_level_options for public and private accounts, and Direct Post privacy_level must match one. Values for each.

TikTok returns different privacy choices for public and private accounts, and Direct Post accepts only a value from that list. The Query Creator Info page says a public account gets PUBLIC_TO_EVERYONE, MUTUAL_FOLLOW_FRIENDS and SELF_ONLY, while a private account gets FOLLOWER_OF_CREATOR, MUTUAL_FOLLOW_FRIENDS and SELF_ONLY. The Direct Post page says the privacy_level you send must match one of those options (read 2026-10-02).
What are the privacy_level values?
privacy_level is a required field in post_info. The enum on the Direct Post page has four values; which of them your user may pick depends on the account.
| Value | Public account | Private account |
|---|---|---|
| PUBLIC_TO_EVERYONE | Offered | Not offered |
| FOLLOWER_OF_CREATOR | Not offered | Offered |
| MUTUAL_FOLLOW_FRIENDS | Offered | Offered |
| SELF_ONLY | Offered | Offered |
What else does creator_info decide for the post?
comment_disabled is true when the creator set comments to No one. duet_disabled and stitch_disabled are true when the account is private or the setting is No one. On the Direct Post side, the server disables duets and stitches for private accounts and comments for creators who set Comments to No one, whatever you send.
The same post_info carries is_aigc. When set to true, the page says the video is labelled with a Creator labeled as AI-generated tag in the description. It defaults to false; it is on you to set it for a video from a generator.
Where does Sume fit?
Sume produces the video and a media.sume.com URL; the TikTok calls are yours. Direct Post PULL_FROM_URL needs a publicly accessible video_url. Fetch the job result with GET /v1/jobs/:id/result and pass its URL on. The page's creator-info call should happen right before the post so the options are current.
# Show only the privacy choices this creator may use, then post with one of them.
curl -s -X POST "https://open.tiktokapis.com/v2/post/publish/creator_info/query/" \
-H "Authorization: Bearer $TIKTOK_ACCESS_TOKEN" \
-H "Content-Type: application/json; charset=UTF-8" \
| python3 -c "import json,sys; print(json.load(sys.stdin)['data']['privacy_level_options'])"What should I do?
Never hard-code PUBLIC_TO_EVERYONE. Query the options, show them, and send what the creator picks. Set is_aigc: true for generated video, and read TikTok's own policy page for what else must be disclosed.
Sources
Related posts
More in Integrations
- TikTok publish webhooks vs Sume run webhooks: wire both safely
TikTok sends webhooks for failed, complete, inbox, public and removed posts. Sume signs its own run webhook separately. Keep two receivers and verify Sume's.
- Val Town free 1-minute timeout: a Sume webhook receiver val
Val Town's free plan stops a val at 1 minute and runs crons every 15 minutes at best. Submit Sume jobs async, then take the result by webhook or a slow cron.
- Vercel Workflow createWebhook is token-only: verify Sume first
createWebhook trusts only the URL token. For a Sume callback, verify the sume-v1 signature in your own route, then resume a hook with resumeHook.
- VS Code mcp.json: servers or mcpServers key for Sume's hosted MCP?
VS Code's .vscode/mcp.json uses a top-level servers key; the portable .mcp.json uses mcpServers. Put Sume's entry under the key that matches its file.
Written by Sume