Optional · BYOK

Your keys. Your consent screen.

Every account runs on Nylon-managed OAuth apps by default. When you need your own — your brand on the consent screen, your quota on your throughput — swap the credentials for any provider and keep every endpoint identical.

What changes

The same dialog, a different name on it

BYOK swaps the credentials Nylon signs with. Your endpoints, payloads and responses stay exactly the same — the only thing your users see is who is asking.

Instagramoauth/authorize
A

Nylon wants to access your account

  • Publish posts on your behalf
  • Read comments and messages
  • Read profile information
CancelAllow

Running on Nylon-managed apps

Your app, your consent screen

Users authorise your brand, not ours. Drop your client id and secret into the dashboard and Nylon runs the OAuth dance on your behalf.

Your rate limits

Platform quotas are counted against your app, so your throughput is not shared with anyone else on the platform.

Start shared, switch later

Ship on Nylon-managed apps on day one. Move a provider to your own credentials whenever your platform review clears — connections stay put.

Secrets stay encrypted

Credentials are encrypted at rest with per-tenant keys, never logged, and never returned by the API once written.

Throughput

A quota nobody else is spending

On a shared platform app your ceiling moves with everyone else's traffic. On your own app it moves with yours.

Shared platform app

Quota split across every tenant

46% of window used

Your own app

Quota counted against you alone

18% of window used

How it works

Four steps, then nothing in your code changes

Credentials are per provider, so you can run Meta on your own app while LinkedIn stays managed — and change your mind later.

ProviderOAuth app
Meta — Facebook & InstagramYour appNylon app
XYour appNylon app
LinkedInYour appNylon app
TikTokYour appNylon app

Existing connections keep working through the swap.

01

Create your platform app

Register an app with the network — a Meta app, an X project, a LinkedIn app. Set the redirect URI Nylon gives you, and request the scopes for what you plan to publish.

02

Store the credentials

Paste the client id and secret into the dashboard, or POST them to the credentials endpoint. They are encrypted at rest with a per-tenant key and never returned by the API again.

03

Connect accounts as normal

Nothing else in your integration changes. Nylon runs the OAuth handshake against your app instead of ours, and the consent screen shows your name and logo.

04

Publish

Requests are signed with your app’s token, so platform quota is counted against you — not shared with every other tenant on the platform.

Which one should you be on?

Most teams never leave the managed apps. These are the reasons to.

Use Nylon-managed apps when

  • You are prototyping or running a proof of concept
  • You have not started platform review yet
  • You publish for a handful of your own brands
  • You want the shortest path to a first published post

Use your own keys when

  • Your users must authorise your brand, not a vendor
  • You need throughput that is not shared with other tenants
  • Your compliance team requires a direct platform relationship
  • You have negotiated elevated access with a network
curl https://api.nylon.dev/v1/providers/instagram/credentials \
  -H "Authorization: Bearer $NYLON_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "client_id": "$META_APP_ID",
    "client_secret": "$META_APP_SECRET",
    "redirect_uri": "https://yourapp.com/oauth/callback"
  }'

# => { "provider": "instagram", "mode": "byok", "verified_at": "2026-09-01T10:22:04Z" }

Ship social publishing this week

Two connected accounts free forever. Every network, every endpoint, nothing to register — no card, no sales call.