Your keys. Your consent screen.
Every account runs on Nylon-managed OAuth apps by default. When you need your own — your brand on the consent screen, your quota on your throughput — swap the credentials for any provider and keep every endpoint identical.
The same dialog, a different name on it
BYOK swaps the credentials Nylon signs with. Your endpoints, payloads and responses stay exactly the same — the only thing your users see is who is asking.
Nylon wants to access your account
- Publish posts on your behalf
- Read comments and messages
- Read profile information
Running on Nylon-managed apps
Your app, your consent screen
Users authorise your brand, not ours. Drop your client id and secret into the dashboard and Nylon runs the OAuth dance on your behalf.
Your rate limits
Platform quotas are counted against your app, so your throughput is not shared with anyone else on the platform.
Start shared, switch later
Ship on Nylon-managed apps on day one. Move a provider to your own credentials whenever your platform review clears — connections stay put.
Secrets stay encrypted
Credentials are encrypted at rest with per-tenant keys, never logged, and never returned by the API once written.
A quota nobody else is spending
On a shared platform app your ceiling moves with everyone else's traffic. On your own app it moves with yours.
Shared platform app
Quota split across every tenant
46% of window used
Your own app
Quota counted against you alone
18% of window used
Four steps, then nothing in your code changes
Credentials are per provider, so you can run Meta on your own app while LinkedIn stays managed — and change your mind later.
Existing connections keep working through the swap.
Create your platform app
Register an app with the network — a Meta app, an X project, a LinkedIn app. Set the redirect URI Nylon gives you, and request the scopes for what you plan to publish.
Store the credentials
Paste the client id and secret into the dashboard, or POST them to the credentials endpoint. They are encrypted at rest with a per-tenant key and never returned by the API again.
Connect accounts as normal
Nothing else in your integration changes. Nylon runs the OAuth handshake against your app instead of ours, and the consent screen shows your name and logo.
Publish
Requests are signed with your app’s token, so platform quota is counted against you — not shared with every other tenant on the platform.
Which one should you be on?
Most teams never leave the managed apps. These are the reasons to.
Use Nylon-managed apps when
- You are prototyping or running a proof of concept
- You have not started platform review yet
- You publish for a handful of your own brands
- You want the shortest path to a first published post
Use your own keys when
- Your users must authorise your brand, not a vendor
- You need throughput that is not shared with other tenants
- Your compliance team requires a direct platform relationship
- You have negotiated elevated access with a network
curl https://api.nylon.dev/v1/providers/instagram/credentials \
-H "Authorization: Bearer $NYLON_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"client_id": "$META_APP_ID",
"client_secret": "$META_APP_SECRET",
"redirect_uri": "https://yourapp.com/oauth/callback"
}'
# => { "provider": "instagram", "mode": "byok", "verified_at": "2026-09-01T10:22:04Z" }Ship social publishing this week
Two connected accounts free forever. Every network, every endpoint, nothing to register — no card, no sales call.