GUIDE
Connecting your accounts to an upload tool
Linking your YouTube channel or your BeatStars store to an outside tool is the one moment in the whole release chain where you hand something over instead of receiving it — which is exactly why everyone hesitates there. Yet the word “connect” covers three mechanisms that have nothing in common, and only one of them should make you walk away. Here is what each actually gives, what it does not, and how to take the access back in thirty seconds.
CONTENTS
THE ESSENTIALS
- Three mechanisms share one name: your password, an official authorisation (OAuth), and your browser session. Only the first one should be refused.
- An OAuth authorisation is not a password: it carries a list of permissions shown to you before you accept, and it is withdrawn from the platform — never from the tool.
- BeatStars has no public publishing API. Any tool that posts there therefore goes through your browser: that is not a hack, it is the only route that exists.
- What breaks a connection is almost never a failure: it is an app still waiting for audit, the wrong channel picked at authorisation, or a closed session.
- The useful question is not “do I trust them” but “what can I take back, and where”. The first cannot be verified; the second opens in two clicks.
01Three mechanisms, one word
Every tool shows the same button — “Connect your account” — and depending on the case it means three operations whose consequences are unrelated. In the first, you hand over your credentials and the tool becomes you. In the second, you hand over nothing: the platform issues it a limited pass that you can take back whenever you want. In the third, nothing leaves your machine at all, and the work happens in your own browser, from the session you already have open.
Working out which of the three you are looking at takes no technical skill, only a glance at where you are typing your password. That is the one test that matters, and it fits in a sentence: a platform password is only ever typed on the platform’s own site.
02The password: the only answer is no
A tool that asks for your username and password does not get upload access: it gets your account. The same credentials would let anyone change your recovery address, delete your videos, touch monetisation or close the channel outright. Nothing in this mechanism limits anything, because it was never designed to.
And there is a consequence nobody mentions: sharing credentials this way breaks the terms of service of every major platform. The day it gets noticed, the tool is not the one penalised — your account is. You carry both the risk and the blame.
The only test: the address bar
The tell that never fails is the address of the page asking for your credentials. A legitimate authorisation sends you to the platform’s own domain: a Google screen lives on accounts.google.com, a TikTok screen on tiktok.com. If the form is hosted by the tool — however well designed, however correct the logo — the answer is no, whatever promise sits next to it.
03Official authorisation: what you are actually signing
This is the mechanism behind “Continue with Google” and its equivalents. It is built so the tool never learns your password: you are sent to the platform’s site, you log in there as usual, and the platform hands the tool a token together with a list of permissions. That token opens those permissions and nothing else, and it is cancelled in one click — from the platform, never from the tool.
The consent screen is the contract
The list shown before you press “Allow” is the only part of the machinery that concerns you, and it is precisely the part everyone skips. It is written by the platform rather than the tool, and it is deliberately broad: “manage your videos” covers uploading and deleting alike. So the useful reflex is not to read it word by word, but to compare it against what the tool claims to do.
| Permission requested (YouTube side) | What it allows | What it does not allow |
|---|---|---|
| youtube.upload | Uploading videos to the channel and filling in their metadata. | Reading analytics, handling comments, touching videos already live. |
| youtube.readonly | Reading the channel, its videos and its playlists. | Writing anything at all. A read-only permission publishes nothing. |
| youtube.force-ssl | Managing the channel as a whole: editing, deleting, commenting, replying. | Almost nothing. This is the broadest permission of the set. |
| yt-analytics.readonly | Reading detailed audience reports. | Publishing, editing or deleting. |
Three questions before you accept
- 1.Is the screen served by the platform’s own domain? Look at the address bar, not the logo.
- 2.Does the permission list match what the tool says it does? A tool that publishes has no need to read your comments.
- 3.Do you know where to withdraw it? If the answer is no, open the revocation page before authorising, not after.
“Google hasn’t verified this app”
That warning screen does not say the tool is malicious. It says the app requests sensitive permissions and has not yet been through Google’s verification process — a long, documented and expensive exercise for a small publisher. Plenty of entirely honest tools have been through it, or are still waiting.
The consequence, though, is very concrete and you will live with it: while an app stays in testing mode at Google, the authorisations it issues stop working after seven days. In practice that means reconnecting your channel every week, with your scheduled uploads failing in between. So the question to ask a tool’s support before subscribing fits in one line — is your app verified, or still in testing?
04TikTok: the unaudited app problem
TikTok adds a layer YouTube does not have. An app can hold a perfectly valid authorisation and still be unable to post publicly: until it has passed TikTok’s audit, whatever it sends lands in your account as private, or as a draft for you to finish by hand. That is not a setting on your account, and you will not fix it from the app: it is a status belonging to the tool.
What you will actually see
Which is why this gets checked before you build a calendar on it, not after you have scheduled a month of releases. A serious tool displays that status, or tells you when asked. And if the answer is “audit in progress”, the behaviour to expect is not a failure: it is a queue of drafts somebody will have to open one at a time.
05BeatStars: why it runs through your browser
BeatStars offers no public publishing API. No outside server can drop a beat there, so any tool that publishes to BeatStars necessarily drives the web interface — that is, it works through a browser extension, from the session you already have open. This is not a dubious workaround, it is the only available route, and a tool claiming otherwise would deserve a question.
What this architecture spares you
Quite a lot, in fact. No BeatStars password is passed to anyone, because you stay logged in yourself, exactly as usual. Nothing is stored with a third party, and there is no token to revoke because nothing was ever delegated: uninstalling the extension is enough, and logging out of BeatStars closes the door for good.
What to check before installing
An extension declares its permissions, and they are readable before installation on its store listing, then at any time in your browser’s extensions page. That is where the only difference that matters plays out between a reasonable extension and one to refuse.
- —“Read and change your data on beatstars.com”: exactly what is needed, and nothing more.
- —“Read and change your data on all websites”: refuse without discussion for a tool that only works on one store.
- —Access to browsing history, tabs or the clipboard: unrelated to filling in a product form.
- —An identifiable publisher, a privacy policy that actually exists, and an extension that has not changed hands since its last update.
The trade-off worth knowing about
Because publishing happens from your machine, it requires your machine. Browser closed, session expired or extension disabled, and nothing goes out — whereas an authorised YouTube upload happens without you, computer switched off. That asymmetry is not a flaw in whichever tool you pick, it is the direct consequence of there being no API: keep it in mind when you decide what you schedule, and at what hour.
06Taking it back: where, and what happens next
Trust is not a question you can settle; reversibility is. Do the move once with nothing at stake, before you need it: open each platform’s revocation page and look at what is listed there. Five minutes, and a vague worry is replaced by an address you know.
- 1Google and YouTubeIn your Google account, under Security, the list of third-party apps you have given access to. It shows each tool, the date you authorised it and the permissions granted; removing access takes effect immediately.
- 2TikTokIn the account settings, the security section lists authorised apps. The exact wording moves from one version of the app to the next, but the entry is always there, and the effect is the same.
- 3BeatStarsNothing to revoke on the platform side, because nothing was delegated. You uninstall the extension, and log out of BeatStars if you also want to close the session the extension was using.
- 4The tool itselfDeleting your account with the tool does NOT withdraw the authorisation on the platform side: these are two independent actions, and the platform-side one is what actually cuts access. Do them in that order — revoke, then close the account.
07Why a connection breaks, and what to do about it
Almost every connection incident falls into six boxes, and none of them is a failure in the proper sense. Recognising them saves the hour you would spend writing to support — and, more importantly, stops you switching tools over a platform rule that will behave identically elsewhere.
| Symptom | Usual cause | What to do |
|---|---|---|
| You are asked to reconnect your channel every week. | The app is still in testing mode at Google: the authorisations it issues expire after seven days. | Ask the publisher whether the app is verified. Until it is, schedule nothing beyond the week. |
| The connection drops after several months without publishing. | An authorisation left unused for a long stretch eventually stops being valid. | Reconnect. That is normal behaviour, not an incident. |
| Your channel does not appear in the list when authorising. | It is a Brand Account channel, and the account picker shows your personal channel first. | Start the authorisation again and pick the right channel explicitly in the selector. |
| Videos arrive as private without you asking for it. | The tool’s project has not passed the platform’s audit: automated uploads are then locked to private. | Flip those videos by hand while waiting for the audit, or publish that batch another way. |
| On TikTok, everything lands as a draft. | Same cause, TikTok side: an unaudited app. | Finish the drafts in the app, and check the status before scheduling any more. |
| Nothing goes out to BeatStars, with no error message. | Session closed, browser quit, or extension disabled by an update. | Log back in on beatstars.com, reopen the tab, restart the queue. |
The Brand Account trap
A YouTube channel can belong to a Brand Account separate from your personal Google account. So at authorisation Google shows a picker, and people click the first row by reflex — the one with their own name on it. The tool then publishes to a personal channel with no subscribers, which does not show up straight away precisely because everything works.
The fix is simple: revoke, start again, pick the right row. The part worth knowing is elsewhere — if you are a manager rather than the owner of the Brand Account, some authorisations will not be granted to you, and the error message will not say so clearly. In that case the owner has to make the connection.
08The check before connecting anything
- The authorisation screen is served by the platform’s domain, not the tool’s.
- The permissions requested match what the tool does, with no unexplained extras.
- You know whether the app is verified by the platform or waiting for audit.
- You have opened the revocation page once, so you know where it is.
- The extension, if there is one, only asks for access to the domain concerned.
- The selected channel is the right one, Brand Account included.
- A privacy policy exists and says what is kept, and for how long — your audio files included.
- You remain the owner of what is produced, and it is written down somewhere.
The hidden-upload test
Then there is the test worth all the others, and it takes ten minutes: connect, publish one single beat as unlisted, then go and look at what actually arrived on the platform. Title, description, tags, thumbnail, visibility, channel. What a tool does with your metadata is discovered there, not on its pricing page — and discovering it on one hidden video costs infinitely less than on the next thirty.
09The mistakes that cost an account
- Typing your YouTube password into a form Google is not hosting, because the logo looked right.
- Accepting a consent screen without reading the list, then being surprised a tool edited videos already live.
- Installing an extension that demands access to all websites in order to fill a form on one store.
- Believing that deleting your account with the tool cuts its access to the channel: the authorisation stays active.
- Authorising the wrong channel, and publishing to it for three weeks before noticing.
- Sharing channel access by handing over a password, when YouTube lets you add a manager instead.
- Scheduling a month of releases on an app still waiting for audit, and collecting a month of drafts.
- Revoking access without checking the queue, and losing everything already scheduled.
- Reusing the platform password as the password for your account with the tool.
10And if you would rather connect nothing
That is a perfectly defensible answer, and there is nothing more to say about it: manual publishing works, and it is described in detail in the bulk uploading guide and in the uploading guide. What you lose is not security, it is pace — and pace is exactly what decides whether anyone finds you, as the upload schedule guide covers.
The middle path: one platform only
There is a sensible middle path, and too few people take it: connect only the platform where you lose the most time, usually YouTube, and keep the rest by hand. A connection is not an all-or-nothing commitment — it is one authorisation per platform, withdrawn separately, and nothing says they all have to be granted on the same day.
READ NEXT
- 10 MIN READHow to make a type beat videoFormats, resolution, looping, loudness, thumbnails and tags: the complete guide to turning a type beat into a YouTube video, then cutting it for 9:16.
- 10 MIN READHow to publish beats to BeatStars automaticallyPrepare your files, fill in the metadata that sells, handle licences and cover art, publish in batches and sync with YouTube and TikTok.
- 12 MIN READWhere to sell your beats: BeatStars, Airbit, TrakTrain or your own storeCommissions, payouts, licences and lock-in: what actually separates BeatStars, Airbit, TrakTrain and your own store — plus the maths that settles it.
- 10 MIN READHow to upload beats to YouTube in bulkPrepare a batch, upload several beats at once, schedule releases to the hour and keep metadata consistent across an entire catalog.
- 11 MIN READHow to upload beats: what to settle before you clickAudio format, loudness, cover art, metadata, rights and samples: everything to settle before you upload a beat, on any platform.
- 9 MIN READTitle, description and tag templatesOne title template, one description block and a reusable tag list for every release — plus the method that stops you rewriting them on every upload.
- 12 MIN READPromoting your beats on TikTok and YouTube ShortsWhere to cut the thirty seconds, which export settings, what to write in the caption and where the buy link really lives: short-form for beatmakers.
- 17 MIN READBuilding a type beat YouTube channelLane, channel identity, playlists, thumbnails, Shorts, revenue and analytics: how to build a type beat YouTube channel that still runs a year from now.
- 15 MIN READBeat licensing and pricing: what you actually sellMP3, WAV, trackout, unlimited, exclusive: what each tier really allows, how to set your prices, and what the contract has to say in plain words.
- 14 MIN READSplitting a beat between producersWho owns what when a beat is co-produced: usual splits, BeatStars payouts, YouTube revenue, samples, and the written agreement that prevents a dispute.
- 16 MIN READHow often should you upload type beatsHow often to release, how to build a buffer of finished beats, where to place your slots, and how to restart a channel after a gap without wrecking it.
- 12 MIN READHow to promote your BeatStars beats on YouTubeWhere the buy link goes, what belongs in the two visible lines of a description, what the pinned comment is for, and how to find out which video actually sold.