MESH CollectiveSign In

Publishing Integrations

How MESH Collective connects to the platforms you publish to

Last Updated: September 1, 2026


What this page covers

MESH Collective is a business-to-business platform that helps marketing teams and agencies plan, write, review, and publish brand content. Its Content Scheduler lets a team draft a post once, route it through internal and client approval, and have it published to the destinations that team has connected — at a time they choose.

This page explains exactly what MESH asks each platform for, why, and what it does with the access. It is written for two audiences: customers deciding whether to connect an account, and platform review teams assessing our integration.

If you are looking for our general data practices, see the Privacy Policy. For the contractual terms, see the Terms and Conditions.


How connecting an account works

  1. An authorized administrator in your organization chooses a destination to connect from within MESH.
  2. For social and video platforms, you are sent to that platform's own consent screen, hosted by the platform, where you sign in and see exactly which permissions are being requested. MESH never sees or stores your platform password.
  3. The platform returns an access credential to MESH. We store it encrypted and use it only to perform the actions described below for the account you connected.
  4. For website platforms (WordPress, Webflow), there is no consent screen: you generate a scoped credential inside your own site's admin and paste it into MESH. It can be revoked from the same place at any time.

You choose which accounts, pages, or sites to connect. Connecting one account never grants MESH access to any other account you hold on that platform.


What we do with the access

Publishing content you have approved

The core function. MESH stores the post you wrote, together with the destination and the time you selected, and submits it to the platform at that time. Because publishing happens at a scheduled moment rather than while you are watching, three things are worth stating plainly:

  • Publishing is unattended. Once an item is approved and scheduled, MESH submits it to the platform automatically without a person present. That is the purpose of the feature.
  • Nothing publishes without human approval. An item must be explicitly approved and then armed for scheduling by a user in your organization before it is eligible to be sent. Content that is still in draft or review is never published.
  • You can cancel. An item can be edited, unscheduled, or deleted at any point before it is sent.

First comment

Where a platform supports commenting on your own posts through its API, MESH can post a single comment on the post it has just published — typically to carry a link or a hashtag block that the team preferred to keep out of the post body. This is the only comment MESH ever posts. It does not reply to other people, moderate, or interact with anyone else's content.

Reading back performance on posts we published

Where you have granted read access, MESH retrieves engagement metrics — impressions, reach, likes, comments, shares — for the posts it published on your behalf. This powers the performance reporting inside your own account. It is used for your analytics only.

Reading account identity

We read the name, identifier, and profile image of the specific page, channel, or site you connected, so the interface can show you which destination a post is going to rather than an opaque ID.


What we never do

  • We do not read your private messages, direct messages, or inbox.
  • We do not access your friends, followers, connections, or contact lists as personal data.
  • We do not post anything you have not written and approved inside MESH.
  • We do not comment on, react to, or interact with other people's content.
  • We do not sell, rent, or share platform data with third parties, and we do not use it for advertising or to build profiles of individuals.
  • We do not use data obtained from these platforms to train machine-learning models.

Platform by platform

Each entry lists the access MESH requests and the feature it exists for. We request the narrowest set that makes the feature work.

Facebook Pages (Meta)

PermissionWhat it is used for
pages_show_listLets you pick which of your Pages to connect
pages_read_engagementReads the Page identity and post-level engagement for your reporting
pages_manage_postsPublishes the posts, photos, and videos you scheduled
pages_manage_engagementPublishes Reels, and posts the optional first comment
pages_manage_metadataRequired by Meta to attach media to a Page post
read_insightsRetrieves performance metrics for posts MESH published

MESH uses these to publish scheduled content to Pages you administer, and to report on how that content performed. Our use of Meta platform data complies with the Meta Platform Terms and Developer Policies.

Instagram (Meta)

PermissionWhat it is used for
instagram_basicReads the connected Instagram Business account's identity
instagram_content_publishPublishes feed posts, carousels, Reels, and Stories you scheduled
instagram_manage_commentsPosts the optional first comment on content MESH published
instagram_manage_insightsRetrieves performance metrics for posts MESH published

Instagram publishing requires a Business account linked to a Facebook Page, which is Meta's requirement rather than ours.

LinkedIn

PermissionWhat it is used for
w_organization_socialPublishes posts to company pages you administer
r_organization_socialReads back the posts MESH published, and their engagement
rw_organization_adminConfirms which company pages you are entitled to post to

MESH posts only to LinkedIn company pages, not to personal profiles, and only to pages the connecting user administers.

TikTok

PermissionWhat it is used for
user.info.basicReads the connected account's identity
video.publishPublishes the videos you scheduled
video.uploadWhere selected, delivers a video to the creator's drafts instead of publishing

MESH surfaces TikTok's required commercial-content disclosure options at the point of scheduling, so a post that needs to be marked as branded content is marked before it is sent.

YouTube (Google)

ScopeWhat it is used for
https://www.googleapis.com/auth/youtube.uploadUploads the videos you scheduled to the channel you connected, and sets them to publish at your chosen time

MESH's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data obtained through Google APIs is used only to provide the features described on this page, is not transferred to third parties except as necessary to provide those features or as required by law, is not used for advertising, and is not read by humans except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.

WordPress

MESH connects using an Application Password that you generate inside your own WordPress admin, under Users → Profile. It is scoped to the account that created it, works only over the site's REST API, and can be revoked from the same screen at any moment. MESH uses it to create posts on the site you connected. It does not read your users, comments, or settings.

Webflow

MESH connects using a Site API Token that you generate in your Webflow site settings. You then tell MESH which CMS collection holds your posts, and which of that collection's fields correspond to title, body, and slug — because Webflow has no fixed idea of a "blog post". MESH uses the token to create items in that one collection.


Where your content and credentials live

  • Credentials are encrypted at rest using AES-256-GCM, and are decrypted only in memory at the moment a publish request is made. They are never written to logs, never shown back to you in full, and never sent to any third party.
  • Content you schedule — post copy, images, video, and the approval history — is stored in our database on infrastructure located in the United States, and is retained while your account is active. See Data retention in our Privacy Policy.
  • Access is scoped to your organization. People in one customer organization cannot see another organization's calendar, connections, or content.

Disconnecting

You can disconnect any destination from the Connections screen inside MESH at any time. On disconnect:

  • MESH stops using the credential immediately, and no further content can be published to that destination.
  • Any items still scheduled to that destination will not be sent.
  • The stored credential is deleted from our systems.
  • Records of what was already published are retained as part of your account history. Content already live on the platform is unaffected — remove it there if you want it taken down.

You can also revoke MESH's access from the platform's own settings — Meta Business settings, LinkedIn account settings, TikTok app permissions, your Google Account's third-party access page, or by deleting the Application Password or Site Token. Revoking on the platform side has the same effect: publishing stops.

To delete your MESH account and the data in it, see Data deletion requests in our Privacy Policy, or contact us at the address below.


Contact

Questions about these integrations, or a request relating to data we hold:

MESH, L.L.C. Email: [email protected]


MESH Collective is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., LinkedIn Corporation, TikTok Ltd., Google LLC, Automattic Inc., or Webflow, Inc. All product names and trademarks are the property of their respective owners.

© 2026 MESH Collective. All rights reserved.

Privacy PolicyTerms & ConditionsIntegrationswhenwemesh.com