Publishing Integrations
How MESH Collective connects to the platforms you publish to
Last Updated: September 1, 2026
What this page covers
MESH Collective is a business-to-business platform that helps marketing teams and agencies plan, write, review, and publish brand content. Its Content Scheduler lets a team draft a post once, route it through internal and client approval, and have it published to the destinations that team has connected — at a time they choose.
This page explains exactly what MESH asks each platform for, why, and what it does with the access. It is written for two audiences: customers deciding whether to connect an account, and platform review teams assessing our integration.
If you are looking for our general data practices, see the Privacy Policy. For the contractual terms, see the Terms and Conditions.
How connecting an account works
- An authorized administrator in your organization chooses a destination to connect from within MESH.
- For social and video platforms, you are sent to that platform's own consent screen, hosted by the platform, where you sign in and see exactly which permissions are being requested. MESH never sees or stores your platform password.
- The platform returns an access credential to MESH. We store it encrypted and use it only to perform the actions described below for the account you connected.
- For website platforms (WordPress, Webflow), there is no consent screen: you generate a scoped credential inside your own site's admin and paste it into MESH. It can be revoked from the same place at any time.
You choose which accounts, pages, or sites to connect. Connecting one account never grants MESH access to any other account you hold on that platform.
What we do with the access
Publishing content you have approved
The core function. MESH stores the post you wrote, together with the destination and the time you selected, and submits it to the platform at that time. Because publishing happens at a scheduled moment rather than while you are watching, three things are worth stating plainly:
- Publishing is unattended. Once an item is approved and scheduled, MESH submits it to the platform automatically without a person present. That is the purpose of the feature.
- Nothing publishes without human approval. An item must be explicitly approved and then armed for scheduling by a user in your organization before it is eligible to be sent. Content that is still in draft or review is never published.
- You can cancel. An item can be edited, unscheduled, or deleted at any point before it is sent.
First comment
Where a platform supports commenting on your own posts through its API, MESH can post a single comment on the post it has just published — typically to carry a link or a hashtag block that the team preferred to keep out of the post body. This is the only comment MESH ever posts. It does not reply to other people, moderate, or interact with anyone else's content.
Reading back performance on posts we published
Where you have granted read access, MESH retrieves engagement metrics — impressions, reach, likes, comments, shares — for the posts it published on your behalf. This powers the performance reporting inside your own account. It is used for your analytics only.
Reading account identity
We read the name, identifier, and profile image of the specific page, channel, or site you connected, so the interface can show you which destination a post is going to rather than an opaque ID.
What we never do
- We do not read your private messages, direct messages, or inbox.
- We do not access your friends, followers, connections, or contact lists as personal data.
- We do not post anything you have not written and approved inside MESH.
- We do not comment on, react to, or interact with other people's content.
- We do not sell, rent, or share platform data with third parties, and we do not use it for advertising or to build profiles of individuals.
- We do not use data obtained from these platforms to train machine-learning models.
Platform by platform
Each entry lists the access MESH requests and the feature it exists for. We request the narrowest set that makes the feature work.
Facebook Pages (Meta)
| Permission | What it is used for |
|---|---|
pages_show_list | Lets you pick which of your Pages to connect |
pages_read_engagement | Reads the Page identity and post-level engagement for your reporting |
pages_manage_posts | Publishes the posts, photos, and videos you scheduled |
pages_manage_engagement | Publishes Reels, and posts the optional first comment |
pages_manage_metadata | Required by Meta to attach media to a Page post |
read_insights | Retrieves performance metrics for posts MESH published |
MESH uses these to publish scheduled content to Pages you administer, and to report on how that content performed. Our use of Meta platform data complies with the Meta Platform Terms and Developer Policies.
Instagram (Meta)
| Permission | What it is used for |
|---|---|
instagram_basic | Reads the connected Instagram Business account's identity |
instagram_content_publish | Publishes feed posts, carousels, Reels, and Stories you scheduled |
instagram_manage_comments | Posts the optional first comment on content MESH published |
instagram_manage_insights | Retrieves performance metrics for posts MESH published |
Instagram publishing requires a Business account linked to a Facebook Page, which is Meta's requirement rather than ours.
| Permission | What it is used for |
|---|---|
w_organization_social | Publishes posts to company pages you administer |
r_organization_social | Reads back the posts MESH published, and their engagement |
rw_organization_admin | Confirms which company pages you are entitled to post to |
MESH posts only to LinkedIn company pages, not to personal profiles, and only to pages the connecting user administers.
TikTok
| Permission | What it is used for |
|---|---|
user.info.basic | Reads the connected account's identity |
video.publish | Publishes the videos you scheduled |
video.upload | Where selected, delivers a video to the creator's drafts instead of publishing |
MESH surfaces TikTok's required commercial-content disclosure options at the point of scheduling, so a post that needs to be marked as branded content is marked before it is sent.
YouTube (Google)
| Scope | What it is used for |
|---|---|
https://www.googleapis.com/auth/youtube.upload | Uploads the videos you scheduled to the channel you connected, and sets them to publish at your chosen time |
MESH's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data obtained through Google APIs is used only to provide the features described on this page, is not transferred to third parties except as necessary to provide those features or as required by law, is not used for advertising, and is not read by humans except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.
WordPress
MESH connects using an Application Password that you generate inside your own WordPress admin, under Users → Profile. It is scoped to the account that created it, works only over the site's REST API, and can be revoked from the same screen at any moment. MESH uses it to create posts on the site you connected. It does not read your users, comments, or settings.
Webflow
MESH connects using a Site API Token that you generate in your Webflow site settings. You then tell MESH which CMS collection holds your posts, and which of that collection's fields correspond to title, body, and slug — because Webflow has no fixed idea of a "blog post". MESH uses the token to create items in that one collection.
Where your content and credentials live
- Credentials are encrypted at rest using AES-256-GCM, and are decrypted only in memory at the moment a publish request is made. They are never written to logs, never shown back to you in full, and never sent to any third party.
- Content you schedule — post copy, images, video, and the approval history — is stored in our database on infrastructure located in the United States, and is retained while your account is active. See Data retention in our Privacy Policy.
- Access is scoped to your organization. People in one customer organization cannot see another organization's calendar, connections, or content.
Disconnecting
You can disconnect any destination from the Connections screen inside MESH at any time. On disconnect:
- MESH stops using the credential immediately, and no further content can be published to that destination.
- Any items still scheduled to that destination will not be sent.
- The stored credential is deleted from our systems.
- Records of what was already published are retained as part of your account history. Content already live on the platform is unaffected — remove it there if you want it taken down.
You can also revoke MESH's access from the platform's own settings — Meta Business settings, LinkedIn account settings, TikTok app permissions, your Google Account's third-party access page, or by deleting the Application Password or Site Token. Revoking on the platform side has the same effect: publishing stops.
To delete your MESH account and the data in it, see Data deletion requests in our Privacy Policy, or contact us at the address below.
Contact
Questions about these integrations, or a request relating to data we hold:
MESH, L.L.C. Email: [email protected]
MESH Collective is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., LinkedIn Corporation, TikTok Ltd., Google LLC, Automattic Inc., or Webflow, Inc. All product names and trademarks are the property of their respective owners.