Social Commerce

Connect TikTok Shop to a Custom Website: Auth, Webhooks and Sync

How to connect TikTok Shop to a custom website: what to sync, the OAuth flow, a webhook plus polling backend, and the mapping mistakes that cause lost orders.

Ảnh đại diện Long Nguyen

Long Nguyen

Lập trình viên Fullstack · Kỹ sư AI · Nhà nghiên cứu

• • 4 phút đọc •

What "connect TikTok Shop to a custom website" actually means

TikTok Shop is not a widget you embed. Shoppers check out inside TikTok, so "connecting" your own website means synchronizing data between two systems, not putting a TikTok checkout on your pages. Once you see it that way, the job splits into four data flows, each with its own failure modes.

Flow Direction What moves Where it breaks
Catalog Your site to TikTok Shop Products, variants, images, prices, category attributes Category rules and required attributes differ per market; rejected listings need a visible error path
Inventory Both ways Stock per SKU Overselling when two channels sell the last unit within the same sync window
Orders TikTok Shop to your site New orders, status changes, buyer and shipping details Missed or duplicated events; status names that do not match your own order states
Fulfillment Your site to TikTok Shop Tracking numbers, shipping provider, cancellations and returns Late tracking upload hurting seller metrics; partial shipments

Decide which of these four you actually need before you write a line of code. Many stores only need orders in and tracking out, and skipping catalog push removes the hardest part of the project.

Three ways to connect TikTok Shop to your own website

The right route depends on how much of your logic is standard and how much is yours.

Route Best when Trade-off
Ready-made connector or app Your site runs a mainstream platform that already has a TikTok Shop integration Fast, but you accept its field mapping, sync timing and limits
Integration platform (iPaaS) You need a few workflows and can live with monthly per-task pricing Costs grow with order volume; complex mapping gets awkward
Custom integration on the TikTok Shop Partner Center API You run a custom-built site, need your own order logic, or sync more than one channel Most work up front; full control over mapping, retries and data ownership

If your website is custom-built, a ready-made connector usually does not exist, which is why the rest of this guide covers the third route.

What you need before writing code

  • An approved TikTok Shop seller account for each shop you will connect, in the market where you sell.
  • A developer app in the TikTok Shop Partner Center. You create the app, choose the API scopes it needs, and get an app key and app secret. Which app type fits depends on whether you connect only your own shop or many merchants' shops, and the current options are described in the Partner Center authorization guide.
  • A public HTTPS backend that can receive redirects and webhook calls. A static site cannot do this on its own.
  • A secure place for secrets: the app secret and every shop's tokens belong in server-side storage, never in front-end code.

API scopes and market availability change, so read the scope list in the Partner Center at the time you build rather than trusting a blog post, this one included.

How the TikTok Shop authorization flow works

TikTok Shop uses an OAuth-style flow. The concepts below are stable; take the exact URLs, parameter names and token lifetimes from the official guide.

  1. Send the seller to TikTok's authorization page for your app. The seller logs in and approves the scopes you requested.
  2. TikTok redirects back to your callback URL with a short-lived authorization code.
  3. Your backend exchanges the code for an access token and a refresh token, using your app key and app secret. This call must run server-side.
  4. Look up the authorized shop and store its identifiers with the tokens. Shop-level API calls need a shop identifier that TikTok returns for that authorization, so store it against the shop record.
  5. Refresh before expiry. Access tokens are short-lived, so a scheduled job should renew them and persist the new pair.

Every API request is also signed with your app secret, so a plain HTTP client is not enough: you need the signing routine from the official docs or SDK. Get it right in a test script first, because signature errors are the most common reason a first call fails.

Practitioner notes on token handling

  • Refresh tokens can be rotated. Save the new value every time and never overwrite it with a stale copy from a parallel job. Serialize refreshes per shop with a database lock.
  • Encrypt tokens at rest and keep them out of logs. A leaked token is direct access to a merchant's orders and customer data.
  • Design for revocation. A seller can revoke access at any time. Treat an authorization failure as "shop disconnected," pause its sync and surface it in your admin instead of retrying forever.

Backend architecture that survives real order volume

The pattern that holds up is the same one used for most marketplace integrations: webhooks for speed, scheduled polling for correctness, a queue in between, and idempotent handlers everywhere.

Component Job Why it matters
Auth service Handles the callback, stores and refreshes tokens per shop One place that owns credentials
Webhook receiver Verifies the signature, records the event, returns a fast success response Slow handlers cause timeouts and retries
Queue and workers Fetch full order or product details and update your database Keeps the receiver fast and lets you retry safely
Reconciliation job Periodically lists recently changed orders and compares with your data Catches events that never arrived
Sync log Stores every outbound call and its result per shop The only way to debug "why is this order missing" a month later

TikTok Shop delivers order and product changes to a webhook you register, and the current event types, payload fields and retry behavior are in the Partner Center webhook documentation. Whatever the retry schedule is, plan for two facts: events can arrive twice, and events can be lost.

A webhook receiver skeleton

The structure below is the part that does not change between platforms. The signature check and the field names come from the official docs, so they are left as clearly marked placeholders rather than guessed.

import json
from django.http import HttpResponse
from django.views.decorators.csrf import csrf_exempt
from django.db import IntegrityError
from .models import WebhookEvent
from .tasks import process_event


def signature_is_valid(request, raw_body):
    # Implement exactly as described in the Partner Center webhook docs.
    raise NotImplementedError


@csrf_exempt
def tiktok_webhook(request):
    raw_body = request.body
    if not signature_is_valid(request, raw_body):
        return HttpResponse(status=401)

    payload = json.loads(raw_body)
    event_key = payload.get("EVENT_ID_FIELD_FROM_DOCS")  # dedupe key

    try:
        # unique constraint on event_key makes duplicates harmless
        event = WebhookEvent.objects.create(event_key=event_key, body=payload)
    except IntegrityError:
        return HttpResponse(status=200)  # already seen

    process_event.delay(event.id)  # heavy work happens in a worker
    return HttpResponse(status=200)

Three details in that snippet carry most of the reliability: verify against the raw body before parsing, store first and process later, and enforce uniqueness in the database rather than in application code.

How to sync products, orders and inventory correctly

Most integration bugs are mapping bugs, not API bugs. These are the decisions to make deliberately.

Area Decision Recommendation
SKU identity What links your product to the TikTok Shop listing? Store TikTok's product and SKU identifiers in a mapping table; do not rely on titles or a single seller SKU string
Categories and attributes Your taxonomy will not match TikTok's Maintain an explicit category map and validate required attributes before pushing, so failures show up in your admin, not as silent rejections
Order status TikTok's statuses versus your states Map every TikTok status explicitly and log unknown values instead of ignoring them
Inventory Which system is the source of truth? Your website database, with pushes to TikTok on every change plus a scheduled full reconcile
Prices and currency Per-market pricing Keep a per-channel price field so a TikTok promotion never overwrites your site price
Customer data Buyer details are personal data Store only what fulfillment needs and follow the data-handling terms you agreed to in the Partner Center

For inventory, safety stock is cheaper than apologizing. Reserving a small buffer per channel costs a few sales at worst; overselling costs cancellations, which count against your shop.

Should you build this yourself or hire a team?

Build it yourself if you have a backend developer, one shop, and you only need orders and tracking. The authorization and webhook pieces are a few days of work, and the long tail is mapping and error handling.

Bring in help when you sell in several markets, sync catalog and inventory in both directions, or already run other channels through the same system. That is the point where the reconcile job, sync log and multi-shop token management stop being optional. Our TikTok Shop API integration work covers exactly this layer, and you can scope it against your own stack before committing to anything.

Common problems when connecting TikTok Shop and how to fix them

Symptom Likely cause Fix
Every API call fails with a signature error Signing routine differs from the docs (parameter order, body handling, secret placement) Reproduce with the official SDK or the Partner Center testing tool, then compare inputs
Calls worked yesterday, fail today Access token expired and refresh did not run or lost a race Per-shop refresh lock, alerting on refresh failure
Orders missing on your site Webhook not registered for that shop, endpoint timed out, or event lost Check delivery status, shorten receiver work, add the reconcile job
Duplicate orders Retried event processed twice Unique constraint on event and order identifiers
Product listed on your site but not on TikTok Category, attribute or image requirement failed review Surface the rejection reason from the API in your admin
Stock mismatch between channels Two channels sold the last unit inside the sync window Safety stock plus push-on-change instead of periodic-only sync

If you want a second pair of eyes on a design like this before building, send us the outline through our free quote form and describe your site, markets and order volume.

CÂU HỎI THƯỜNG GẶP

Câu hỏi thường gặp

Can I embed TikTok Shop checkout on my own website?

No. TikTok Shop orders are placed inside TikTok. Connecting a custom website means syncing products, inventory, orders and tracking between your system and TikTok Shop through the Partner Center API.

Do I need a developer account to connect TikTok Shop to a custom website?

Yes for a custom integration. You create an app in the TikTok Shop Partner Center, request the API scopes you need, and have each seller authorize it. If a ready-made connector exists for your platform, you can skip building against the API yourself.

Should I use webhooks or polling to get TikTok Shop orders?

Use both. Webhooks give you orders quickly, but events can be duplicated or lost, so a scheduled reconciliation job that lists recently changed orders is what guarantees nothing is missed.

Where should I store TikTok Shop access and refresh tokens?

On your server only, encrypted at rest and never in front-end code or logs. Refresh them per shop with a lock so parallel jobs do not overwrite a newer token with an older one.

How long does it take to connect a TikTok Shop to a custom website?

Authorization plus order and tracking sync for one shop is typically a matter of days for an experienced backend developer. Multi-market catalog sync, two-way inventory and error handling are what make larger projects take longer.

Cập nhật cùng Netalith

Nhận kiến thức công nghệ, cập nhật sản phẩm và ưu đãi đặc biệt qua email.