Can your AI agent post videos to TikTok and YouTube for you?
Both posting APIs are free but audited: until then, YouTube locks uploads private and TikTok shows posts only to you. The two routes left, and what they cost.
Yes, but rarely through the platforms’ own posting APIs. Both are free, and both hold back an app that has not passed an audit: YouTube locks every upload from an unaudited project as private, with no appeal, and TikTok takes an unaudited app’s posts only from a private account, visible to the owner alone until each is made public by hand. TikTok’s rules also count a tool for posting to your own accounts as an unacceptable use, so the audit will not lift that for you. The two routes left are a posting service that has already passed both reviews, which your agent calls through an API or MCP server, or your agent driving a browser you are already signed in to. The first gives a third party standing permission to post as you; the second needs your browser running, and YouTube’s terms forbid automated access without its permission.
YouTube: private until the project is audited
YouTube’s upload method, videos.insert in the Data API, costs nothing, and quota is not what stands in the way: a project gets 100 uploads a day by default. The catch is in the method’s own reference: every video uploaded through it from an unverified project created after 28 July 2020 is “restricted to private viewing mode.” YouTube calls such a video locked as private, and its help page on locked videos is plain about what follows: you cannot appeal, and the video has to be uploaded again through a verified service or YouTube itself.
Lifting the restriction means passing YouTube’s API compliance audit, requested through its Audit and Quota Extension Form. The audit reviews the project as an API client like any other, against developer policies that expect a privacy policy users agree to, users with “final authority” over anything the client uploads for them, and access for YouTube’s reviewers to the client when they ask. That is a sizeable project for one person’s agent.
This is the wall a do-it-yourself upload script, or a skill from a public registry, runs into. If it asks you to create a Google Cloud project and an OAuth client of your own, it uploads through an unaudited project, and everything it posts will be locked private.
TikTok: posts only you can see
TikTok’s Content Posting API is free and audited too. Its getting-started page says that “all content posted by unaudited clients will be restricted to private viewing mode,” and the content-sharing guidelines give the detail: an unaudited app posts only at SELF_ONLY visibility, for at most five users in 24 hours, and each of those accounts must itself be set to private at the time of posting. Even to reach that stage, TikTok has to approve the app for the posting scope. The same guidelines say how such a post goes public later: the owner switches the account to public, then changes each post’s privacy to “Everyone.” So a tool of your own can publish, clumsily: the account has to be private whenever the agent posts, and every video is made public by hand afterwards.
The audit will not remove that for a personal tool. The same guidelines list what TikTok counts as unacceptable, and one entry is “a utility tool to help upload contents to the account(s) you or your team manages.” They also ask an app that posts directly to let the user pick the privacy setting from a list with no default, to show a preview, and to send nothing until the user has expressly agreed. Read together, they describe apps built for many creators, each approving their own posts. Audited apps meet a daily cap as well, which TikTok puts at “typically around 15 posts per day” per creator account.
Route one: a posting service your agent calls
A posting service is an app that has already passed these reviews. It offers one API across both platforms, and often an MCP server, so posting becomes a tool call for your agent. Two examples, at September 2026 prices: Upload-Post has a free tier of ten uploads a month, which by its own plan notes leaves TikTok out, and paid plans from $24 a month (less paid yearly), and says its app is verified with the platforms; Blotato starts at $29 a month for 20 social accounts, with its API and MCP server. Connecting one works like any other MCP server.
What a service costs beyond the fee is access. You authorize it on each platform, and from then on a third party holds standing permission to post to your accounts, used whenever your agent, or anyone else holding the service’s API key, asks. Treat that key like the password to your channels. Before choosing one, check whether the plan you would pay for includes TikTok, whether it passes through the settings an AI-made video needs (below), and whether it can upload a draft rather than post straight to the public.
How much you want to approve
Both platforms leave room for a supervised middle way, and it answers most of the worry about an agent posting as you. TikTok’s upload flow sends the video to the account’s TikTok inbox, where the owner opens the notification, finishes the post in the app and publishes it; Upload-Post calls this draft mode. On YouTube, an upload goes up private and you publish it from YouTube Studio once you have watched it. The agent renders and uploads; the last tap, and every setting on the post, stays yours. Scheduling is a different choice: a video uploaded with a publish time (status.publishAt) goes public at that time with no further look from you. Posting straight to the public is the other end: none of your time, and nothing between a bad render or a wrong caption and your followers.
Route two: your agent in your signed-in browser
The other way skips the APIs. The agent opens YouTube Studio or TikTok’s upload page in a browser where you are already signed in, attaches the file, fills in the details and posts, the way you would. No audit applies, and every setting the page offers is there, including any a service does not carry.
It has to be a browser you signed in to yourself. Google says it may block sign-ins from browsers “being controlled through software automation rather than a human”, so an agent’s own automated browser is a poor place to log in to YouTube. OpenClaw can drive your signed-in Chrome in two ways: attaching over remote debugging, which Chrome asks you to allow the first time, or through its browser extension, which needs nobody at the desk. Both are in its browser profiles docs, and an agent on a server can reach a browser on your computer through a node host running there.
One practical catch: OpenClaw’s upload action takes files only from its own uploads folder or from media it has received, so a video the agent rendered elsewhere is copied there first. What the agent hands back to you (sign-ins, two-factor prompts, CAPTCHAs) is covered in the guide to OpenClaw’s browser.
The costs are availability and exposure. The browser, and the computer it runs on, has to be on and signed in whenever the agent posts, and each post is an agent working through a page built for people, slower than an API call and at the mercy of the next redesign. A signed-in browser is also sensitive in its own right: whatever the agent reads on the web shares a browser with your accounts, which is where prompt injection can do the most harm.
The risk to your account
YouTube’s terms of service forbid accessing the service “using any automated means (such as robots, botnets or scrapers)” except for public search engines or with YouTube’s prior written permission, which is what an agent operating YouTube Studio is doing. The same terms let YouTube suspend or terminate an account that breaches them materially or repeatedly. TikTok’s US terms (updated July 2026) forbid automated scraping and “inauthentic commercial behaviors, such as by operating spam or impersonation accounts,” and say nothing specific about automated posting.
Neither platform says how it treats an occasional post made from its owner’s own browser on the owner’s instruction, so there is no published line to stay behind. The account at stake is the one you are trying to grow, and the API route, through an audited app, is the one both platforms sanction.
Settings an AI-made video needs, whichever route
Both platforms ask for disclosures at upload, and an agent that posts has to set them, or leave the post unpublished until you have:
- TikTok’s AI label. TikTok requires a label on AI-generated content that contains realistic images, audio or video. Through the API it is the
is_aigcfield, which adds the “Creator labeled as AI-generated” tag. - TikTok’s commercial disclosure. A video promoting your own business sets
brand_organic_toggle; a paid partnership setsbrand_content_toggle. Both fields, and the AI label, are in the direct post reference. - YouTube’s AI use disclosure. Realistic content made or altered with AI is disclosed under “AI use” in the Attributes section of YouTube Studio, or with
status.containsSyntheticMediathrough the API. YouTube’s help page exempts content that is not realistic, minor edits, and cloning your own voice for a voice-over, and warns that creators who consistently skip it can have a label applied, content removed or their YouTube Partner Program membership suspended.
A posting service’s documentation should say which of these it passes through. Where one is missing, the supervised route covers it: TikTok’s post is finished in the app, and YouTube’s setting sits in the video’s Attributes in Studio before you make it public.