Social Media Permissions
When you connect a social media account to Ambassify, the network asks you to approve a set of permissions (also called OAuth scopes). This page lists every permission we request, per network, and explains what we use it for.
We Only Ask for What a Feature Needs
Ambassify does not ask for every permission at once. What you see on the consent screen depends on what you are doing at that moment.
| Situation | Who | Where | What we ask for |
|---|---|---|---|
| Log in or sign up with a social account | Everyone | Login page (web and mobile app) | Your basic profile and email address, so we can identify you |
| Connect an account to share campaigns (including auto-share) | Members | Ambassify app (web and mobile) | Permission to post on your profile and on any company pages you manage, plus statistics about those posts |
| Configure mentionable accounts | Admins | Ambassify Manage | LinkedIn only: access to search a company page’s followers, so admins can choose which accounts members can mention in their shares |
| Add an import source | Admins | Ambassify Manage | Access to read a page’s posts, so they can be turned into campaigns. Some networks only grant this together with write access (see below); Ambassify only reads from an import source |
A few principles apply across all networks:
- Step by step. Logging in with LinkedIn does not give Ambassify permission to post. Posting permissions are only requested when you choose to connect an account for sharing.
- We never see your password. You approve permissions on the network’s own website. Ambassify receives an access token (and, where the network issues one, a refresh token), never your social media password.
- We don’t read your timeline. Posts are only read from accounts an admin has added as an import source. Connecting your own account to share does not import your posts.
- Nothing is posted without a trigger. Ambassify only posts when you share a campaign, or when you have turned on auto-share for that account.
- You stay in control. You can disconnect an account in Ambassify, or revoke Ambassify’s access in the network’s own settings, at any time.
Log in with LinkedIn
| Permission | What we use it for |
|---|---|
r_liteprofile | Your name and profile picture, to create or match your Ambassify profile |
r_emailaddress | Your email address, to match you to your Ambassify account |
These two permissions are always part of any LinkedIn request, also when you connect for sharing.
Share to your LinkedIn profile or a LinkedIn Page
Requested when a member connects LinkedIn in the Ambassify app. Your profile and any LinkedIn Pages you administer are connected in the same step.
| Permission | What we use it for |
|---|---|
r_basicprofile | Your name, headline and profile picture, to show which account is connected |
w_member_social | Publish posts on your personal profile when you share a campaign |
r_organization_admin | List the LinkedIn Pages you administer, so you can share to them too |
w_organization_social | Publish posts on a LinkedIn Page you administer |
r_1st_connections_size | The number of your 1st-degree connections, to estimate the reach of your shares |
r_member_postAnalytics | Engagement statistics (such as reactions and comments) for posts you shared through Ambassify |
LinkedIn shows the Page permissions to everyone who connects. If you don’t administer a LinkedIn Page, they give Ambassify access to nothing.
Configure mentionable accounts
Requested when an admin chooses, in Ambassify Manage, which LinkedIn accounts members can mention in their shares. Next to the sharing permissions above (except r_member_postAnalytics), this asks for:
| Permission | What we use it for |
|---|---|
r_organization_followers | Search a LinkedIn Page’s followers, so the admin can pick which accounts members can mention |
Import posts from a LinkedIn Page
Requested when an admin adds a LinkedIn Page as an import source in Ambassify Manage.
| Permission | What we use it for |
|---|---|
r_basicprofile | Show which LinkedIn account is connected |
rw_organization_admin | List the LinkedIn Pages you administer, so you can choose which one to import from |
r_organization_social | Read the Page’s posts, so they can be used to create campaigns |
Ambassify uses rw_organization_admin only to look up which Pages you administer. It does not change any Page settings.
When you connect LinkedIn again for a different feature, we combine the new permissions with the ones you already granted. That way, a reconnect never silently removes access a feature depends on.
Log in with Facebook
| Permission | What we use it for |
|---|---|
public_profile | Your name and profile picture, to create or match your Ambassify profile |
email | Your email address, to match you to your Ambassify account |
Share to a Facebook Page
Requested when a member connects Facebook in the Ambassify app. Ambassify only publishes through the API to Facebook Pages the member manages, not to personal Facebook profiles.
| Permission | What we use it for |
|---|---|
business_management | List the Pages you manage, including Pages owned through a Meta Business account |
pages_manage_posts | Publish posts, photos and videos on a Page you manage |
pages_read_user_content | Read reactions and comments on posts shared through Ambassify, to report engagement |
read_insights | Read view and reach statistics for posts shared through Ambassify |
Import posts from a Facebook Page
Requested when an admin adds a Facebook Page as an import source in Ambassify Manage.
| Permission | What we use it for |
|---|---|
business_management | List the Pages you manage |
pages_read_engagement | Read the Page’s posts, so they can be used to create campaigns |
Meta may add related permissions to the consent screen that a requested permission depends on.
Ambassify connects to Instagram professional accounts (Business and Creator accounts) through Instagram Login. Personal Instagram accounts cannot be connected.
| Permission | What we use it for |
|---|---|
instagram_business_basic | Your username, profile picture, follower count (to estimate reach) and your posts (for import sources) |
instagram_business_content_publish | Publish photos, videos and carousels on your account when you share a campaign |
Instagram grants both permissions together, whether you connect Instagram to share (Ambassify app) or an admin adds it as an import source (Ambassify Manage). Posts are only read for import sources.
X (formerly Twitter)
X does not use fine-grained permissions for the type of connection Ambassify uses. You approve access for the Ambassify app as a whole, at the permission level set on our X app: read and write.
| Access | What we use it for |
|---|---|
| Read | Your profile (name, picture, follower count to estimate reach) and your posts (for import sources) |
| Write | Publish posts on your account when you share a campaign |
X grants read and write access together for every connection, whether you connect X to share (Ambassify app) or an admin adds it as an import source (Ambassify Manage). Ambassify only posts when you share, and only reads posts for import sources.
Log in with Google
| Permission | What we use it for |
|---|---|
profile | Your name and profile picture, to create or match your Ambassify profile |
email | Your email address, to match you to your Ambassify account |
Share to a Google Business Profile
Requested when a member connects a Google Business Profile in the Ambassify app.
| Permission | What we use it for |
|---|---|
https://www.googleapis.com/auth/business.manage | List the business locations you manage and publish posts to them |
Because shares can be scheduled or published automatically, this connection also asks Google for offline access. That lets Ambassify publish while you are not actively signed in.
Apple
Apple is only used to log in. We request your name and email. Apple lets you hide your real email address; in that case we receive a private relay address instead.
Networks Without Permissions
For Pinterest, XING and WhatsApp, Ambassify does not connect to your account. Sharing opens the network’s own share window with the campaign content filled in, and you publish it yourself. No permissions are requested and no access token is stored.
Other Connected Services
These are not social networks, but they use the same connection flow.
| Service | Permission | What we use it for |
|---|---|---|
| Strava | activity:read | Read your activities for fitness challenges in your community |
| Canva | profile:read | Identify your Canva account when you connect it to Ambassify |
Related Documents
Questions about these permissions? Contact our CISO at security@ambassify.com.