Tutorials
TikTok profile in JavaScript
One authenticated call to /api/v1/tiktok/profile?handle=nasa, the response it returned, and the line that reads one field out of it.
What you need
Node 18 or later, where fetch is global. No package to install. The same code runs in a browser, except that a browser would expose your key — call this from your server.
The call
const url = "https://honesthook.com/api/v1/tiktok/profile?handle=nasa";
const response = await fetch(url, {
headers: { Authorization: `Bearer ${process.env.HH_KEY}` },
});
if (!response.ok) {
throw new Error(`HTTP ${response.status}`);
}
const envelope = await response.json();
console.log(envelope.success, envelope.platform, envelope.endpoint);
What came back
{
"success": true,
"platform": "tiktok",
"endpoint": "tiktok/profile",
"data": {
"author": {
"id": "7664638705177150477",
"handle": "nasa",
"name": "NASA",
"followers": 1711912,
"following": 23,
"posts_count": 44,
"verified": true,
"is_private": false
}
},
"error": null,
"cached": true
}
Recorded response, captured 15 Sep 2026. A live call returns the value at the moment you ask, not this one.
Every field in that capture
| In JavaScript | Type in this capture |
|---|
envelope.success | boolean |
envelope.platform | string |
envelope.endpoint | string |
envelope.data.author.id | string |
envelope.data.author.handle | string |
envelope.data.author.name | string |
envelope.data.author.followers | number |
envelope.data.author.following | number |
envelope.data.author.posts_count | number |
envelope.data.author.verified | boolean |
envelope.data.author.is_private | boolean |
envelope.error | null |
envelope.cached | boolean |
A field we cannot read comes back null, never 0. A zero would be a claim about the account; null is a fact about our collection.
Reading one field
console.log(envelope.data.author.followers);
envelope is the object from the block above. Keep the key on the server: a key shipped to a browser is a key anyone can read.
The hard part of reading a TikTok profile is not parsing it. It is getting the real page at all: a request from a datacenter address gets served a challenge page that answers 200 OK and contains no data. Nothing errors. You get a page and no numbers.
That is the failure this endpoint exists to absorb.
What you are calling
You are calling our endpoint, not TikTok's. The request goes to honesthook.com with your key in an Authorization header. The residential exit and the browser-like handshake that turn that challenge page into the real one are on our side of the call.
The handle in the example is the one that produced the response below. Change it and you get another account; the envelope does not change shape.
Before you copy the block
Keep the key in an environment variable — all three examples read HH_KEY.
Then read the response. The profile endpoint answers about the account, not about its videos, and a count we cannot read is null rather than 0: a zero would be a claim about the account, and a null is a fact about our collection.